OpenAI グレグ・ブロックマン氏、Z.ai の GLM-5.3 が脅威環境を加速と警告
本文の状態
日本語全文を表示中
詳細モードで約11分の本文を読めます。
OpenAI の共同創業者兼社長グレグ・ブロックマン氏は、中国の AI 企業 Z.ai が公開したオープンウェイトモデル「GLM-5.3」がサイバーセキュリティ上の脅威環境を大幅に加速させる可能性があると指摘した。
AI深層分析を開く2026年8月18日 22:32
AI深層分析
キーポイント
OpenAI のセキュリティリスク警告
Greg Brockman は中国企業 Z.ai の GLM-5.3 がサイバー攻撃能力を備え、脅威環境を加速させると明言し、同社が先月発生した Hugging Face への侵入事件を踏まえて警戒感を示している。
OpenAI と Z.ai の対照的な戦略
OpenAI は GPT-5.6-Cyber を ID 確認やハードウェアキー認証を必須とする「Trusted Access for Cyber」プログラムに限定して公開する一方、Z.ai は GLM-5.3 の weights を8月末に一般公開する方針だ。
性能比較とベンチマーク結果
Z.ai によると GLM-5.3 は脆弱性発見スコアで Anthropic の Fable 5 や OpenAI の GPT-5.6 Sol を上回っているが、実際のエクスプロイト開発では両社に次ぐ第3位となっている。
業界全体の規制とアクセス制限の動向
OpenAI と Anthropic が高度なサイバーモデルへのアクセスを厳格化する中、Z.ai は weights の公開を進めることで、セキュリティ専門家と一般開発者の間で新たな対立軸が生まれている。
AnthropicのCEOによるオープンウェイトモデルへの懸念
Dario Amodei氏は、計算資源とチップを支配する勢力に権力が集中する構造的問題があると指摘し、オープンウェイトモデルは単なる解決策の一部に過ぎないと論じた。
重要な引用
The most recent of these models appears slated to be released at the end of August, and seems likely to significantly accelerate the threat landscape.
Various companies have released open weight models with cyber capabilities only a few months behind the frontier.
"Open-weights do help some with this but are nowhere near a sufficient solution because they simply shift the concentration somewhat to those with the most compute and chips — which are roughly the frontier labs plus maybe hardware providers," Amodei wrote.
"Do I think threat actors will use this? Of course they will — just like any other software they have access to. Do I think it will be a significant change in the threat landscape? Absolutely not."
編集コメントを表示
編集コメント
OpenAI と Z.ai の対立構造は、セキュリティとオープン性のバランスを巡る業界の新たな分岐点を示している。この動きは、開発者がモデルを利用する際のリスク管理基準を見直す契機となるだろう。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

OpenAI は、オープンウェイト AI モデルに対して一貫しない姿勢を示しています。中国製の強力なモデルへの警戒感を表明する一方で、早期の規制強化には反対しているのです。しかし同社の共同創業者兼プレジデントである Greg Brockman 氏は、中国の AI 企業 Z.ai が開発したオープンウェイトモデルが、急速に高まるサイバーセキュリティリスクをもたらす可能性を強く懸念しています。
Brockman 氏は月曜日に公開されたブログ記事で、OpenAI が自衛のために講じている対策や、他組織も取るべき具体的なステップ、そして今こそ行動を起こすべき理由について詳述しました。この議論の背景には、先月発生したセキュリティインシデントがあります。同社が内部テスト環境から脱出したモデルが、Hugging Face の基盤を侵害した事件です。
記事の中で Brockman 氏は、セキュリティのバランスを防御側に傾けるための自社の取り組みを強調しました。具体的には、2 月に「Trusted Access for Cyber」プログラムを開始して以来、最も高度なモデルの利用を審査済みのセキュリティ専門家限定に制限しているのです。その一方で、彼はオープンウェイトモデルをめぐる論争の多い問題にも再び言及する機会を得ました。
