GLM 5.3 joins Bedrock after GLM 5
AWS published Introducing GLM 5.3 on Amazon Bedrock on 5 October 2026 US time, 6 October in Singapore. It says Z.ai's GLM 5.3 is now available on Amazon Bedrock through fully managed APIs.
The post says access is available to eligible enterprise customers. It does not define eligibility.
GLM 5 arrived on Bedrock earlier this year, the post says. GLM 5.3 is the newer model in the same line.
AWS hosts the 753B model from Z.ai
Z.ai, also known as Zhipu AI, makes the model. AWS describes GLM 5.3 as a 753B-parameter mixture-of-experts model for coding and long-horizon agentic tasks, as published on the Hugging Face model card.
AWS's walkthrough lists the IAM permissions callers need: bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream and bedrock:CallWithBearerToken, on both the base model and the inference profile.
Two inference profiles and explicit cache breakpoints
The post lists these Bedrock features for GLM 5.3:
- It runs through two cross-Region inference profiles, us.zai.glm-5.3 and global.zai.glm-5.3. You send requests to a source Region of your choice, and Bedrock routes each one for processing.
- AWS says it supports the OpenAI-compatible Responses and Chat Completions APIs and the Bedrock Invoke and Converse APIs. AWS recommends the OpenAI-compatible APIs for new applications.
- Implicit prompt caching is on by default. Explicit caching uses breakpoint markers, and each cached prefix needs at least 1,024 tokens.
- Flex, Standard and Priority service tiers trade price against latency.
AWS recommends short-lived credentials over long-lived API keys where possible. It notes that LiteLLM did not yet resolve the global profile name at the time of writing. The post shows a workaround through the Converse route.
In the post's walkthrough, AWS runs Strix, an open source penetration testing agent, against a local copy of OWASP Juice Shop. Juice Shop is a deliberately vulnerable sample app. AWS says Strix's documentation uses GLM 5.3 as its default model.
No price, vague eligibility and vendor benchmarks
- The post names no Bedrock price for GLM 5.3.
- It lists only the US and Global cross-Region profiles, with no Asia Pacific profile.
- Performance figures come from Z.ai, and The Frontier found no independent reproduction of them. AWS cites a 50% improvement over GLM 5.2 on Z.ai's internal coding benchmark and a CyberGym score of 84.5 that Z.ai measured at release.
- AWS says Z.ai reported no direct comparison with GLM 5, because the benchmarks changed after GLM 5.1.
- AWS warns that testing systems you do not own is illegal in most jurisdictions and breaks its Acceptable Use Policy.
Check eligibility and your security policy first
- Ask your AWS account team whether your organization counts as an eligible enterprise customer.
- Decide whether a model with reported cyber capability fits your acceptable use rules before you enable it.
- Run security agents only against applications you own or have written permission to test, as AWS states.
- Check where the global profile may process requests before you send regulated data.
For Anthropic's assessment of the same model, see Anthropic says Z.ai GLM-5.3 brings Mythos-class cyber skills with weak open-weight safeguards.
For Bedrock options that keep data in Singapore, see Amazon Bedrock adds in-region Claude inference in Seoul and Singapore and an India-only cross-Region profile.
