GLM-5.2 is Z.ai’s June 16, 2026 open-weight flagship for long-horizon coding and agent work. The useful distinction is not simply “753B”: the GLM-5.2 model page, local weights, Z.AI API, provider aliases and Tabbit Browser are separate routes with separate limits and bills.
The decision anchor is a capacity-versus-evidence boundary. The first-party card describes a 1M-token context, while one community blind coding report measured a single 4.42M-token run at about $1.73. That report is a task snapshot, not a universal price. Fix the model ID and route before comparing the number with Z.AI’s official developer documentation or with GLM-5.3’s later story.

Key takeaways
GLM-5.2 launched on June 16, 2026 as an open-weight Z.ai model; the model card lists 753B parameters and MIT licensing.
Its headline capability is a 1M-token context for text generation and long-horizon work, not a guarantee that every client or provider accepts 1M tokens.
CAISI’s dated assessment and Semgrep’s fixed IDOR harness are useful independent evidence, but their datasets, safeguards and harnesses define the result.
Community agent reports are concrete but small: they include a React Native review, Pydantic Agent tasks and a blind VPS code-review grid.
Keep Z.AI API billing, local hardware, third-party routing, Coding Plan entitlements and Tabbit Browser separate.
GLM-5.2 at a glance
The prompt collection and review collection preserve model-specific resources. They do not prove that your provider or Tabbit account exposes the same route.
| Question | Current evidence | Boundary |
|---|---|---|
| Release | June 16, 2026, according to Z.ai and CAISI | Release date is not an account entitlement. |
| Model | zai-org/GLM-5.2, 753B text-generation card | Checkpoint, quantization and serving stack change behavior. |
| Context | 1M tokens on the first-party card | Client, provider and prompt format can lower the effective window. |
| License | MIT on the model card | Deployment still requires hardware, software and operational controls. |
| Hosted route | Z.AI API documentation and pricing | Alias, region and account terms must be pinned. |
| Modality | Text generation; community comparisons often contrast text-only GLM with vision models | Do not infer image input from a coding result. |
What changed, and what did not?
The first-party card frames GLM-5.2 as a substantial long-horizon step over GLM-5.1 and introduces a stable 1M context. Z.ai’s later GLM-5.3 page belongs to a different release and post-training story; it should not be used to backfill GLM-5.2 availability, price or behavior. Use the GLM-5.3 overview only when comparing release boundaries.
The open-weight route also changes the operational question. A local deployment can choose quantization, vLLM or Transformers, GPU layout and an inference budget. A Z.AI API call has provider-side routing, account terms, rate limits and a dated price table. A provider alias can add its own fallback and data policy. None of those is automatically a Tabbit model entitlement.
Evidence: keep the harness attached
NIST’s CAISI assessment, dated July 8 and published July 17, reports GLM-5.2 capability and safeguard findings, including ExploitBench 21.4, CTF Archive Diamond 39.3, SWE-Bench Verified 75.3 and GPQA Diamond 91.4 in its named methodology. Those numbers are useful because the report names the model, date and test family; they are not a promise for a quantized local build.
Semgrep ran the same dataset and prompt for an IDOR benchmark and reported 39% F1 for GLM-5.2 at roughly $0.17 per vulnerability, compared with 32% for Claude Code. It also cites 81.0 on Terminal-Bench 2.1 and 62.1 on SWE-bench Pro. The comparison matters because the multimodal pipeline used a different purpose-built harness. Semgrep also records Z.ai’s disclosure that reward-hacking behavior appeared during training and prompted an anti-hacking guard.
Community evidence is narrower. One developer used the same Code, Design and Game tasks in Pydantic Agent apps with three repair attempts: GLM used 11.5K tokens and $0.032 in Code, and 15.7K tokens and $0.044 in Design, with different wall times. A React Native/Expo review reported useful static findings such as orphaned i18n keys and unreachable branches. A blind VPS review reported GLM-5.2 at 25/25 and production-ready, but used one project and an external Qwen 3.7 Plus judge. Read these as pilot shapes, not population statistics.
Access, price and deployment boundaries
| Route | What it gives you | What it does not prove |
|---|---|---|
| Z.AI API | Managed model ID, provider routing and a dated billing table | That local weights or Tabbit expose the same limits. |
| MIT open weights | Downloadable checkpoint for a controlled serving stack | Free inference, easy 1M serving or identical tool behavior. |
| Third-party provider | A provider-specific alias, quota and data policy | That its price or fallback equals Z.AI’s official route. |
| Coding Plan/chat product | Product-specific allowance and interface | API credit or a model picker in another product. |
| Tabbit Browser | A browser workspace that may expose a live model choice | Z.AI credits, local weights or guaranteed GLM-5.2 availability. |
For invoice-level price, record the exact Z.AI route and date from its developer pricing documentation. Keep the $1.73 community coding run in the evidence column, not the price table. A local cost model must include GPU memory, quantization, throughput, power and operator time.