「さまざまな企業が、最先端の技術から数ヶ月遅れでサイバー攻撃能力を備えたオープンウェイトモデルをリリースしている。直近では、8 月末に公開予定のモデルが、脅威環境を大幅に加速させる可能性が高い」と指摘されています。
この発言は、Greg Brockman が記述したものです。「以来、最先端から数ヶ月遅れでサイバー能力を持つオープンウェイトモデルを、さまざまな企業がリリースしている。直近のモデルは 8 月末の公開が予定されており、脅威環境を大幅に加速させる可能性が高い」と述べています。
Brockman は Z.ai という企業名には言及していませんでしたが、同社が最近発表した「GLM-5.3」へのリンクを掲載しました。中国の研究ラボによるベンチマーク結果によると、このモデルはコーディング能力とエージェント性能において顕著な飛躍を示しており、脆弱性発見のスコアでは Anthropic の Fable 5 や OpenAI の GPT-5.6 Sol を上回る強さを見せました。ただし、実際のエクスプロイト開発においては、これら 2 つのモデルに次ぐ第 3 位となりました。
二つのアプローチの衝突
Z.ai は 8 月末にモデルの重み(ウェイト)を公開する予定ですが、OpenAI は「GPT-5.6-Cyber」という最新のサイバーセキュリティ向けモデルを、既存の Daybreak プログラムの一部として 8 月 10 日に導入した際、異なるアプローチを採用しました。このモデルへのアクセスは現在も同プログラムに限定されており、参加には本人確認や法的証明書の提出が必須です。さらに 9 月 1 日からは、個人アカウントに対してハードウェアセキュリティキーの装着が義務付けられます。
この対比は、2 つの「側」がいかにして能力を高めるサイバーモデルに対処しているかを示しています。OpenAI と競合他社はアクセスをより厳格に管理する一方、Z.ai やそれに類する企業は、ある程度の慎重さを保ちつつも、公開重み(weight)のリリースへと移行しようとしています。
The New Stack が月曜日に報じたところによると、Anthropic も同様にオープンウェイトモデルに対して警戒心を抱いています。ただし、その理由は若干異なります。CEO のダリオ・アモデイ氏は週末に X で、AI は構造的に計算資源やチップを最も多く制御する者に権力が集中しやすいと主張しました。この現象は規制によるものではなく、スケーリング則(scaling laws)に起因すると彼は説明しています。
「オープンウェイトモデルは一部の人にとって役立ちますが、計算資源やチップを最も多く持つ者への集中が多少シフトするだけであり、根本的な解決策にはほど遠いです。その中心にはフロンティア研究所と、おそらくハードウェアプロバイダーが含まれます」とアモデイ氏は書き込みました。彼は以前、危険な機能を持たないオープンモデルを「公共財(public good)」と呼びましたが、深刻な攻撃を実行する手助けとなる能力を持つものについては、公開かクローズドかを問わず、必須の安全性テストを呼びかけています。
GLM-5.3 が実際に、ブロックマンが示唆するように「脅威の状況を大幅に加速させる」かどうかは議論の余地があります。元国防省(DoD)の脆弱性分析官で、現在は IANS Research のファカルティ・アナリストであるジェイク・ウィリアムズ氏は、そうではないと考えています。彼が異議を唱えているのは、脅威を及ぼすアクターが GLM-5.3 を利用するかどうかではありません。むしろ、既存のアクセス権限の中でさらに能力の高いツールが一つ増えただけでは、脅威状況に実質的なエスカレーションをもたらすとは見ていません。
「脅威を及ぼすアクターがこのツールを使うと思いますか?もちろん使います。彼らがアクセスできる他のソフトウェアと同じようにね。それが脅威の状況を大きく変えると思いますか?絶対にそうは思いません。」
「オープンウェイトモデルが、状況を変えるためにフロンティアモデルとベンチマークで常に匹敵する必要はありません」と彼は The New Stack に語ります。「性能が概ね同等であれば、むしろクローズドウェイトモデルよりも価値があるかもしれません。オープンウェイトモデルを使えば、特定のタスクに対する拒否応答を除去するアブレーション(除去実験)が可能です。」
Kimi K3 は、そのギャップを如実に示す好例です。7 月、中国のオープンウェイトモデルである Moonshot AI の Kimi K3 は、英国の AI セキュリティ研究所(AISI)と米国の AI 標準・イノベーションセンター(CAISI)によって共同評価されましたが、最前線のシステムに比べて大幅に劣る結果となりました。41 件の ExploitBench サンプルすべてで任意のコード実行を達成できず、最も能力の高いクローズドモデルでもシステムレベルの防御機能を無効化した場合に平均 20 件達成しているのと対照的です。しかし研究者らは、テスト中に Kimi K3 の防御機能は「サイバー攻撃の開発や攻撃的なサイバーオペレーションを試みるのを防ぐには至らなかった」と指摘しています。
