Post-Cutoff.com
  1. Home
  2. Posts
  3. Nathan Lambert criticizes Anthropic's GLM-5.3 cyber report

Nathan Lambert criticizes Anthropic's GLM-5.3 cyber report

Nathan Lambert @natolambert · x · 2026-09-29 · ★★★ · archived

Open the original ↗

Most prominent critique (70K views) of the Anthropic report from an open-model researcher.

Summary

Nathan Lambert (Ai2) says Anthropic's GLM-5.3 post is 'solipsistic', insinuates Z.ai is reckless, and ignores that closed models were used in more documented cyberattacks. He proposes 'Open Unsafe, Closed Unsafe' instead of 'Open Dangerous, Closed Safe', credits the authors for acknowledging that open models help spread cyber readiness (Project Glasswing does not reach all critical industry), and mentions that when Fable was released Amazon found a workaround giving access to the model's full capabilities via API.

Archived text

Sigh.

I wrote this post below, but then I didn't post it because I am tired of the consistent pushback I get from folks with the same safety worldview as Anthropic. I guess that means I should send it. Here goes!

This post is pretty solipsistic and doesn't properly take recent events in cyber risks into it's discussion. It is really hard for me to watch how the US frontier labs like Anthropic don't have the ability to consider other approaches to safety and ways things could play out.

It insinuates that Z ai (Chinese lab, builds GLM series) doesn't really care about safety and is reckless to take their business strategy.

Saying things like "Given this evidence, we think it's likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm." and "This is unlike any other similarly capable AI model, all of which were released with safeguards or through limited access programs." while closed models have been used on more of the documented cyber attacks is just bowing out of the interesting question.

A plausible view is that open model weights and closed model apis (with some safe guards) are both far closer to being easy to mis-use, rather than API models being closer to safe. The trope "Open Dangerous, Closed Safe" may be closer to "Open Unsafe, Closed Unsafe"

Closed models have stronger capabilities and stronger safeguards, but the stronger capabilities part could matter more in net harm if both the safeguards are porous.

At the same time, as the authors do acknowledge (thanks - thats progress!), open models without extreme cyber guardrails are important to rapidly diffuse cyber readiness in the economy -- as programs like project glasswing are not perfect in getting all critical industry onboarded.

There will be more issues like the time when Fable was released and Amazon found a workaround, which allowed them to access the full capabilities of the model served readily at an API.

The blog overall is reasonable in it's narrow line, but it's a very effective tool in a complicated, rapidly evolving media ecosystem to reinforce a certain type of safety thinking.

Media: https://pbs.twimg.com/media/HTaqIJJbAAAUMb1.jpg?name=orig

views 69580 · likes 652 · reposts 78 · replies 47 (at fetch time)

Archived 2026-09-30 via fxtwitter (unofficial).

Related events

All posts · id: 2026-09-29-natolambert-glm-5-3-report-critique