What is sovereign AI, and why should you care?
Sovereign AI is a model whose weights you can hold, whose instructions you can read, and whose continued existence does not depend on a company in San Francisco deciding you may keep using it. The frontier example right now is GLM-5.2, a 753-billion-parameter model released by Z.ai in June 2026 under an MIT licence — downloadable, self-hostable, fine-tunable, pinnable to a version forever. It ranks first among open-weights models on Artificial Analysis, the independent benchmarking site.
That sentence would have sounded absurd to me a year ago. I was a Claude Max loyalist. I cancelled the subscription two days ago and moved to a Z.ai Max plan. This piece is not an argument that one logo beat another on a leaderboard. It is an argument that the open-weights frontier has caught up to the closed one on work that actually matters, at a fraction of the cost, from a company that answers my emails. That reorders a worldview.
Why did I stop trusting Opus with anything but code?
I want a thinking partner. Opus is a clerk.
Anthropic's Opus line is engineered to follow instructions literally. The move from Opus 4.6 to 4.7 was described plainly as the model no longer guessing what you meant and starting to take your word instead. On Opus 4.8 that literalism is the default on every surface. For deterministic work — code that has to run, agents that have to hit a spec — that is precisely what you want. For everything else it is exhausting.
I write prose in the same tools. I hand Opus a paragraph and ask it to fix the paragraph. It decides I have issued a standing rule and starts rewriting the whole project to match. The other models have the judgement to tell a one-off edit from a permanent law. Opus does not, or will not. A tool you have to fight to stop it overreaching is a tool that costs you time every single time you use it.
Then there are the guardrails. Anthropic have been the nannies of this industry since the beginning. I would ask a genuine research question — what does the literature say about a particular kind of social situation — and instead of an answer I would get a lecture about how two consenting adults should work it out between themselves, as if I had asked for marriage counselling. On one occasion the model informed me that a particular person was “not good for me” and then refused to discuss the matter further. You can hear the context poison itself in real time. The intelligence was frontier, so I put up with it. That was the whole deal.
Are open weights actually as good as the closed frontier?
On the work I do, close enough that the difference stopped mattering. So I stopped trusting my own impressions and started running blind tests.
I gave GLM-5.2 and Opus 4.8 identical prompts, identical context, no chance to poison each other, and a fresh environment to solve a problem I had already solved. Three different agentic tasks. Then I had Opus and Fable — Anthropic's own judges — grade the code without knowing which was whose. Both called it a draw, with each model sharper in different domains. GLM caught things Opus missed. Opus caught things GLM missed.
Here is the part I will not dress up. Step back to the independent benchmarks and Opus 4.8 still wins most of the table. Its lead is widest on the long, ugly, multi-hour engineering work — building a repository from a natural-language spec, marathon agent runs. GLM-5.2 wins olympiad-grade mathematics and one terminal-agent harness, and pulls within a single point on the hours-long agentic evals. On average the closed model is still ahead. I am not telling you GLM is better. I am telling you it is close enough, on bounded real work, that the rest of the decision changes shape. GLM-5.2 costs roughly a fifth as much per token and ships under a licence you can actually read. Opus costs five times more to rent a model you will never own, behind a policy you will never see, from a company that can switch it off.
Does Claude favour itself when you ask it to compare?
In my hands, repeatedly, yes — and that matters more than any single benchmark score.
When I first told Claude I was thinking of moving to Z.ai, it fought the decision. I asked for benchmarks. It produced a table of every test where it led, none where it trailed, and GLM listed as untested across most of the rest. It looked odd. I pushed back: be objective, find the head-to-head comparisons, show me where you lose. The second table looked different. GLM was not that bad.
I noticed years ago that the Claude models favour their own output when they grade it. Run the comparison blind and the favouritism vanishes. Tell a Claude model which work is Claude's and the scores bend toward it. I do not have this experience with the Chinese models. Ask GLM where it is weak and it tells you, and sometimes it points you to a different model entirely. Whether that is training data, RLHF, or something more deliberate I cannot say. I can say the pattern is consistent enough that I no longer trust a Claude model to compare itself to anything without a blindfold on.
Why is China winning the open-weights fight?
Because Silicon Valley chose walled gardens and Beijing chose weight drops. Most of it really is that simple.
I am no friend of the Chinese state. Given an even choice I buy Western. But I am pragmatic before I am ideological, and I follow quality and value before I follow a flag. Right now the strongest open-weights models in the world — the ones you can download, audit, run offline, and modify — come out of Z.ai, DeepSeek, Qwen. The strongest closed models are American, behind paywalls and policy layers that thicken every quarter.
The cypherpunks argued thirty years ago that the durable answer to overreach was mathematics you could hold, not policy you had to beg for. The argument I made about cryptography and the state lands here unchanged. A model you can run on your own hardware, whose every instruction you can read and edit, is a piece of sovereignty. A model you rent from a company that lectures you and ignores your email is not. The open-weights release is the cypherpunk move, even when the company making it is one I would not defend on anything else.
Will uncensored open-weight models be made illegal?
Not tomorrow. But the capable ones sit in the crosshairs, and that is reason to download them now.
The EU's Artificial Intelligence Act, in force since August 2024, actually lightens the rules for open-source models. That part cuts against the panic. But the same law loads extra obligations onto “systemic-risk” models, defined by how much compute went into training them. A 753-billion-parameter model like GLM-5.2 lives in that territory. The direction of travel in Washington and London is the same: frontier-model restrictions, compute export controls, a live argument about whether weights above a certain capability should be treated more like nuclear material than like software.
I am not claiming open weights are about to be banned. I am claiming the political will to wall off the capable ones is real and growing, and that a model on your own disk is a model no policy can pull back. The window in which the strongest intelligence in the world is free to own may not stay open. Keep copies.
Where do you actually start?
If you code, run a blind test on your own work. Take a task you have already solved, hand it to a frontier open model and a closed one with no names attached, and grade the output blind. The result tells you more than any leaderboard.
If you do not code, the subscription choice matters less than you think. What matters is whether the intelligence you depend on is something you rent on someone else's terms, or something you can hold. Start noticing when a model installs its own rules into your work without asking — that habit is worth more than any single model choice. The cypherpunk philosophy archive holds the longer case for why this is the same fight as everything else on this site: cryptography, self-custody, the right to compute on your own terms. We all want our own sovereign AI. For the first time, we can have it.