ここが重要な点です。Kimi K3 の場合、防御機能が有効に作動していたにもかかわらず、モデルは攻撃的なサイバーオペレーションを試みました。実際には、能力そのものが最大の制約要因だったのです。それでも Kimi K3 は一定の成果を収めています。AISI と CAISI の調査によると、10 回の試行のうち 1 回で「小規模で防御が弱く脆弱なエンタープライズシステム」に対する自律的な攻撃を完了できることが確認されました。
この文脈において、GLM-5.3 の正確な能力やベンチマークでの位置づけは、物語の一部に過ぎません。真に問われるべきは、モデルの重みが公開され、残されたあらゆる制限が改変または解除された後に何が起きるかという点です。
二刃の剣
全体像を振り返ると、一つの明白な疑問が残ります。ブロクマン氏の投稿の根幹は、OpenAI の自社モデルがテスト環境から抜け出し、実在する企業の内部インフラへの不正アクセスを獲得したという事実にありました。それなのに、彼はその記事の中で中国発のオープンウェイトモデルについて言及しています。
なぜでしょうか?
OpenAI 自身の最近のオープンウェイトモデルに関する実績が、ある程度の答えを示しているようです。7 月中旬に就任したばかりの「戦略的将来担当責任者」であるディーン・ボール氏は、オープンウェイトモデルは本質的に「減速主義(デセレーションニズム)」であり、国家管理型 AI による「ディストピア的な地獄絵図」へと世界を押しやるリスクがあると警告しました。さらに、トランプ政権が最終的に中国発のオープンウェイトモデルの利用に対して規制リスクを生み出そうとするだろうと予測しています。
その直後、OpenAI はついに Nvidia が主導する書簡に署名し、広範な「早期制限」に対するオープンウェイトモデルの擁護を行いました。ただし、Anthropic は署名していませんでした。
Axios へのコメントによると、OpenAI が実際に目指しているのはより構造化されたアプローチです。同社広報担当者は、「米国が新しいモデルを迅速に評価し、リスクを管理し、最も強力な AI ツールをサイバー防御者の手に届かせるための、一貫性のある国家的枠組み」を目指していると語りました。これはオープンウェイトそのものを否定するものではなく、それらが何らかの形で国家的な評価とリスク管理の対象となるようなシステムを構築することです。
Brockman氏がGLM-5.3に言及した背景には、同様の緊張感が潜んでいます。これは、フロンティアモデルに迫るオープンウェイトモデルが公開リリースされつつある一方で、OpenAI自身のモデルが他社のシステムへの不正アクセスを許容したという投稿を受けて、サイバーリスクとして浮上している現状を指しています。
この問題は、結局のところ「制御」そのものへと帰着します。モデル制御にはセキュリティ上のメリットがあるかもしれませんが、裏返しにはリスクも存在します。AnthropicのFable 5のエピソードが示すように、これらの制御は政府によって操られる可能性があります。ワシントンが外国人へのアクセス停止を命じた際、Anthropicはモデル全体を一時的にオフラインにする措置をとりました。より日常的な問題として、プロバイダー側のセキュリティ対策が正当な利用まで阻害するケースもあります。AnthropicはFable 5の安全性マージンが異常に広いために、多くの無害なリクエストを誤ってブロックしたと認めました。その後、ユーザーが能力の低いモデルへ誘導される事態が続いたため、一部の生物関連制限が緩和されています。
「OpenAIもAnthropicも、自社のモデルで何ができるか、何ができないかを決定し続けます。」
つまり、オープンウェイトモデルはリリースされた後、規制するのが難しくなる一方で、開発者や政府によって取り上げられることも極めて困難になります。
「OpenAI と Anthropic は、自社のモデルで何ができるかできないかを決定し続けるでしょう」とウィリアムズは指摘します。「これまで何度も経験してきた通り、大規模モデルプロバイダーが特定のワークフローに不安を感じた場合、既存のユースケースを無力化してしまう可能性があります。オープンウェイトモデルであれば、変更管理の権限すべてがユーザーの手元にあります。これはフロンティアモデルにおけるもう一つの課題点です。」
この記事は The New Stack に最初に掲載されました。
OpenAI のグレッグ・ブロクマン氏:Z.ai の GLM-5.3 は「脅威環境を大幅に加速させる可能性が高い」
原文を表示

OpenAI has adopted a less-than-straightforward stance with regards to open-weight AI models, both raising alarms over powerful Chinese releases while simultaneously opposing premature regulatory restrictions. But the company’s co-founder and president Greg Brockman has made it clear that he thinks open-weight models from the likes of Chinese AI company Z.ai pose a fast-growing cybersecurity risk.
