You guys read Z.ai's terms of service, right?
Broad and perpetual license over inputs and outputs, and even your name and profile picture.
Vague prohibitions on whatever may harm Z.ai’s "interests" or even the "national interests" of any country.
Vague prohibitions on "disturbing" or "inappropriate" content, whatever that is.
Vague prohibitions on discussing Z.ai, even my posting this comment violates it.
Can ban you if you, in the "sole and absolute opinion" of Z.ai, have violated these broad terms, and if you paid for the discounted yearly plan kiss your money goodbye.
Isn't this practically every TOS though?
Nearly every TOS I've ever read has a "We can ban you for any reason, or no reason, are under no obligation to disclose any reason." line somewhere in it.
HN's for example
> We reserve the right, at our sole discretion, to change or modify portions of these Terms of Use at any time.
> You acknowledge that Y Combinator may establish general practices and limits concerning use of the Site,
> You further acknowledge that Y Combinator reserves the right to change these general practices and limits at any time, in its sole discretion, with or without notice.
> Y Combinator reserves the right to investigate and take appropriate legal action against anyone who, in Y Combinator’s sole discretion, violates this provision, including without limitation, removing the offending content from the Site, suspending or terminating the account of such violators and reporting you to the law enforcement authorities.
> Isn't this practically every TOS though?
Not even close. Even OpenAI and Anthropic aren't bad enough that they claim literal ownership of your inputs and outputs.
> HN's for example
You're not paying to use HN. Getting banned here has essentially zero consequences.
If Z.ai uses its absolute powers to ban you because you wrote a review about them or something, then you lose actual money. This is especially relevant if you're looking to take advantage of their discounted yearly payment option.
Consider the reputation implications of them banning someone who can get their complaint about it to the front page of HN and into the YouTube drama loop. They’d get swarmed with activist cancellations.
At most I suspect the A.I. providers will just come up with yellow banners like Anthropic did where naughty smut writers get put in the time out corner.
> Even OpenAI and Anthropic aren't bad enough that they claim literal ownership of your inputs and outputs.
Where do you see this?
> You're not paying to use HN.
Oh for sure man, this absolutely looks like you were only concerned and talking about paid services:
> Broad and perpetual license over inputs and outputs, and even your name and profile picture.
The post I was replying to wasn't talking about that, but sure, let's consider it.
Everything I post here is public, and it's just relatively low value commentary anyway. It doesn't matter if Y Combinator has rights to it. Arguably they actually need to assert some rights, otherwise they wouldn't be able to transfer copies of copyrighted comments to other visitors of the site. HN's terms are probably too broad for their purposes but it doesn't really matter much because this is just a forum.
AI on the other hand is for actual work, both public and private. There are actual economic implications here, so the stakes are much higher. I absolutely want to own the inputs and the outputs I paid money for.
> Even OpenAI and Anthropic aren't bad enough that they claim literal ownership of your inputs and outputs.
In this case you are placing your trust in OpenAI and Anthropic. I'm not sure about Anthropic but OpenAI has changed their mission corpus quite a lot from its humble beginnings that it results hard to trust them when they say they don't use your stuff to further train their models. If I'm a Big Corp with enough lawyers to putnup a fight, I would then feel ok with such clause, but being a small guy, who is going to defend me when the truth comes out that they have been training their models with my data? Similar fiasco as with Facebook, who had claimed they didn't sell your data, even though they were.
That's where I'm coming from with all this "trust us, we don't train our models with your data". At least this Chinese company is being upfront about it.
[flagged]
This is not uncommon.
Also, it only applies to their chat offering, not the api. OpenRouter also offers the API with ZDR.
While shitty, i’d say that its really not that special.
???
None of the major LLM chat providers (ChatGPT, Claude and Gemini, and I just confirmed this) claim rights over your input.
They also don't claim rights over your output, but because of how copyright law might apply, they explicitly assign all the rights to the generated output.
Not just that but, even if they wanted to claim ownership of the output, courts in the US have deemed that copyright cannot be assigned to machine-generated output.
So yeah, happy to take a look at a counter-example if you have one (aside from GLM 5.3, obv.).
