Separate routine development from dangerous requests. The proposed safeguards aim to block high-risk cyber requests while allowing ordinary coding, maintenance, and defensive security work to proceed—avoiding a blanket restriction that would undermine the programme’s open-source utility.
Gate the highest-risk functions. The most sensitive offensive capabilities are intended to be available only to verified users under “Cybersecurity Trusted Access,” creating a controlled-access layer even as broader defensive tools and community access are expanded.
Why the “Chinese Project Glasswing” comparison matters. Project Glasswing is Anthropic’s initiative to use frontier AI for securing critical software through early, controlled access. Researcher Gabriel Wagner’s comparison is therefore interpretive, not an official equivalence: Z.ai appears to share the defence-first ambition, but with a more explicitly open-source distribution model—treating transparency, community auditing, and widespread defensive access as security assets rather than liabilities.
The important caveat is that this is a company initiative and stated policy direction, not proof that China’s cybersecurity posture has already changed. Its credibility will depend on whether Z.ai’s access controls remain effective after broader model availability, whether audits lead to responsible disclosure and patching, and whether independent testing validates the claimed safety boundaries.