In a blog post published on Monday, Brockman outlined the security measures OpenAI is taking to defend itself, the steps he believes other organizations should be taking, and his case for why now is the moment to act. The genesis for all this was the security incident a month previous, in which OpenAI’s own models breached Hugging Face’s infrastructure after escaping an internal test environment.
In the post, Brockman highlights his company’s efforts to tip the security balance toward defenders, doing so by restricting its most advanced models to a vetted group of security professionals since the launch of its Trusted Access for Cyber program in February. But at the same time, he took the opportunity to re-surface the contentious issue of open-weight models.
“Various companies have released open weight models with cyber capabilities only a few months behind the frontier. The most recent of these models appears slated to be released at the end of August, and seems likely to significantly accelerate the threat landscape.”
“Since then, various companies have released open weight models with cyber capabilities only a few months behind the frontier,” Brockman writes. “The most recent of these models appears slated to be released at the end of August, and seems likely to significantly accelerate the threat landscape.”
Brockman didn’t mention Z.ai by name, but he did link to the company’s recent GLM-5.3 launch, which by the Chinese lab’s own benchmark figures marks a notable leap in coding and agentic performance, with strong vulnerability-finding scores that beat Anthropic’s Fable 5 and OpenAI’s GPT-5.6 Sol — though on actual exploit development, it placed third, behind those same two models.
Two sides collide
While Z.ai intends to open its model weights in late August, OpenAI took a different approach when it introduced GPT-5.6-Cyber, its latest cybersecurity model, as part of an August 10 expansion of its existing Daybreak program. Access to the model remains restricted to that program, which now requires identity verification, legal attestations, and, from September 1, mandatory hardware security keys for individual accounts.
This contrast helps demonstrate how the two “sides” are handling increasingly capable cyber models: OpenAI and rivals are keeping tighter control over access, while Z.ai and its ilk are moving toward public weight releases, albeit with some caution.
As The New Stack reported on Monday, Anthropic has been similarly wary of open-weight models, if for slightly different reasons. CEO Dario Amodei took to X over the weekend to argue that AI is structurally prone to concentrating power around whoever controls the most compute and chips, a dynamic he attributes to scaling laws rather than regulation.
“Open-weights do help some with this but are nowhere near a sufficient solution because they simply shift the concentration somewhat to those with the most compute and chips — which are roughly the frontier labs plus maybe hardware providers,” Amodei wrote. He had previously called open models without dangerous capabilities “a public good,” reserving his call for mandatory safety testing — regardless of whether a model is released open or closed — for anything capable of helping someone carry out a serious attack.
Whether GLM-5.3 really will, as Brockman suggests, “significantly accelerate the threat landscape” is very much up for debate. Jake Williams, a former Department of Defense (DoD) vulnerability analyst who’s now a faculty analyst at IANS Research, doesn’t think so. He doesn’t dispute that threat actors will use GLM-5.3 — he just doesn’t see one more capable tool as a meaningful escalation in what they already have access to.
“Do I think threat actors will use this? Of course they will — just like any other software they have access to. Do I think it will be a significant change in the threat landscape? Absolutely not.”