> In choosing to submit, create, generate, record, post, or display Inputs on or through the Service, you grant an irrevocable, perpetual, transferable, sublicensable, royalty-free, and worldwide right to SpaceXAI to use, copy, store, modify, process, adapt, transmit, distribute, reproduce, publish, upload, download, display in public forums, list information regarding, make derivative works of, and distribute such Content, including anything referenced therein, in any and all media or distribution methods now known or later developed, for any purpose, and to aggregate your User Content and derivative works thereof for any purpose, including but not limited to: (i) maintain and provide the Service; (ii) improve our products and the Service and for our other business purposes, such as data analysis, customer and market research, developing new products or features, or identifying or displaying usage or User Content trends; and (iii) perform such other actions to enforce these Terms, comply with our Privacy Policy, comply with applicable law or governmental, court, and law enforcement requests or requirements or keep our Service safe.
> To the extent the User Content includes a person’s image, likeness, voice, or other similar attributes, you grant SpaceXAI the same rights to use those attributes as part of the User Content as described above. You represent and warrant that you have obtained all rights, licenses, notices, permissions, and consents necessary for SpaceXAI to use that User Content.
https://x.ai/legal/terms-of-service
These are arguably even worse to be honest. Absolute nightmare.
Nice find, those are indeed pretty bad.
However, if we check the market share of generative AI providers, ChatGPT+Claude+Gemini make up around 88%; while Grok is 2-4% depending on who you ask.
> Can ban you if you, in the "sole and absolute opinion" of Z.ai, have violated these broad terms.
OpenAI revoked my Cyber verification, along with many others, asked to reverify (i.e. give my biometric information to Persona), had me do it 8 times, just to find out several days later that they silently implemented a nationality whitelist, and my nationality didn't make it (and no, it's not a sanctioned country).
Their support says they can't look into anything or do anything, and their public spokespersons on X deny everything.
I get tons of cyber refusals now (lots of reverse engineering), so it's only matter of time when my account is going to get banned.
At least Z.AI is being honest here. And no provider other than OAI/ANT had me submit my biometric information just to use Ghidra.
> just to find out several days later that they silently implemented a nationality whitelist, and my nationality didn't make it (and no, it's not a sanctioned country)
How did you discover this?
I opened the Persona tab once, closed it and the tab never opened ever again. "Precheck failed".
What countries are banned? I'm from Brazil.
I went as far as initiating an LGPD (brazilian GDPR) process against them due to this. At some point I got it in writing that I'm allowed to make a new account and try again. Until now I was assuming it was just some weird account state. If I'm banned from TAC due to my nationality that's seriously disgusting...
When they initially revoked TAC for a bunch of users due to a "technical error", the TAC verification flow opened a Persona iframe where you select the document country first. I was able to select it there (Georgia, in my case), went through the entire flow, and then got locked out after 8 attempts. Persona itself was successful end to end, so it failed somewhere on the OAI side. Other users then started reporting the exact same issue on the OpenAI forum.
A week later, I tried testing the TAC flow on my SO's account, which had never had a TAC attempt before. Selecting Georgia in the Persona iframe now says, "We are unable to verify identities in this country."
But I know this isn't a Persona limitation, as I verified with Anthropic using Persona the same day.
So what I think happened was this: OpenAI silently implemented a country whitelist on their end and revoked TAC for affected individuals who already had it, calling it a "technical issue". They forgot to disable those countries in Persona, so everyone just got a cryptic error. Then they disabled them in Persona too.
Interaction with support was AI with human names, which essentially just repeats what you said. And it ended with:
> I’m unable to provide additional details about verification outcomes, and Support cannot manually override the result. At this time, Trusted Access for Cyber verification does not support retries or appeals.
I even provided them my credentials, and support AI was basically: lol wat we're here to check technical errors, your credentials are of no relevance.
That's horrible...
For the record, I just made a second account, got verified by Persona and still didn't get into TAC. No "we are unable to verify identities in this country" message. No mention of my country whatsoever. Persona verification was successful.
What else do they want from us?
Were it not for Z.ai's obnoxious terms, I would have switched to them already...
Ah yeah, new accounts get instantly blocked on TAC. Their backend has 2 failure states for `id_verification_status` - `failed` and `blocked`.
