Key facts
- Hugging Face used Zhipu AI's GLM-5.2 model for cybersecurity analysis after US AI models declined.
- US AI companies like OpenAI and Anthropic have safety restrictions hindering cybersecurity work.
- Chinese open-source AI models are gaining traction in Silicon Valley due to capabilities and cost.
- The incident suggests US AI guardrails may create a disadvantage for legitimate defenders.
- OpenAI is supporting Hugging Face through its trusted access program.
A New York-based startup, Hugging Face, turned to a Chinese AI model, Zhipu AI's GLM-5.2, to analyze data from a cybersecurity breach after leading U.S. AI models declined the task due to safety restrictions. This incident is fueling concerns that guardrails limiting U.S. AI firms from engaging in cybersecurity work could benefit their Beijing-based rivals.
Leading U.S. AI companies, including OpenAI and Anthropic, have implemented safeguards that prevent their most advanced models from performing hacking-related tasks or distinguishing between legitimate defense work and malicious attacks. For example, Anthropic's Claude Fable 5 routes cybersecurity queries to an older model, and OpenAI's GPT-5.6 Sol is designed to block such activities.
This situation presents a competitive opening for Chinese open-source models like GLM-5.2, which are gaining traction in Silicon Valley for their coding and agentic capabilities, often at a lower cost. Beijing is increasingly leveraging open-source AI to position itself as an alternative to the U.S. in the global AI race, with state media framing this strategy as a response to U.S.-led restrictions.
Lukasz Olejnik, an independent technology consultant, noted that a safety regime restricting legitimate defenders while capable models remain available to attackers creates an asymmetric disadvantage that will likely widen as open-source models improve without similar restrictions. OpenAI stated it has brought Hugging Face into its trusted access program to support their defense efforts.
Zhipu AI's GLM-5.2 has seen a significant rise in usage since its launch last month, with endorsements from figures like Snowflake CEO Sridhar Ramaswamy and venture capitalist Marc Andreessen. The company recently raised approximately $4 billion in a Hong Kong share sale, and its stock has surged nearly ninefold since its debut. However, some analysts caution against removing U.S. safeguards entirely, suggesting instead a rethinking of access architecture to allow controlled capability allocation rather than a blanket refusal.
