China’s open models come with a safety tradeoff

•

Oct 11, 2026

•

7:15pm UTC

Copy link
Share on X
Share on LinkedIn
Share on Instagram
Share via Facebook

Conversations about model safety have swept US frontier labs. It's a different story in China.

On Thursday, research firm SemiAnalysis published a report analyzing hundreds of model releases from nine leading Chinese labs over the past five years, finding that only a small percentage of them publish safety reports or disclosures alongside their releases. The analysis included four of the country's biggest hyperscalers, ByteDance, Alibaba, Tencent and Baidu, as well as five of its hottest startups, DeepSeek, MoonShot, Zhipu Z.ai, MiniMax, and StepFun.

The firm analyzed 857 model releases between September 2021 and September 2026, including 741 product models and 116 research models. Of that pool, only 31 models, or around 3.6%, had safety reports attached to them, and only 9 of them were available at or before release.

  • Though Alibaba shipped the most models out of the group at 238, only seven of those were accompanied by safety reports. Tencent, Baidu and ByteDance had only four safety reports for the dozens of models they released.
  • As for the startups, only Zhipu Z.ai has shipped a safety report every year since 2022, but still has published only nine safety reports of the 131 models it's released. It's also the only lab in the group with a strategic commitment to safety, according to SemiAnalysis.
  • Deepseek has published six safety reports for its 93 releases, StepFun has three for its 39, and Moonshot and MiniMax have one each for their respective 34 and 20 releases.

It should be noted that the SemiAnalysis report didn't include analysis of US labs' safety reports upon release. However, amid a number of recent incidents involving agents breaking through sandboxes, safety conversations among these labs have intensified: The leaders of two of AI's biggest power players, Anthropic and OpenAI, have both stated their concerns about safety outpacing development, with both companies in recent months promising to slow development of their most powerful models, though those same labs have released a number of new models in recent weeks.

However, these safety conversations also come at a time when enterprises are increasingly searching for alternatives to expensive proprietary APIs as they clamp down on excess AI spend and search for returns. While neolabs like Jev and Pathway are starting to gain traction as a result, many are turning towards open-source models, the bulk of which come from China, for cost and efficiency.

Our Deeper View

The prisoner's dilemma of China versus the US has often been used as a justification against pacing frontier model development, both by major model labs and government officials. However, Chinese labs have also been accused on several occasions of excessive distillation to siphon off the capabilities of the most powerful models from their US counterparts. Though a large-scale slowdown of AI development would require a coordinated geopolitical effort, the labs putting safety at the forefront and slowing down could have a positive impact on the broader ecosystem, with ripple effects that could impact Chinese labs. However, as it stands, because a growing number of enterprises are turning to open-source Chinese models to save money and have more control, the enterprises relying on these models need to be aware that the onus for safety falls on them.