- AWS added Z.ai's GLM 5.3 to Bedrock for eligible enterprise customers and demonstrated it with Strix, an open-source AI security-testing agent.
- Z.ai's cyber security claim comes without test results in AWS's post. With agent-led testing, control over scope rests with whoever launches the agent.
- Leaders should ask who can launch such agents, whether written permission is recorded, where inference runs, and whether credentials are short-lived.
Security testing used to be something you hired. A consultancy sent people, ran its tools, and handed you a report. A new AWS announcement shows the other model: an AI agent you run yourself, on a model you rent by the token. The tool is easier to start. The decision about who may point it at what does not get easier.
What AWS announced
AWS published a post on October 5, 2026 that lists GLM 5.3 on Amazon Bedrock, its hosted service for AI models. The model comes from Z.ai, also known as Zhipu AI. Access goes to eligible enterprise customers. AWS describes it as a mixture-of-experts model with 753 billion parameters, tuned for coding and long agentic tasks.
The developer, Z.ai, claims the model has notable cyber security strengths. AWS repeats that claim. The post, as provided, gives no independent test results. The list of gains over the earlier GLM 5 is cut off in the text we reviewed.
How it works
A mixture-of-experts model splits its parameters into specialist groups. Only some of them work on any one request. That is how a very large model can still be practical to serve.
Bedrock hosts it, so the customer runs no inference servers. AWS lists cross-Region inference among the features. Developers can call the model through OpenAI-compatible APIs, which AWS recommends for new applications. Code that already uses OpenAI-style APIs may port more easily.
Cost is handled by prompt caching. Long coding jobs resend the same context each turn: instructions, tool definitions, repository files. Implicit caching is on by default and cuts latency and input cost for repeated prefixes. Explicit caching lets the developer mark which prefixes to reuse, which AWS says can raise the hit rate.
The demo is the story
AWS picked a security task to show the model off. Its walkthrough features Strix, an open-source tool that uses AI to attack software the way a penetration tester would. Strix runs the target code, looks for vulnerabilities and tests each one.
Strix launches several helper agents that chart which parts of an app are exposed. It then tries to prove each suspected flaw with a working exploit. AWS says this proof step cuts the time wasted on false alarms. The demo target is OWASP Juice Shop, an app built to be vulnerable and run locally.
AWS notes that Strix's own documentation currently selects GLM 5.3 as its default model. Strix can instead be set to use Bedrock rather than an outside inference provider. In that setup, AWS says, inference runs "under your AWS account's controls."
The lesson here is about where control sits. When testing was a service, the contract defined scope. When testing is an agent, scope lives with whoever starts it. AWS says plainly that you should only test applications you own or have written permission to test. It adds that unauthorized testing is illegal in most jurisdictions.
What this does not show
This is one vendor announcement. It does not show how often companies will adopt agent-led testing. It does not show how GLM 5.3 compares with other models at finding flaws. AWS also points to its managed service, AWS Continuum, for continuous testing at scale. That is a commercial offer, and readers should weigh it as one.
AWS advises temporary credentials over long-lived API keys when connecting these tools. A security agent holds real access to your systems. How its keys are issued and expire is part of the risk.
Questions to put to your team
Ask who can launch an AI testing agent today, and against which systems. Ask whether written permission is recorded before each run. Ask where the model's inference runs, and whose controls apply to the prompts and findings.
Ask whether credentials for these tools are short-lived. Ask who triages the reports, since the agent's proof-of-concept claims still need a human to judge severity and fix priority.
An agent makes testing your own code easy to start. The harder part is deciding, in writing, who is allowed to start it.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: DIGITIMES Asia.





