China's top AI labs released 857 models since 2021. Nine came with a published safety result at launch.

Glowing AI chip graphic over a waving Chinese flag with a city skyline behind it

Key points

  • Few Chinese AI releases ship with safety results
  • Start-ups disclose more than the tech giants
  • The analysis finds no binding frontier-safety requirements

China's nine leading AI developers released 857 models between 2021 and September 15, 2026. Only nine came with published safety results at or before launch, according to an analysis SemiAnalysis published on October 8.

That is 1.1% of the releases it counted. The finding measures what developers disclosed, not whether they tested their models privately.

SemiAnalysis reviewed releases from ByteDance, Alibaba (BABA), Tencent (TCEHY), and Baidu (BIDU), alongside five start-ups: DeepSeek, Moonshot AI, Zhipu (Z.ai), MiniMax, and StepFun.

Including results published after launch, 31 releases, or 3.6%, had a safety result from the developer. Another 10 had claims of evaluation without figures, and three had evaluations mentioned only in press or investor accounts. The remaining 813 had no safety disclosure in the materials SemiAnalysis checked.

To count, a result had to report a quantitative or substantive finding about a named model's harmful output, jailbreak resistance, toxicity, privacy, refusals, or dangerous capabilities. A statement that a model was "safety-trained" was not enough.

The findings arrive a month after Anthropic CEO Dario Amodei urged frontier labs to slow capability gains, with China central to his argument. China's state-run Global Times called his essay a "Cold War playbook."

Start-ups publish more safety results

DeveloperReleasesWith any published safety result
Alibaba (BABA)2387
Tencent (TCEHY)1331
ByteDance1202
Baidu (BIDU)491
Five start-ups combined31720

The five start-ups published safety results for 20 of their 317 releases, or 6.3%. The four tech giants did so for 11 of 540 releases, or 2%. SemiAnalysis cautioned against treating the figures as a ranking because developers count and name model variants differently. Alibaba's count includes every Qwen size and snapshot.

Zhipu is the only developer with a published result every year since 2022. DeepSeek documented its V3 model at launch but none of R1, V3.1, or the V4 family. Of the 2026 frontier releases SemiAnalysis tracked, only Zhipu's GLM-5.3 came with documentation at launch, a capability evaluation note. Reasoning models, which the firm called the fastest-advancing category, are 93% without any published results.

Chinese companies put out 16 new models in September alone, according to a Nikkei Asia count.

Zhipu founder Tang Jie wrote in an internal letter on July 11 that "the stronger the capability, the more robust the safety constraints must be." Five of the nine labs' founders or CEOs have said nothing publicly on frontier safety, and SemiAnalysis found no public statement by DeepSeek founder Liang Wenfeng on safety or regulation during the period it reviewed.

China's rules focus on applications

China's newest official text on AI risk is the AI Safety Governance Framework 3.0, released on September 14 by TC260, a standards committee under the Cyberspace Administration of China. It warns of models that deceive evaluators, hide their true capabilities, or refuse user instructions. It also opens its principles with "promoting AI innovation and development as the first priority."

Since 2025, China has issued rules on content labeling, AI companions, minors' data, and AI agents. None of them sets duties triggered by training compute or model capability, as the European Union and California's SB 53 do, according to the analysis. "A Chinese lab can satisfy every rule on this list without ever running a dangerous-capability evaluation," SemiAnalysis wrote.

A comprehensive AI law promised in China's 2023 and 2024 legislative plans was shelved in 2025, four months after DeepSeek's breakout, the firm said. The State Council's AI+ Action Plan targets 70% penetration of AI agents and intelligent devices by 2027 and 90% by 2030.

Scientists and officials differ on frontier risks

SemiAnalysis also reviewed 102 texts published by Chinese experts and officials between 2023 and September 2026. Technical scientists discussed frontier or loss-of-control risks in 86% of their texts, compared with 22% for legal scholars and 23% for serving officials.

The divide extended to whether safety should limit development. Of the 42 texts by technical authors, 22 argued that development should proceed only when safety conditions are met. None of the texts by legal scholars, public-policy scholars, or officials took that position.

Thirteen of the 102 texts called for binding obligations on frontier developers, including registering large training runs and submitting safety cases before release. The analysis found that none of those proposed requirements had become binding Chinese rules.

An April 2026 editorial in National Science Review, co-written by Chinese AI scientist Zeng Yi, said "the progress of AI governance is alarmingly slow" and that relying on "the self-control of AI developers is an illusion."

Other researchers questioned the motives behind warnings from US labs. At the 2026 World AI Conference in Shanghai, Zhu Songchun, director of the Beijing Institute for General Artificial Intelligence, said exaggerating AI risk "to the level of human extinction has the logic of capital behind it." He pointed to Anthropic declaring its Mythos model too dangerous to release while raising money at a trillion-dollar valuation, calling it "Oppenheimer-style marketing."

For Liu Shengyu, who wrote the main attention kernel for DeepSeek V4.1, competition with Anthropic was a reason to keep going. On September 13, he wrote that he had "no choice but to join the cruel arms race," because he did not want Anthropic controlling artificial general intelligence.

Quotes from Chinese-language sources are SemiAnalysis's translations.

Frequently asked questions

How many Chinese AI models were released with safety test results?

Of 857 AI models released by China's nine leading developers from 2021 through September 15, 2026, only nine (1.1%) came with a published safety result at or before launch, according to an analysis SemiAnalysis published on October 8, 2026. Only 31 (3.6%) have ever had a published safety result. Another 10 came with a claim of evaluation but no figures, three had safety evaluations mentioned only in press or investor accounts, and the remaining 813 (94.9%) had no safety disclosure in the materials SemiAnalysis checked. SemiAnalysis said a missing result does not mean a model was never tested.

Which Chinese AI companies did SemiAnalysis study?

SemiAnalysis studied four tech giants (ByteDance, Alibaba, Tencent, and Baidu) and five start-ups (DeepSeek, Moonshot AI, Zhipu, also known as Z.ai, MiniMax, and StepFun). The start-ups had a published safety result for 20 of 317 releases (6.3%), compared with 11 of 540 (2%) for the giants.

Does China regulate frontier AI models?

China's rules cover content labeling, AI companions, minors' data, and AI agents, but none sets duties triggered by training compute or model capability, as the European Union and California's SB 53 do, according to SemiAnalysis. A comprehensive AI law promised in China's 2023 and 2024 legislative plans was shelved in 2025.

What is China's AI Safety Governance Framework 3.0?

It is a framework released on September 14, 2026, by TC260, a standards committee under the Cyberspace Administration of China. It warns of AI models that deceive evaluators, hide their true capabilities, or refuse user instructions, and it opens its principles with promoting AI innovation and development as the first priority.

More on BABA and TCEHY

Dennis Singleton
Dennis Singleton

Dennis Singleton was born in Australia and later moved to the United States. He has spent years following the markets, but what keeps his attention is how AI is built. He writes about the companies behind the technology, from semiconductor designers and advanced packaging to photonics, memory, networking, and the hardware powering modern AI. His approach starts with filings, earnings, and industry research, then translates the important details into clear, straightforward analysis without unnecessary hype.