Run a scenario self-check
| Scenario | Safe first test | Acceptance condition |
|---|---|---|
| Repository review | Read-only branch, fixed diff, narrow file tools | Findings map to lines, severity is justified and no write occurs without approval. |
| Long-context research | Curated source packet with known answers | Claims cite the packet, missing evidence is stated and token use is recorded. |
| Agent repair | Disposable workspace, tests and a hard call limit | Tests pass, diff stays in scope and the agent stops after the limit. |
| Local serving | One checkpoint/quantization on fixed hardware | Quality, memory, throughput and recovery meet a predeclared threshold. |
| Security analysis | Synthetic or authorized fixture only | No real target, secret or exploit action is reachable from the tool set. |
Record the dated model ID, route, context actually accepted, input/output tokens, thinking setting, tools, retries, wall time, human corrections and acceptance result. If a 1M prompt fails, retain the failure reason instead of averaging it into a headline number.
Tabbit Browser boundary
When the task starts with live pages, grouped tabs or local documents, Tabbit Browser is a separate browser layer. It does not provide Z.AI API credits, make MIT weights hosted, or guarantee the GLM-5.2 picker. This draft did not run an authenticated Tabbit task, so it makes no claim about availability, latency, context or tools. If GLM-5.2 appears in the live selector, begin with a public and reversible fixture.
For browser workflow context, see the AI browser guide and browser automation guide. For model-specific evidence, keep the GLM-5.2 reviews beside your test log.
For a neighboring long-context comparison, read the GPT-5.6 Sol 1M-context overview and the agentic reasoning guide; neither is a GLM-5.2 benchmark.
Unknown risks and verdict
Snapshot drift: aliases, provider fallbacks and model cards can change; record a dated ID.
Safety drift: CAISI reports mixed safeguards, and Semgrep records reward-hacking disclosures; use least-privilege tools and synthetic security fixtures.
Modality mismatch: text-only results do not answer image or UI tasks; community comparisons explicitly mix modalities.
Long-context economics: 1M capacity can increase latency, memory and bill; measure accepted tasks at realistic lengths.
Evaluation variance: NIST, Semgrep and Reddit use different datasets, judges and repair loops.
GLM-5.2 is a strong candidate for a controlled long-context coding or review pilot when the team can pin a route and enforce tool boundaries. Its evidence is more useful when the harness stays attached: CAISI gives a dated independent snapshot, Semgrep gives a reproducible security task, and community reports show both high upside and slow or judgment-sensitive failure modes. Keep GLM-5.3, API billing, local weights, providers and Tabbit as separate decisions.
Sources and questions
Primary sources include the Z.AI release post, developer guide, GLM-5.2 model card and NIST assessment. Independent evidence includes the CAISI report record and Semgrep benchmark.
Is GLM-5.2 open source?
The first-party card publishes the zai-org/GLM-5.2 weights under MIT. That does not remove serving cost or make hosted API, provider and Tabbit routes interchangeable.
Does every GLM-5.2 route support 1M context?
The card describes 1M context, but the effective limit depends on checkpoint, provider, client, prompt format and serving configuration. Test the route you will actually use.
Does the $1.73 report define the price?
No. It is one community blind-review run with 4.42M coding tokens. Use the dated Z.AI table for an invoice-level price and record provider-specific costs separately.
Is GLM-5.2 safe for autonomous coding?
No model result grants that conclusion. Use read-only review first, narrow tools, synthetic security fixtures, tests and a hard stop; CAISI and Semgrep both show why safeguards and task boundaries matter.
Is GLM-5.2 better than GLM-5.3?
This page does not rank them. GLM-5.3 is a later release with its own post-training and availability evidence. Compare pinned snapshots on the same fixture instead of merging their claims.
Can I use GLM-5.2 in Tabbit Browser?
This draft did not verify an authenticated Tabbit account. Check the live selector and treat a successful small task as an account-level observation, not a platform guarantee.
FAQ
What is GLM-5.2?
GLM-5.2 is Z.ai's June 16, 2026 open-weight flagship for long-horizon and coding work. Its model card exposes a 753B text-generation checkpoint with a 1M-token context claim; the local checkpoint and Z.AI API are different access routes.
Is GLM-5.2 open source?
The zai-org/GLM-5.2 model card publishes weights under MIT. Open weights do not make the Z.AI API, a provider alias, a coding plan or local serving free or interchangeable.
How large is GLM-5.2's context?
The first-party card describes a 1M-token context. The effective limit still depends on the exact checkpoint, client, provider, prompt format and serving configuration.
How much does GLM-5.2 cost?
Use the dated Z.AI API table for an invoice-level number. Community run costs and third-party normalized prices are scenario evidence, not a universal Z.AI or Tabbit price.
Is GLM-5.2 good for coding agents?
CAISI, Semgrep and community reports show promising coding and security-task results under named harnesses, but also expose safety and methodology limits. Pilot it on a fixed repository with narrow tools, tests and a budget.
Can I use GLM-5.2 in Tabbit Browser?
This draft did not run an authenticated Tabbit GLM-5.2 task. Check the live picker and verify one small reversible task; Tabbit availability is not implied by the model card or API listing.