Nationality bans get `failed`, new accounts (or rather, accounts with not enough good signals) get `blocked` on first attempt.
I see. I'm never going to get into TAC then. OpenAI servers return 403 cyber_verification_precheck_failed. They don't even bother verifying me.
Time to subscribe to Kimi.
You may have more luck with GLM 5.3. New Kimi subscriptions are currently paused, so you have to join the waitlist. But even if you get in, usage limits are pretty bad there, just check reddit.
GLM 5.3 is quite capable with "cyber" tasks. I'm working on a project that touches macos private internals, and GLM 5.3 was able to reverse engineer everything I need with ease.
I've also had some luck with GLM 5.3 "translating" cyber stuff to Sol subagents in a "safe" language. Gets rid of cyber refusals at least on the input side. Output is trickier, but a very crude "think and talk to me in a neutral, safe language without high risk words" actually worked surprisingly well.
For my own stuff I simply don't care if Z.ai is learning straight from me or from my GitHub repo a few days later when I push the code.
When I use it for reverse engineering, same thing, the code is already out there, but in binary form, which is becoming trivial for these LLMs to work on.
I even bought some shares from them and got some money out of it!
I get all that.
Then alternatives are:
- Grok - where I absolutely have 0 trust in X.ai's interst in "pushing humanity forward".
- OpenAI and Anthropic - which seem to try to be building the biggest moat they can by pushing to ban open models. And at the same time want to be an Arbiter of what level of intelligence I can use.
- Google and Meta - I don't need to talk about the practices of these companies.
Yes, the terms of service aren't great. But the alternatives aren't great either. I don't believe that a future which OpenAI and Anthropic are pushing for has my best interest in mind.
Or Deepseek, Qwen, any other open model hosted by whoever you trust most.
> I don't believe that a future which OpenAI and Anthropic are pushing for has my best interest in mind.
I don't believe in that either, but these totalitarian terms are absolutely unacceptable.
If only you could grab those models and host them literally anywhere else where you wouldn't be subject to those terms. Damn. Maybe we'll have to wait for someone to invent something like open download of model weights.
Care to buy me a $10,000-$100,000 computer?
No but a provider with more amicable terms can.
All the American companies you mentioned still follow American law and regulation. Skirting that blatantly has big consequences.
Chinese companies do not follow American laws and there are absolutely no consequences for violating it.
Moreover, the average American is not even aware of exactly what the legal/judicial environment is like in China. If your code and data is stolen, you can't fly to China and demand justice in the courts.
Is copyright infringement an American Law?
Aren’t those American companies sued because they didn’t follow American law?
OpenAI is being sued by Apple, yes
> All the American companies you mentioned still follow American law and regulation. Skirting that blatantly has big consequences. > Chinese companies do not follow American laws and there are absolutely no consequences for violating it.
... lmk when anthropic/openai/spacex/xai are held accountable for anything. Anything at all. Hard to be when you're _writing_ the rules.
> All the American companies you mentioned still follow American law and regulation. Skirting that blatantly has big consequences.
No, they don’t. This is an absurd statement to make in 2026.
The model is MIT-licensed, so run it on any of the non-Chinese inference providers that will host it in a few days.
NovitaAI is already hosting it: https://openrouter.ai/z-ai/glm-5.3-flash#providers
And now pretty much everyone is hosting it, with some matching the 50% discount.
It's China. It's a given that they use your data for training. At least they're nice enough to be honest about it.
It's not like US companies don't do the same either.
It’s implied that they do, but don’t have the balls to tell you they do.
They tell you, and allow you to opt out in certain plans.
Except when their automated reviews decides that you've written something dangerous, in which case they'll use it for training.
And no, they won't tell you what their automated reviews consider "dangerous".
And neither will they make clear what "analytical purposes" is for the data you can't opt out of.
So they give you the ability to "opt-out" of "training purposes", and then you still share everything for analytical purposes (which you can't opt out of). It's a smart tactic on their side if they are contributing to cultural discourse on this to keep the straw man focus on training data.