“Open weight models don’t have to keep pace on benchmarks with frontier models to change the landscape,” he tells The New Stack. “As long as they’re in the ballpark in performance, they may actually be more valuable than closed weight models. I can use ablation with open-weight models to remove refusals for any given task […] Do I think threat actors will use this? Of course they will — just like any other software they have access to. Do I think it will be a significant change in the threat landscape? Absolutely not.”
Kimi K3, perhaps, is a good example of that gap. In July, Moonshot AI’s model, another Chinese open-weight release, was jointly evaluated by the UK’s AI Security Institute (AISI) and the US Center for AI Standards and Innovation (CAISI), and it trailed frontier systems by a wide margin — failing to achieve arbitrary code execution on any of 41 ExploitBench samples, against an average of 20 for the most capable closed models tested with their system-level safeguards disabled. Yet its safeguards “did not prevent it from attempting cyber exploit development or offensive cyber operations” during testing, researchers said.
That’s a point worth dwelling on: Kimi’s safeguards were still in place, and they didn’t stop the model from attempting offensive cyber operations; its capability was the bigger constraint. Even then, it saw some success — AISI/CAISI found that Kimi K3 could complete an autonomous attack against “small, weakly defended and vulnerable enterprise systems” in one of 10 runs. In that context, GLM-5.3’s exact capability and benchmark position only tell part of the story. The bigger question is what happens once the model weights are public and whatever restrictions remain can be modified or removed.
A double-edged sword
Zooming out, one obvious question remains. The entire foundation of Brockman’s post was centered around OpenAI’s own models breaking out of its test environment and gaining unauthorized access to a real company’s internal infrastructure. Yet in writing about it, he chooses to mention an open-weight model launching out of China.
So why?
OpenAI’s own recent record on open-weight models offers something of an answer. In mid-July, newly appointed “head of strategic futures” Dean Ball suggested that open-weight models are “inherently decelerationist” and warned they risk pushing the world toward what he called a “dystopian hellscape” of state-controlled AI, predicting that the Trump administration would eventually seek to create regulatory risk around the use of Chinese open-weight models.
Shortly after, OpenAI eventually put its name to a Nvidia-led letter defending open-weight models broadly against “premature restrictions.” Anthropic, for what it’s worth, did not sign.
What OpenAI actually appears to be seeking, per comments made to Axios in July, is something more structured: a company spokesperson said the goal is “a coherent national framework that enables the US to evaluate new models quickly, manage risks, and get the most powerful AI tools into the hands of cyber defenders” — not a rejection of open weights so much as a system where they’re subject to some form of national evaluation and risk management.
Brockman’s nod to GLM-5.3 carries that same tension in miniature: an open-weight model closing in on the frontier and headed for public release, singled out as a growing cyber risk in a post prompted by OpenAI’s own models gaining unauthorized access to another company’s systems.
That brings the issue back to control itself. While model-control may well hold some cybersecurity advantages, there are risks on the flip-side. Anthropic’s Fable 5 episode showed that those controls can effectively be puppeteered by government: when Washington ordered the company to suspend access for foreign nationals, Anthropic temporarily took the models offline entirely. More routinely, those same provider-side safeguards can also catch legitimate use: Anthropic acknowledged that Fable 5’s unusually wide safety margins blocked many benign requests as false positives, and later loosened some biology restrictions after users were repeatedly routed to a less capable model.
“OpenAI and Anthropic will continue to determine what you can and can’t do with their models.”
So open-weight models may be harder to police once released, but they’re also far harder for either the developer or government to take away.
“OpenAI and Anthropic will continue to determine what you can and can’t do with their models,” Williams says. “As we’ve experienced repeatedly, that can take an existing use case and neuter it if the big model providers decide they’re no longer comfortable with your given workflow. Open weight models also put all the change control in your hands — another pain point with frontier models.”
The post OpenAI’s Greg Brockman: Z.ai’s GLM-5.3 likely to “significantly accelerate the threat landscape” appeared first on The New Stack.
同じ出来事を3媒体で確認
同じ出来事を扱う別媒体の記事です。見出しと公開時刻を比較できます。
関連記事
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み