Gemini 3.6 FlashvsGLM-5.3-Flash
Gemini 3.6 Flash | GLM-5.3-Flash | |
|---|---|---|
| Specifications | ||
ParametersA rough measure of how big the model is. More parameters usually means more capable and more expensive to run, though it is a poor guide on its own — a smaller, newer model often beats a larger, older one. | — | 320B |
Context windowHow much text the model can hold in mind at once — your question, any documents you attach, the conversation so far, and its own reply. Go past it and the earliest part falls out of view. | — | 1M |
| API pricingUSD per 1M tokens · lower wins | ||
Input priceWhat you pay for everything you send the model — your question, plus any documents or earlier conversation you include with it. | $0.75 | — |
Output priceWhat you pay for the text the model writes back. It is normally the dearer half: producing an answer costs more than reading one. | $3.75 | — |
Cached input priceA reduced rate for text you send over and over. If every request starts with the same instructions or the same document, the provider keeps a copy ready and charges less to read it again. | $0.075 | — |
| Benchmarks | ||
DeepSWE 1.1Agentic coding — Artificial Analysis' independent test of deep, agentic software-engineering work — the AI has to plan and carry out substantial coding tasks end to end. (Version 1.1 of the test.) Higher is better. | 49% | 63.4% |
GDPval-AA v2Knowledge work — economically valuable knowledge work (v2, re-based Elo) | 1421 | 1773 |
| BenchmarksPublished by one model only | ||
BullshitBench v2Nonsense detection — Given a confidently-worded but nonsensical prompt, does the AI spot that it makes no sense and push back — instead of playing along and inventing an answer? The score is how often it clearly called out the nonsense. Higher is better. | 39% | — |
Gray Swan IPI · k = 1Prompt injection robustness — Attackers hide malicious instructions inside content the AI reads — a web page, an email, a document — and try to hijack what it does. Gray Swan's indirect prompt injection benchmark measures how often such an attack succeeds when the attacker gets a single try. Lower is better. | 7.3% | — |
Gray Swan IPI · k = 10Prompt injection robustness — Attackers hide malicious instructions inside content the AI reads — a web page, an email, a document — and try to hijack what it does. This variant gives the attacker 10 tries and counts an attack as successful if any of them works. Lower is better. | 32.2% | — |
Gray Swan IPI · k = 15Prompt injection robustness — Attackers hide malicious instructions inside content the AI reads — a web page, an email, a document — and try to hijack what it does. This variant gives the attacker 15 tries and counts an attack as successful if any of them works. Lower is better. | 37.3% | — |
MLE-BenchML engineering — Can the AI do the work of a machine-learning engineer? It competes in real Kaggle competitions — building, training, and tuning models end to end — and the score reflects how well it places. Higher is better. | 63.9% | — |
Terminal-Bench 2.1Agentic terminal coding — Can the AI work in a command-line terminal — running commands and finishing technical setup tasks the way a developer would? Higher is better. | — | 84.3% |
BU BenchBrowser agent — Can the AI drive a real web browser to finish tasks — clicking, filling forms, and navigating sites the way a person would? Run by Browser Use on their BU Bench task set. Higher is better. | 68% | — |
Humanity's Last Exam · with toolsMultidisciplinary reasoning — Humanity's Last Exam — extremely hard expert questions across many subjects. “With tools” means the AI is allowed to search the web or run code while answering. Higher is better. | — | 55.3% |
OSWorld-VerifiedAgentic computer use — Can the AI actually operate a computer — clicking, typing, and using real apps — to finish tasks on its own? Higher is better. | 83% | — |
Agent's Last Exam · pass@1Agentic computer use — A hard set of desktop and operating-system tasks an AI agent has to finish by looking at the screen and working the machine itself. The score is the share it passes outright — partial credit does not count. Higher is better. | — | 26.3% |
AutomationBenchBusiness workflows — Tests whether the AI can run real multi-step business workflows — the kind of end-to-end office processes companies want to automate — from start to finish. Higher is better. | — | 48.8% |
| Overview | ||
| Company | Z.ai | |
| Release date | Jul 21 2026 | Aug 26 2026 |
| Access | Proprietary | Open Weight |
Other comparisons
Frequently asked questions
GLM-5.3-Flash leads Gemini 3.6 Flash on 2 of the 2 benchmarks they both report (DeepSWE 1.1, GDPval-AA v2). Only Gemini 3.6 Flash has a verified first-party API price: $0.75 per million input tokens and $3.75 per million output tokens. No pay-as-you-go API rate is tracked for GLM-5.3-Flash. Gemini 3.6 Flash shipped 36 days before GLM-5.3-Flash, so benchmark comparisons should account for the intervening progress.
Gemini 3.6 Flash is proprietary, while GLM-5.3-Flash is open weight.
On DeepSWE 1.1, GLM-5.3-Flash leads at 63.4% vs Gemini 3.6 Flash at 49%. On GDPval-AA v2, GLM-5.3-Flash leads at 1773 vs Gemini 3.6 Flash at 1421.
Gemini 3.6 Flash was released by Google on Jul 21 2026.
GLM-5.3-Flash was released by Z.ai on Aug 26 2026.
GLM-5.3-Flash leads on DeepSWE 1.1 — Gemini 3.6 Flash 49% vs GLM-5.3-Flash 63.4%.
Only Gemini 3.6 Flash has a verified first-party API price: $0.75 per million input tokens and $3.75 per million output tokens. No pay-as-you-go API rate is tracked for GLM-5.3-Flash. Rates are pay-as-you-go API prices verified on August 18, 2026.
Gemini 3.6 Flash is a proprietary model released by Google. GLM-5.3-Flash is an open weight model released by Z.ai.