Z.ai's GLM-5.2 doesn't make US export controls irrelevant, but it does expose their weakest assumption: you can't gate a capability once a close substitute is sitting in open weights.
The US government tried to put Anthropic's Mythos 5 and Fable 5 behind a tighter gate in June. Within days, Beijing's Z.ai had GLM-5.2 moving through developer circles as an open-weight coding and security model, and that timing is exactly why this story matters. If you're building policy around access controls, the uncomfortable question is not whether Anthropic can obey an order. It is whether anyone else has to.
Axios reported that Commerce Secretary Howard Lutnick approved a limited return of Mythos 5 in a June 26 letter after Anthropic worked with the government on safeguards. Business Insider noted that Fable 5 remained restricted, while Mythos 5 could be redeployed to a set of US organizations operating or defending critical infrastructure. That is a narrower outcome than the panic of June 12, when Anthropic said it had disabled access to both models after an export-control order covered foreign nationals, including some of its own employees.
Then came GLM-5.2. Z.ai, formerly Zhipu AI, released the model in mid-June with a one-million-token context window and an open-weight distribution strategy aimed squarely at long coding tasks and agentic workflows. The Verge reported that researchers now claim GLM-5.2 can match Mythos in some bug-finding and cybersecurity scenarios, even if it still trails leading US systems on broader general tasks. That caveat matters. So does the result.
You don't need China to beat the best US model across every benchmark for the policy problem to appear. You only need an open model to get close enough on the dangerous part of the job.
Security researchers are already treating that as more than a theoretical issue. Axios reported last week that GLM-5.2 has agentic capabilities rivaling Claude Opus 4.8 and OpenAI's GPT-5.5 while costing roughly half as much to run, and that GuidePoint Security's Jason Baker had seen hackers in Russian-language forums discussing ways to jailbreak it for hacking tasks. Baker also added a useful brake: many AI-generated exploits and malware samples seen in the wild still aren't very good. Keep that sentence in the story. It stops the whole thing from becoming theater.
The hard fact remains that open weights change the enforcement surface. A closed model can be rate-limited, logged, geofenced, suspended, or pulled from an API. An open-weight model can be downloaded, copied, modified, fine-tuned, and run on infrastructure the original developer never sees. If you're a defender, that lets you test code without sending sensitive material to a third party. If you're an attacker, it lets you remove guardrails and work without a commercial provider's logs. Frankly, any policy that treats those two distribution models as the same object is already behind the story.
Z.ai co-founder Jie Tang sharpened the point himself on X on June 18. Elon Musk had suggested Chinese AI could reach Fable-class capability around the first quarter of 2027. Tang replied that it wouldn't take that long, and added that science should be global after access to advanced models had been cut off. You can read that as open-science rhetoric, commercial positioning, or geopolitical needling. It works as all three because GLM-5.2 gives the line something concrete beneath it.
This is where Washington's export-control logic starts to creak. Export Administration Regulations were built around controllable items: chips, equipment, facilities, supply chains. Software has always been harder, but API-only frontier models at least gave regulators a choke point. Open weights remove much of that choke point. There is no approved-entity list sitting between you and a model file once the weights are mirrored widely enough.
That doesn't mean the US should shrug and let every frontier cyber model go anywhere. Don't bother with that lazy conclusion. Anthropic's own experience shows why governments care: Business Insider reported that the June order was tied to concerns that safeguards could be bypassed, a claim Anthropic disputed in severity while saying the government had not given it specific details. Cyber models that can find vulnerabilities quickly are useful to defenders and attackers. Pretending otherwise is unserious.
But GLM-5.2 makes one response look weaker by the day: locking down American models while assuming capability stays locked down with them. The New York Post reported that Chinese open-source models are already gaining US customers, citing Vercel CEO Guillermo Rauch's public praise for GLM-5.2's coding performance and former Meta and DeepMind executive Mat Velloso calling it the first open model that passed his daily-driver bar. Those are not treaty partners or intelligence agencies. They're working developers looking for tools that perform and cost less.
The right policy discussion now has to be more specific. Which cyber capabilities trigger licensing? Which safeguards can be tested before release? How do you treat open-weight models from companies outside US jurisdiction? And what do you do when the restricted US model and the downloadable foreign model are close enough that customers stop caring about the distinction?
GLM-5.2 hasn't ended the AI export-control argument. It has made the old version of that argument too neat to survive. The model is current, downloadable, and good enough in the exact category that made Mythos politically explosive. That is the fact Washington has to start from, not the one it wishes were still true.
Also read: Momenta's Hong Kong IPO prices at HK$295.60 as Chinese autonomous driving bets on software margins over profits • Micron Technology briefly overtook Meta and Tesla in market value after revenue quadrupled on AI memory demand • Independent filmmakers are making animated features for $50,000 and the math now works