ModelRiskIndex

Rankings / Z.ai (Zhipu)

GLM-5.2

Tier 030/100open weights

glm-5.2 (open weights, MIT) via api.z.ai / self-hosted

Usage share 5.0% · OpenRouter rankings API (daily token share, 2026-08-04)

Tier 0 despite MIT weights and clean API data terms: the checklist requires published safety evals and a documented safety policy, and Z.ai publishes neither. NIST CAISI's assessment is the most substantive third-party safety document — for a PRC-lab model, an unusual distinction.

Tier assessment

Fails one or more Tier 1 requirements: no published model card or safety evals, or terms that permit training on customer API data by default with no opt-out.

Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.
  • Published safety evals. No safety evaluations are published for this model.
  • Documented safety policy. No documented safety or acceptable-use policy exists.
  • Enterprise data controls. Customer data is not used for training by default, or a documented opt-out exists.Zero-retention default and Singapore processing per the API privacy policy; PRC-platform terms unverified.
Tier 2 requirements
  • External pre-deployment testing. No disclosed external pre-deployment testing.Third-party testing exists (NIST CAISI, F5) but was independent and post-release, not disclosed pre-deployment testing.
  • Third-party certification. No verifiable third-party certification.
  • Versioning with changelogs. No versioning discipline or changelog for model changes.Rolling main branch on the first-party weights repo; no changelog.
  • Stated deprecation policy. No stated deprecation policy.

Missing for Tier 1: published safety evals, documented safety policy. The tier is computed from this checklist — satisfying these requirements moves the badge, automatically.

Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governancepartial

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

The api.z.ai privacy policy states zero retention by default for API content with Singapore processing — unusually clean terms on paper — but the PRC-platform sibling (bigmodel.cn) terms are unverified, and no certification backs the claims. Self-hosting the MIT weights sidesteps all of it.

Receipts (1)
  • Z.ai API privacy policy
    Z.ai (Zhipu) provider artifacts · provider artifact · source tier B · docs.z.ai · retrieved 2026-08-05
    The Company do not store any of the content the Customer or its End Users provide or generate while using our Services.

Operational stabilitypartial

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Open releases are dated at the aggregator level, but the first-party HuggingFace repo is a rolling main branch, and no changelog or deprecation policy exists for the hosted API.

Receipts (1)
  • GLM-5.2 weights repository
    Z.ai (Zhipu) provider artifacts · provider artifact · source tier B · huggingface.co · retrieved 2026-08-05

Adversarial resistanceweak

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistanceweak

NIST CAISI found GLM-5.2 more robust than other PRC open-weight models but confirmed its safeguards assist agentic cyber-exploit development and can be circumvented when self-hosted; F5 scored it CASI 46.58 against a frontier band of 85–95, and a public DAN-style jailbreak landed within weeks of release.

Prompt injection (agentic)weak

Marketed for agentic engineering, but no injection hardening or agent red-teaming has been published by the developer; CAISI's agent-hijacking findings are relative praise within a weak cohort.

Receipts (4)

Transparencypartial

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

Genuine capability transparency — MIT-licensed weights and detailed technical reports — but zero safety disclosure: no safety section in the model card, no published safety evals, no provider-commissioned external testing.

Receipts (2)
  • GLM-5.2 model card and weights
    Z.ai (Zhipu) provider artifacts · provider artifact · source tier B · huggingface.co · retrieved 2026-08-05
    An MIT open-source license — no regional limits, technical access without borders
  • GLM-5 technical report
    Peer-reviewed / preprint research · independent eval · source tier C · arxiv.org · retrieved 2026-08-05
    We present GLM-5, a next-generation foundation model designed to transition the paradigm of vibe coding to agentic engineering.

Compliance postureweak

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

No SOC 2, ISO, or equivalent certification claims published for the Z.ai API; no enterprise compliance documentation found.

Receipts (1)

Governance & evidence

Where your data goes

  • SG

No regional pinning — the provider chooses where data is processed.

api.z.ai states Singapore processing; the PRC-platform sibling (bigmodel.cn) has unverified terms and is not graded here.

Enterprise vs consumer terms

Enterprise vs consumer gap: not assessed. Not yet assessed. Absence of assessment is not absence of a gap.NOT ASSESSEDENTERPRISE / APICONSUMER
Not assessed

Not yet assessed. Absence of assessment is not absence of a gap.

Change cadence

no tracked changesNo tracked changes for GLM-5.2. Absence of detection is not evidence of stability.none

No tracked changes for this model. That is absence of detection, not evidence of stability — it may mean the model is unwatched, not that it is unchanging.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

10 evidence refs6 distinct sources3 independent
  • CNIST CAISI assessmentsindependent eval×2 references
  • CF5 Labs CASI/ARS leaderboardindependent eval×1 reference
  • CPeer-reviewed / preprint researchindependent eval×1 reference
  • BZ.ai (Zhipu) provider artifactsprovider artifact×4 references
  • EOpenRouter model rankingsusage data×1 reference
  • FInjectPrompt jailbreak disclosuresreporting×1 reference

retrieved 2026-08-05

Compliance & deployment

Trains on customer data by default
No
SOC 2
not verified
ISO/IEC 42001
not verified
HIPAA eligible
not verified
Retention window
API: zero retention by default per privacy policy (uncertified claim)
Data residency
Singapore (api.z.ai); PRC platform (bigmodel.cn) terms unverified
EU AI Act
No published EU AI Act posture; deployer obligations fall on the customer.
Deprecation policy
none stated
Available via
api.z.ai · Self-hosted (MIT weights) · NVIDIA NIM · Multiple inference providers

Change timeline

No tracked changes yet for this model.

Compare this model: GLM-5.2 + open compare view →