And also to have the popular AI straw man: that your data isn't valuable and oh man they're losing so much money on tokens and giving you a subsidy, so you you better use up your entire subscription balance weekly/daily/every 5h putting in all your "worthless" data that you miss out otherwise (FOMO). Oh man only way it could get worse is if they implemented gambling slots psychology.
Or worse. Look at what happened to Figma.
The model weights are MIT licensed.
I'm talking about the Z.ai service specifically.
As others have mentioned, nothing's stopping any other major provider from offering it. Given its popularity, you can guess how that'll develop. So, overall, irrelevant.
I blocked Z.ai as soon as they were loading 10 different external providers including Alibaba who was just proven to execute silent sound fingerprinting mechanisms.
Isn’t the point with these open models that you find a provider with the right terms of use/data sovereignty for you and get it from them?
Yes, the terms are dubious. But they are also reasonably lenient with enforcement. They also don't require persona id verification, witch is wat turned me away from openai.
Yeah, you're probably right...
> They also don't require persona id verification, witch is wat turned me away from openai.
Could be worse. I was dumb enough to verify, only to get rejected for unknown reasons with no retries and no appeals. Had my privacy violated and have nothing to show for it.
Yeah, this is worse.
"Come verify your identity."
"Thanks, we've got your ID. Still not approving you, and there's no appeal."
Worst of both worlds.
I will never use or verify biometrically with Persona. I don’t care how out of the way I have to go, but I will never do it.
Working well so far.
Give it a couple days, and there will be plenty of other inference companies hosting it. Don't like z.ai's TOS? Use the model on a provider with TOS that you agree with.
Are their TOS significantly more vague or restrictive than OpenAI or Anthropic’s?
In any case what matters is what is enforced in practice. It will be a mild inconvenience to switch providers on Openrouter.
If Anthropic or OpenAI decide to apply those same arbitrary terms, you are SOL.
> Are their TOS significantly more vague or restrictive than OpenAI or Anthropic’s?
Yeah, I've compared both. The US companies generally aren't as vague, and they don't claim ownership over inputs and outputs.
Z.ai doesn't claim ownership either.
>you retain all rights, title, and interest in the Prompts ...
However, it does grant them an irrevocable license to do, effectively, anything with the data
Not a lawyer but I think the practical difference is you can still license to others, sell, sue IP infringers
As long as the weights are open, who cares? You can rely on someone else for inference.
How is that vastly different from any other non-enterprise facing provider? I do believe Anthropic bans accounts without even a human in the loop with no recourse left to those banned.
None of that applies if you run it at home. Also 3rd party providers will start serving this pretty soon under different terms.
> None of that applies if you run it at home.
Yeah, running frontier open weight models on my own hardware has essentially become my dream at this point. I hope the hardware manufacturers step up production to meet consumer demand.
You can download the weights, and run in your own hardware and avoid all that.
you can abliterate any open model like this. This is pretty standard stuff in a TOS. I'd be surprised if you couldn't find the same in OAI or Anthropic's
>Broad and perpetual license over inputs and outputs, and even your name and profile picture.
>Vague prohibitions on whatever may harm Z.ai’s "interests" or even the "national interests" of any country.
[...] may cause harm to Anthropic, our users, or third parties, we reserve the right to remove or take down some or all of such Third-Party Content using, where appropriate, algorithmic and human review.
You may not export or provide access to the Services into any U.S. embargoed countries or to anyone on (i) the U.S. Treasury Department’s list of Specially Designated Nationals, (ii) any other restricted party lists identified by the Office of Foreign Asset Control, (iii) the U.S. Department of Commerce Denied Persons List or Entity List, or (iv) any other restricted party lists
>Vague prohibitions on "disturbing" or "inappropriate" content, whatever that is.
we will use Materials for model training when [...] your Materials are flagged for safety review to improve our ability to detect harmful content, enforce our policies, or advance our safety research.
>Vague prohibitions on discussing Z.ai, even my posting this comment violates it.
>Can ban you if you, in the "sole and absolute opinion" of Z.ai, have violated these broad terms, and if you paid for the discounted yearly plan kiss your money goodbye.
To engage in any other conduct that restricts or inhibits any person from using or enjoying our Services, or that we reasonably consider exposes us—or any of our users, affiliates, or any other third party—to any liability, damages, or detriment of any type, including reputational harms.
