Z.ai published GLM-5.3 as a post-training update on the same mixture-of-experts base as GLM-5.2 [E1][E2]. The official model page gives a 1-million-token context window, a 128,000-token maximum output, and text-only inputs, with reasoning always on [E2]. Artificial Analysis lists the model at 753 billion total parameters and 40 billion active [E3]. The API was live on 18 August at the same list price as GLM-5.2; the weights were not [E1][E3].
The independent score that landed inside the window is the agentic one. Artificial Analysis put GLM-5.3 at 60 on its Intelligence Index, a seven-point rise from GLM-5.2 and a tie with Kimi K3 [E3][E4]. On GDPval-AA v2 the model moved from 1,524 to 1,770 Elo, second overall behind Claude Opus 5 [E3][E4]. Those numbers come from Artificial Analysis’s own page and its 18 August post, not from a Z.ai press table [E3][E4].
Cyber claims are a different grade of evidence. Z.ai reports 84.5 percent on CyberGym, 54.4 percent on ExploitBench, and 2,436 vulnerabilities found across 269 projects, of which 1,097 were medium or high severity [E1][E2]. The CyberGym project page exists as an independent benchmark of 1,507 real vulnerability instances; the official leaderboard had not confirmed a matching GLM-5.3 entry by the freeze [E5]. Vendor harness settings are not the same thing as a third-party rerun [E1][E5].
No public checkpoint sat on Hugging Face, GitHub or ModelScope at the freeze [E3]. Z.ai’s own blog said it would release the weights in two weeks after launch, once safety evaluation and hardening are complete [E1]. Artificial Analysis separately recorded the laboratory saying the files would come within the next week [E4]. Prior GLM-5.x releases carried MIT terms; no 5.3 licence text has been published [E1][E3].
The laboratory is explicit about why the files are late. It describes cyber capability that developed faster than expected and a staged path: selected security partners, then broader API, then weights [E1]. That is a first-person dual-use admission, not an outside inference [E1]. Private deployment of an unguarded open-weight exploit model is the risk the delay is meant to price [E1][E5].
The house gives a 0.72 probability that Z.ai will publish GLM-5.3 weights under a permissive licence by 1 September 2026, 23:59 UTC [E1][E3]. YES requires a public Hugging Face, ModelScope or GitHub release with downloadable weights and a licence text by that deadline. The counter-case, carried at 0.48, reads the safety hold as a clock that can slip without a new public excuse [E1]. An API-only continuation, a delayed announcement, or a non-permissive licence settles NO [E1][E3].