
AI in Cybersecurity: Mythos & Zhipu
Something significant happened in the AI and cybersecurity space this late June. In case you missed the buzz or currently out of the loop, here's what happened, what experts said, and why it matters for business owners who rely on digital systems to run their operations.
A Chinese AI company called Zhipu AI, operating internationally as Z.ai, released a model called GLM-5.2 on June 13, 2026. Within days, independent security researchers were reporting that it performed on par with some of the most restricted, most powerful AI cybersecurity tools in the world, including Anthropic's Claude Mythos, a model so sensitive that the U.S. government pulled it from global access on national security grounds on June 12, 2026.
On June 30, the government have lifted those restrictions following two weeks of negotiations between Anthropic and the Commerce Department.
The difference between the two tools is that GLM-5.2 is free. Downloadable by anyone. Runnable on private hardware. And subject to no export controls.
What Is Zhipu AI / Z.ai?
Zhipu AI is a Chinese artificial intelligence company focused on developing large language models for enterprise, research, software engineering, and cybersecurity applications. The company has become one of China's leading AI developers through its GLM (General Language Model) family, which emphasizes open-weight releases and practical deployment. Unlike several frontier AI models developed by U.S.-based organizations that remain available only through restricted APIs or controlled partnerships, many GLM models are released under permissive licenses that allow developers, researchers, and organizations worldwide to download and customize them locally.
The company operates internationally under the name Z.ai.
What Is GLM-5.2?
Z.ai shipped GLM-5.2's model weights under an MIT license: a 744-billion-parameter mixture-of-experts model with a context window reaching a million tokens, enough to take in an entire code repository.
In practical terms, that context window means the model can read and analyze an entire software codebase in a single session. This capability has direct implications for both cybersecurity defense and offense.
GLM-5.2 also excels in coding tasks, scoring 62.1 on SWE-bench Pro, outperforming GPT-5.5 (58.6), and shows competitive performance in agentic tool use, matching Claude Opus 4.8 in some evaluations.
What Is Claude Mythos?
Claude Mythos is Anthropic's most advanced frontier AI model. On June 12, 2026, the U.S. government imposed export controls requiring Anthropic to restrict all foreign access to Mythos and its public sibling Fable 5, citing national security concerns.
Washington ordered Anthropic to cut off foreign access to Mythos and its public sibling, Fable 5, on June 12, citing national security. That means Zhipu's comparison claim can't be independently verified, and may never be in its current form.
Following two weeks of negotiations, Anthropic said on June 30, 2026 that it would begin restoring access to Claude Fable 5 and Mythos 5 after the US Department of Commerce notified the company that it had removed its export controls.
Commerce Secretary Howard Lutnick wrote to Anthropic citing "significant progress" in the talks, stating that "a license will no longer be required to export, reexport, or in-country transfer the Claude Mythos 5 Model."
The episode, a government-ordered shutdown followed by a negotiated restoration in a little over two weeks, illustrates the degree to which frontier AI cybersecurity models have become a geopolitical and regulatory flashpoint.
The Frontier-Grade Cybersecurity
Two independent evaluations produced findings that attracted significant attention from the security community.
Independent testing by Semgrep placed GLM-5.2's IDOR (Insecure Direct Object Reference) vulnerability detection at an F1 score of 39%, surpassing Claude Code's 32–37% on identical evaluations.
IDOR vulnerabilities are a common class of authorization flaws that allow unauthorized users to access data or systems they shouldn't be able to reach. Detecting them accurately and at scale is a high-value capability for both security teams and attackers.
Graphistry called GLM-5.2 the first open-weight model it would recommend for a frontier-grade cybersecurity experience. Within days, Axios reported hackers trading jailbreaks on Russian-language forums, and one researcher describing the model chaining exploits "the way an elite human attack would."
On agentic coding benchmarks it beats GPT-5.5 outright and lands within a few points of Claude Opus 4.8, at roughly a sixth of the API cost.
Critical Shift in AI in Cybersecurity
Forbes contributor Craig S. Smith framed the release this way, "The release signifies a critical shift where advanced cyber-AI is no longer contained behind gated APIs."
On the governance implications, Smith identified three practical shifts for business and security leaders:
Plan for adversaries who can read an entire codebase and configuration, not just probe exposed endpoints,
Compress patch cycles for known vulnerabilities from quarters to days, and;
Build the in-house capacity, under real governance, to point these models at your own software before someone else does.
TheStreet identified the deeper strategic problem:
A free, downloadable alternative closing the gap on cost and agentic performance was already a hard sell.
A premium model whose access list a Commerce Secretary can edit by letter, even temporarily, makes the case harder still.
On the governance gap created by open-weight release, "Closed models like Opus 4.8 and Mythos live entirely on Anthropic's servers, accessed through an API the company, or a regulator, can switch off at will. Open models like GLM-5.2 ship their weights under a license that lets anyone download, modify, and run the system on their own hardware. That difference used to be mostly philosophical. It's now a procurement decision."
Legal Obligations & Practical Implications
China's National Intelligence Law (2017) requires in Article 7 that all Chinese organizations and citizens "support, assist, and cooperate with state intelligence work in accordance with the law." China's Data Security Law (2021) and Cybersecurity Law (2017) add data localization and government access provisions. The U.S. Department of Homeland Security has explicitly warned that this legal framework can compel Chinese companies to provide data from US persons or businesses on government demand.
In May 2026, U.S. House lawmakers opened a formal inquiry into cybersecurity risks from Chinese AI models in critical infrastructure, naming Zhipu AI among the companies under scrutiny alongside DeepSeek, MiniMax, and ByteDance.
This legal obligation applies regardless of any company's stated privacy policy or where individual servers are physically located.
You don't need to be a cybersecurity expert to understand the practical implications here. Here is what the facts point to:
AI-powered attacks are no longer theoretical. The same capabilities that security teams use to find vulnerabilities in software can now be used by anyone with a consumer-grade computer and an internet connection. The attack surface for businesses that rely on websites, CRMs, and digital infrastructure has expanded.
Patch cycles need to be shorter. The consensus from security experts following the GLM-5.2 release is clear: vulnerabilities that previously gave businesses months to remediate now need to be addressed in days. Outdated software, unpatched plugins, and poorly maintained websites are no longer low-priority maintenance items.
Who built your systems matters. Software and websites built without security best practices embedded from the start are the easiest targets for AI-assisted vulnerability scanning. The question of who built your digital infrastructure is increasingly a security question, not just a quality question.
Vendor dependency is a real risk. The Z.ai story illustrates that AI tools your business depends on can be restricted or cut off with little notice. Understanding which of your systems depend on third-party AI APIs (and what happens if those APIs become unavailable) is worth knowing before it becomes a problem.
AI in cybersecurity has moved from a specialist conversation to a business continuity conversation. The release of GLM-5.2 is one data point in a larger shift. Advanced AI capabilities that were previously restricted to government-vetted organizations are now accessible to anyone, including people with malicious intent.
Staying informed about these developments isn't just for CISOs and security teams. It's for anyone running a business on digital infrastructure, which, in 2026, is almost everyone.
Virtual Central builds and maintains websites and digital systems for small business owners and agencies. If you have questions about the security and resilience of your current setup, we're happy to take a look.
Book a call with Cris. It's not a sales call. Just a conversation to see if our services match your vision.