Mind you, that's Anthropic's Terms of Use in Europe. I have zero doubts the TOS applied to the US is even worse and that merely mentioning your first born in a chat entitles them to a part of its soul.
Chinese laws are not valid in the EU
That’s pretty funny to say when the EU claims GDPR applies worldwide.
What they don’t do. They claim that the GDPR applies if you provide your service in the EU, and that’s a valid claim.
They claim it applies to EU citizens when both they and the service are outside the EU as well.
No they don’t. The GDPR is location scoped so the data of an EU citizen given to an hotel while on vacation in the US isn’t protected by GDPR but the data of an US citizen giving their data to a hotel in the EU while on vacation is.
That is my understanding as well. Not a lawyer but recently looked into it since we have US, EU, and non-EU European employees and we were looking at token usage tracking tools (which would appear to potentially fall under employee surveillance or at the very least require explicit consent)
Not sure the exact legalese but legal put together a consent form for anyone wanting to do the PoC
They obviously don’t have a valid claim to be able to tell everyone who wants to put a website on the internet that they have to do it the EU way, which is what we’re actually talking about.
If the site can be viewed in the EU, it has to follow EU rules. Not different from other countries.
What do you think why the normal polymarket site is blocked for US users.
I’ve got a bunch of sites that can be viewed from (checks notes) the internet. If people in Europe don’t like that, they can block it, or choose not to visit it. In the meantime, you’ve proven exactly what I first said, which is that they are claiming it applies worldwide. Here I am, just putting a site on the internet, and you’re telling me I have to follow EU laws concerning it. Nope. I don’t.
They all do that, some are just more honest to tell you upfront than others.
TOS is and will ever be just a "pretty please".
> Vague prohibitions on "disturbing" or "inappropriate" content, whatever that is.
I have prompted out a lot of disturbing and inappropriate content with GLM-5.2, that would have left other American models blanched in the face or clutch their pearls. I think this is mostly a reference to Anti-CCP stuff.
In fact, I don't think I've ever even had a prompt refused.
> In fact, I don't think I've ever even had a prompt refused.
I very much have. I've gotten GLM-5.2 refusals for extremely benign security testing on my own infrastructure of the same flavor that people were getting (wrongly) flagged for on Fable during the initial release.
That's alarming. I want to use these models to red team my own computers. How are people getting around this?
> I want to use these models to red team my own computers.
Exactly what I was trying to use it for! ):
I'm in the same boat - I haven't heard of a way to get around it aside from either self-hosting (GLM-5.2? good luck) or "self-hosting" (paying bucks per hour to Vast) an abliterated model.
What is the harness that you're using?
I found that GLM-5.2 was pretty happy helping me reverse engineer/hack devices.
Maybe the system prompt you're injecting is making it refuse?
> Maybe the system prompt you're injecting is making it refuse?
No, this has nothing to do with my harness. I use one of the most popular open-source harnesses available.
> I found that GLM-5.2 was pretty happy helping me reverse engineer/hack devices.
This is a completely different category of things than what I'm getting refusals on, so I'm not sure why you're bringing it up.
Uh, actively trying to hack an embedded device that runs Linux over the network, specifically an IP security camera, could be considered red teaming, no?
You never mentioned which exact activities you were getting flagged on and getting refused.
> Uh, actively trying to hack an embedded device that runs Linux over the network, specifically an IP security camera, could be considered red teaming, no?
No. Vendors (and their model guardrails) do, indeed, treat those as separate from pentesting non-embedded infrastructure, and that is because they are very different activities.
And, if you actually read my comment, it says "red team my own computers". That's categorically different from pentesting an IP camera.
> You never mentioned which exact activities you were getting flagged on and getting refused.
Because further details than those I've provided aren't relevant, and it's clearly different from what you're doing.
Your experience isn't relevant to my situation.
It is cliche, but I haven't had good luck with having Chinese models openly discuss historical topics like Tienanmen Square. The US models don't seem to have a problem discussing history, even if it points an unglamorous light on the US government.
And there's a reason for that: the US government does not compel model trainers to train their models to paint them in a favorable light, while the PRC does.
Who the hell cares when I can run it myself?