China's GLM-5.2 AI model is winning over US firms, Sridhar Vembu explains why
Chinese AI model GLM-5.2 is rapidly gaining attention beyond its home market, with major US technology companies beginning to adopt it for enterprise use. Zoho co-founder Sridhar Vembu says the shift is being driven by economics, flexibility and open-source development, but experts also warn that the model introduces new cybersecurity concerns.

American technology companies are increasingly turning to Chinese artificial intelligence models, a trend that would have seemed unlikely just a year ago. At the centre of the conversation is GLM-5.2, an open-weight AI model from Chinese startup Z.ai that has quickly become one of the most talked-about alternatives to leading US models.
The discussion gathered fresh momentum after Zoho co-founder Sridhar Vembu highlighted the growing interest among major American software firms. In a post on X, Vembu pointed to recent industry developments, arguing that companies are embracing Chinese open-source AI not because of geopolitics, but because it offers a compelling mix of lower costs, strong performance and the freedom to run models on their own infrastructure.
The comments come as enterprises rethink how they deploy AI, balancing performance against rising inference costs, data privacy and dependence on cloud providers.
Vembu explains why American companies are embracing Chinese AI model GLM-5.2
According to Vembu, the industry's priorities are changing. Referring to Databricks' decision to embrace GLM-5.2 and Microsoft's earlier interest in DeepSeek, he argued that American software companies are increasingly looking towards Chinese open-source models as a way to reduce token costs while retaining greater control over their AI deployments.
"I have long advocated using the Chinese models running in one's own infrastructure," Vembu wrote.
Unlike proprietary AI services that process requests through company-operated servers, GLM-5.2 can be downloaded and deployed locally. This allows organisations to keep sensitive data within their own environments while avoiding recurring API costs associated with commercial AI platforms.
Vembu added that Zoho has already adopted a similar strategy internally, using smaller, organisation-specific AI models in production. As building customised AI systems becomes easier, he believes more enterprises will train their own domain-specific models rather than relying entirely on large, closed commercial offerings.
That approach reflects a broader shift taking place across enterprise AI. Businesses increasingly want models they can fine-tune, audit and integrate directly into existing software stacks without sending proprietary information to third-party providers.
GLM-5.2 appears well positioned to benefit from that demand. Released under the permissive MIT licence, the model is freely downloadable and can run entirely on private hardware. Early benchmarks suggest it is also highly competitive. On agentic coding tasks involving large software repositories and long-horizon reasoning, it reportedly outperforms GPT-5.5 and comes close to Anthropic's Claude Opus 4.8, while costing roughly one-sixth as much through APIs.
For companies building AI-powered developer tools or software assistants, those economics are difficult to ignore.
GLM-5.2: An open-source threat
The same qualities making GLM-5.2 attractive to enterprises are also raising concerns among cybersecurity experts.
Because the model is open-weight, there is no central provider monitoring how it is being used. Once downloaded, organisations and individuals can run it entirely offline, leaving no provider-side logs or oversight. That challenges the governance model that has largely shaped US AI regulation, where cloud-based providers can monitor, restrict or intervene when misuse is detected.
Security researchers have also found the model to be remarkably capable in cybersecurity tasks. Independent evaluations suggest GLM-5.2 performs on par with some of America's most advanced AI systems when identifying software vulnerabilities. Semgrep reported that it outperformed Claude on an insecure direct object reference (IDOR) detection task while achieving significantly lower costs per vulnerability identified. Another evaluation by Graphistry described it as the first open-weight model suitable for frontier-level cybersecurity work.
The implications extend beyond defensive security. Reports have already emerged of hackers discussing jailbreak techniques for GLM-5.2 on Russian-language forums, while one researcher claimed the model could chain exploits in a manner resembling an experienced human attacker.
Anthropic CEO Dario Amodei warned earlier this year that advanced AI systems had already uncovered tens of thousands of software vulnerabilities, giving defenders only a limited window to patch them before such capabilities became widely accessible. The emergence of GLM-5.2 suggests that window may be narrowing.
For enterprises, however, the calculation is becoming increasingly straightforward. Lower costs, competitive performance and full deployment control make Chinese open-source AI difficult to ignore. The challenge now is ensuring that the same technology accelerating software development does not also make sophisticated cyberattacks easier to execute.

Google burns cash for first time as AI spending pushes 2026 capex to $205 billion
Tesla sells more cars but makes less money: Why Musk’s AI pivot is squeezing profits
OpenAI launches Presence to bring AI agents into customer support and enterprise workflows
Samsung Galaxy Fold 8 Ultra, Fold 8, Flip 8 launched: Here is how much it costs in India with discounts
Florida pastor sues OpenAI, says ChatGPT's medical advice delayed emergency treatment: Report
