All newsReleases

Z.ai publishes its flagship weights — under a licence that binds only companies above $10bn

Published: 8/29/2026 · Source: Z.ai — model card and licence file for GLM-5.3 on Hugging Face

Z.ai uploaded the weights of GLM-5.3 on 28 August 2026, two weeks after announcing the model and four days after opening a placeholder repository with nothing behind it. The upload is 141 files and 755 GB: 753 billion parameters, released natively in FP8 rather than converted after the fact, with a separate BF16 copy alongside. It is the largest set of weights the company has ever put online. The licence is the part worth reading. Two days earlier Z.ai gave its small model, GLM-5.3-Flash, the MIT licence on day one. The flagship did not get it. GLM-5.3 ships under a bespoke document Z.ai calls the „GLM-5.3 License”, and its body is MIT in substance — permission to use, copy, modify, merge, publish, distribute, sublicense and sell, to deploy and fine-tune, and to pass those rights on. One clause is added. If a licensee runs a model-as-a-service business — defined as giving third parties inference or fine-tuning access in a way that lets them control inputs, parameters or training data — and the group's revenue exceeds ten billion dollars over any consecutive twelve months, it must pass a Z.ai security review before any commercial use. The company decides the scope of that review itself. Two exclusions are written in: end-user products that merely embed the model in a feature do not count, and neither does relaying requests to models hosted by someone else. The threshold is what makes this different from the restrictions we documented elsewhere this month. Alibaba's recent open-weight release requires a separate agreement from anyone selling the model as a service, whatever their size. Z.ai's clause is aimed at a specific and very short list — the cloud operators large enough to clear ten billion dollars — and leaves every startup, laboratory, university and self-hosting company entirely free. It is a gate on a handful of doors, not a toll on the road. There is a second reason the release matters. Z.ai's own model card says the model's cyber capability „developed faster than we expected”, and its comparison table puts GLM-5.3 first on CyberGym, the vulnerability-discovery benchmark, at 84.5 per cent — ahead of every closed model the company lists. Further along the exploitation chain the ranking inverts: on ExploitGym GLM-5.3 finishes 105 tasks in a two-hour budget against 181 and 216 for the two closed leaders, and on ExploitBench it reaches 54.4 against their 78.0 and 76.5. The model that now leads at finding flaws is the one anyone can download; the models that lead at using them are the ones nobody can.