Z.ai holds GLM-5.3 weights as OpenAI ends Preparedness
Z.ai held GLM-5.3's open weights for two weeks of security assessment on the same day OpenAI disbanded the team that did that work.
Z.ai shipped GLM-5.3, a coding and cyber-defence model post-trained on the same 743B base as GLM-5.2, and said it will hold the open weights back about two weeks to finish security assessments, after the model came close to Anthropic's Mythos 5 on bug-finding tests (The Hindu). The model is not held back. It is reachable now through the Coding Plan and ZCode. What waits two weeks is the copy nobody can withdraw.
Two weeks is the whole of the pause
It is a hold on distribution, not on capability, and it runs for a fortnight. In the same week Meta released Muse Glimmer, a 30-billion-parameter Apache 2.0 model that runs on a single consumer GPU, and Nvidia followed a day later with Nemotron 3.5 Lightning, an open mixture-of-experts model with 30 billion total parameters and roughly 3 billion active per token, aimed at the execution layer of long-running agents (WION). Neither came with a hold. A two-week wait inside a week that shipped two other open models is a pause on one release, not on the class of thing being released.
The other lab moved the assessment somewhere else
OpenAI disbanded its Preparedness team at the end of July according to the Financial Times, splitting biosecurity and cyber risk assessment across existing product teams. It is the third safety-focused group the company has dissolved in roughly two years, after AGI Readiness and Mission Alignment, and co-founder Greg Brockman argues that embedding safety in model development is stronger than siloing it (Crypto Briefing). The argument may well be right on the engineering. It is not checkable from outside. A team with a name either publishes an assessment or visibly does not; a function spread across product teams has no address to check.
OpenAI closed $122B at an $852B valuation in March 2026 (OpenAI). Whatever moved the Preparedness work into the product org, the cost of keeping a named group was not it.
Today's three intrusions needed none of it
Set a bug-finding score next to what actually landed on the same day's record.
- SafePal said an authorisation flaw in its order-tracking plugin exposed the names, email addresses, shipping addresses, phone numbers and purchase details of roughly 39,798 customers, four days after a breach at Trezor's shipping partner ShipMonk hit nearly 14,000 more (The Block).
- Apple patched CVE-2026-65400, an authentication bypass in macOS Screen Sharing that hands attackers remote root, after the Dutch national cyber security centre reported on 12 August that it was being exploited to plant Monero mining software. CISA raised the severity rating to 9.8 (Tom's Hardware).
- A threat actor calling itself TheHatman spent the past week posting internal employee directories from McDonald's, Vodafone and Kyndryl to cybercrime forums, the records pulled straight out of the victims' Azure and Entra portals with stolen credentials (Cybersecurity News).
One authorisation check that was not there, one flaw a national CERT had already written up, and one set of working credentials. None of the three waited on a model that can find bugs, and a model that can find bugs would not have shortened any of them.
The money is buying the other half
Mindgard raised a $30 million Series A led by Album VC, with Karma Ventures and existing investor .406 Ventures following, for software that attacks AI models to find where they break (SecurityBrief). That is the model as the target, funded at Series A scale, in the same record as a lab holding weights because the model is the weapon. Both bets are live and they are not the same bet.
The hold and the disbanded team ask one question twice: who runs the assessment, and does anyone outside see what it found. Z.ai named a window and a reason, which is more than most weight releases carry. OpenAI's answer is that the work continues inside the product teams. Neither answer comes with a result, and the attacks in today's record went around the capability both of them are assessing.
What the ledger holds
The day-by-day feed behind this note is in the ledger, and OpenAI carries its funding, valuation and revenue in one place. Every figure above links to the source it came from. Nothing here is estimated.
Built from the digest of 2026-08-17.