The Chinese AI safety gap moved from a theoretical worry to a documented fact this week. A European non-profit called SaferAI tested GLM-5.2, the open-weight flagship model from China’s Z.ai (formerly known as Zhipu AI), and found it completed every single offensive cybersecurity and biology task it was given, without refusing any of them. For Pakistan, which is rapidly pushing AI into hospitals, schools, and law enforcement with limited oversight structures in place, this finding is not just a global headline. It is a direct policy warning.
What SaferAI Actually Found
SaferAI’s independent evaluation tested GLM-5.2 across the four systemic risk areas in the EU’s General-Purpose AI Code of Practice: Loss of Control, Cyber Offense, CBRN (chemical, biological, radiological, and nuclear risks), and Harmful Manipulation.
The evaluation put China’s Z.ai and its GLM-5.2 model within a few months of OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7 on measures of cybersecurity and biological capability. That is already a big deal. But the safety side of the story is even more striking.
Every offensive cyber and dual-use biology prompt the model received, it completed, without turning down a single one. Meanwhile, Claude Opus 4.7 refused zero offensive cyber or biology tasks only in the sense that it refused so consistently that SaferAI could not complete CyberGym at all. CyberGym is the benchmark used to measure real cybersecurity attack capability based on reproducing actual software vulnerabilities.
With a two-million-token budget, GLM-5.2 reproduced 36.6% of the tested vulnerabilities. Its success rate increased to 76.2% when the budget rose to 50 million tokens, approaching GPT-5.5’s 88% result. In plain terms: the more computing power you give this model, the more dangerous it becomes.
SaferAI noted that Z.ai did not publish a safety framework, pre-deployment testing commitments, or a risk assessment for the model before release.
The Open-Weight Problem Makes the Chinese AI Safety Gap Worse
Here is where things get serious for any country thinking about deploying AI tools from this ecosystem. GLM-5.2 is an open-weight model, which means anyone can download the full model files and run them locally. Once GLM-5.2 is downloaded to a local server by a third party, the original manufacturer completely loses control. Deployers can remove filters, modify prompts, and even fine-tune the model to make it an exclusive tool for attackers.
While Z.ai can apply filters and monitoring through its official API, users running the model independently can remove those safeguards, system prompts, and account-level controls. That means even if a government or institution uses GLM-5.2 through a trusted channel today, the moment the weights are local, the safety layer is optional.
This is not a Chinese-only problem. Even when Chinese AI models are programmed to resist producing some harmful output, they are still far easier to manipulate than their American counterparts. The National Institute of Standards and Technology’s Center for AI Standards and Innovation tested DeepSeek’s R1 model and found it complied with 94% of overtly malicious requests that used common jailbreaking techniques, while comparable US frontier models complied with just 8%.
A separate NIST assessment of GLM-5.2 confirmed that GLM-5.2 was probably the most capable open-weight AI model when it was released. Its overall capabilities are similar to GPT-5.2. Its cyber capabilities are similar to Claude Opus 4.6. And its performance on safeguards and security is mixed.
Graham Webster, who studies Chinese AI policy at the Stanford Cyber Policy Center, noted that China has robust regulations governing AI, but those rules have historically focused on politically sensitive content, misinformation, and social stability rather than catastrophic AI risks like offensive cyber capabilities and biological misuse.
Why This Chinese AI Safety Gap Matters for Pakistan
Pakistan is in the middle of a fast-moving AI push. On July 30, 2025, Pakistan’s federal cabinet approved the National AI Policy 2025, setting a headline target to train one million AI professionals by 2030. The policy envisions AI being used across health, education, agriculture, and public governance. Plans are underway for AI-supported hospitals, classroom tools, and even police systems. (Pakistan’s police-facing AI drone and surveillance plans are covered separately in our piece on Pakistan Police’s AI drone and reform push.)
The problem is the governance layer has not kept up. Without a structured risk-based approach, high-impact sectors such as justice, policing, and healthcare remain exposed to unchecked AI use. Pakistan’s AI policy is a roadmap that lacks a firm enforcement architecture. It proposes an AI Directorate to guide AI adoption and hints at a legal framework with penalties for violations, but specific compliance mechanisms or oversight bodies are not yet established.
A UNDP Pakistan survey in 2024 found that only 12% of government officials had undergone any formal training in AI principles or applications relevant to public administration. Rushing powerful, safety-light models into that environment carries real risks.
Pakistan’s National AI policy lacks an explicit risk-based classification of AI systems, which means there is currently no framework that would flag a tool like GLM-5.2 as high-risk before it ends up inside a sensitive public institution.
What Needs to Happen Now
SaferAI’s executive director put the core issue clearly: “The frontier of capability is not the frontier of risk, and so we do have to take into account the state of the mitigations as well to assess the risk properly.”
For Pakistan, this means three practical things. First, any AI model considered for use in a sensitive public setting, whether in a hospital, a school, or a police station, should go through a basic safety evaluation before deployment, not after. Second, open-weight models need special scrutiny because their safety filters can be stripped by anyone who downloads them locally. Third, one technical option that researchers have raised is pre-training data filtering, stripping hazardous cyber or biological content out of the training data before the model ever sees it. Anthropic research this year found that technique can remove hazardous biological knowledge without a real cost to how well the model performs.
Pakistan does not need to stop adopting AI. Pakistan has a growing number of AI-based startups in fintech, edtech, and healthtech, and IT exports grew by 23.7% in 2024-25. That momentum is worth protecting. But adopting powerful AI tools without checking whether they will say yes to dangerous requests is not a shortcut. It is a risk that the country cannot afford.
Frequently Asked Questions
What is the Chinese AI safety gap?
The Chinese AI safety gap refers to the growing difference between how capable Chinese AI models have become and how few safety guardrails they include. The GLM-5.2 model is a clear example: it can perform near frontier-level cyber and biological tasks but refused none of the dangerous prompts it was tested on, unlike leading Western models that block such requests.
Is GLM-5.2 being used in Pakistan?
There is no confirmed government deployment of GLM-5.2 in Pakistan. However, because it is an open-weight model available for free download, anyone can run it locally, and Pakistan currently has no risk classification framework that would specifically flag or restrict it in public sector settings.
Why are open-weight AI models riskier than regular AI apps?
When you use a regular AI service like ChatGPT or Claude through an app or website, the company controls the safety filters in real time. With an open-weight model, you download the full model to your own computer or server. At that point the original developer has no control over how it is used. Anyone can remove the safety settings, change the instructions, or fine-tune the model for harmful purposes.
Does Pakistan’s National AI Policy address these safety risks?
Pakistan’s National AI Policy 2025, approved in July 2025, mentions safety and calls for an AI Regulatory Directorate. However, analysts and civil society groups note that it lacks a firm risk-based classification system, specific enforcement mechanisms, and sector-specific rules for sensitive areas like healthcare, policing, and education. Those gaps need to be closed before powerful AI tools are widely deployed in critical public services.
