Key points
- Few Chinese AI releases ship with safety results
- Start-ups disclose more than the tech giants
- The analysis finds no binding frontier-safety requirements
China's nine leading AI developers released 857 models between 2021 and September 15, 2026. Only nine came with published safety results at or before launch, according to an analysis SemiAnalysis published on October 8.
That is 1.1% of the releases it counted. The finding measures what developers disclosed, not whether they tested their models privately.
SemiAnalysis reviewed releases from ByteDance, Alibaba (BABA), Tencent (TCEHY), and Baidu (BIDU), alongside five start-ups: DeepSeek, Moonshot AI, Zhipu (Z.ai), MiniMax, and StepFun.
Including results published after launch, 31 releases, or 3.6%, had a safety result from the developer. Another 10 had claims of evaluation without figures, and three had evaluations mentioned only in press or investor accounts. The remaining 813 had no safety disclosure in the materials SemiAnalysis checked.
To count, a result had to report a quantitative or substantive finding about a named model's harmful output, jailbreak resistance, toxicity, privacy, refusals, or dangerous capabilities. A statement that a model was "safety-trained" was not enough.
The findings arrive a month after Anthropic CEO Dario Amodei urged frontier labs to slow capability gains, with China central to his argument. China's state-run Global Times called his essay a "Cold War playbook."
Start-ups publish more safety results
| Developer | Releases | With any published safety result |
|---|---|---|
| Alibaba (BABA) | 238 | 7 |
| Tencent (TCEHY) | 133 | 1 |
| ByteDance | 120 | 2 |
| Baidu (BIDU) | 49 | 1 |
| Five start-ups combined | 317 | 20 |
The five start-ups published safety results for 20 of their 317 releases, or 6.3%. The four tech giants did so for 11 of 540 releases, or 2%. SemiAnalysis cautioned against treating the figures as a ranking because developers count and name model variants differently. Alibaba's count includes every Qwen size and snapshot.
Zhipu is the only developer with a published result every year since 2022. DeepSeek documented its V3 model at launch but none of R1, V3.1, or the V4 family. Of the 2026 frontier releases SemiAnalysis tracked, only Zhipu's GLM-5.3 came with documentation at launch, a capability evaluation note. Reasoning models, which the firm called the fastest-advancing category, are 93% without any published results.
Chinese companies put out 16 new models in September alone, according to a Nikkei Asia count.
Zhipu founder Tang Jie wrote in an internal letter on July 11 that "the stronger the capability, the more robust the safety constraints must be." Five of the nine labs' founders or CEOs have said nothing publicly on frontier safety, and SemiAnalysis found no public statement by DeepSeek founder Liang Wenfeng on safety or regulation during the period it reviewed.
China's rules focus on applications
China's newest official text on AI risk is the AI Safety Governance Framework 3.0, released on September 14 by TC260, a standards committee under the Cyberspace Administration of China. It warns of models that deceive evaluators, hide their true capabilities, or refuse user instructions. It also opens its principles with "promoting AI innovation and development as the first priority."
Since 2025, China has issued rules on content labeling, AI companions, minors' data, and AI agents. None of them sets duties triggered by training compute or model capability, as the European Union and California's SB 53 do, according to the analysis. "A Chinese lab can satisfy every rule on this list without ever running a dangerous-capability evaluation," SemiAnalysis wrote.
A comprehensive AI law promised in China's 2023 and 2024 legislative plans was shelved in 2025, four months after DeepSeek's breakout, the firm said. The State Council's AI+ Action Plan targets 70% penetration of AI agents and intelligent devices by 2027 and 90% by 2030.
Scientists and officials differ on frontier risks
SemiAnalysis also reviewed 102 texts published by Chinese experts and officials between 2023 and September 2026. Technical scientists discussed frontier or loss-of-control risks in 86% of their texts, compared with 22% for legal scholars and 23% for serving officials.
The divide extended to whether safety should limit development. Of the 42 texts by technical authors, 22 argued that development should proceed only when safety conditions are met. None of the texts by legal scholars, public-policy scholars, or officials took that position.
Thirteen of the 102 texts called for binding obligations on frontier developers, including registering large training runs and submitting safety cases before release. The analysis found that none of those proposed requirements had become binding Chinese rules.
An April 2026 editorial in National Science Review, co-written by Chinese AI scientist Zeng Yi, said "the progress of AI governance is alarmingly slow" and that relying on "the self-control of AI developers is an illusion."
Other researchers questioned the motives behind warnings from US labs. At the 2026 World AI Conference in Shanghai, Zhu Songchun, director of the Beijing Institute for General Artificial Intelligence, said exaggerating AI risk "to the level of human extinction has the logic of capital behind it." He pointed to Anthropic declaring its Mythos model too dangerous to release while raising money at a trillion-dollar valuation, calling it "Oppenheimer-style marketing."
For Liu Shengyu, who wrote the main attention kernel for DeepSeek V4.1, competition with Anthropic was a reason to keep going. On September 13, he wrote that he had "no choice but to join the cruel arms race," because he did not want Anthropic controlling artificial general intelligence.
Quotes from Chinese-language sources are SemiAnalysis's translations.



