Xi Jinping at the Great Hall of the People in Beijing in 2025 (file photo). Image: Presidencia de la República del Ecuador / Wikimedia Commons, Public domain, cropped

China's biggest AI developers published a safety result alongside only 9 of the 857 models they released over five years, according to a new report from research firm SemiAnalysis. That is about 1% of launches, from a group that includes DeepSeek, Alibaba, ByteDance and Moonshot.

The report, titled "Beijing Will Not Pace the Frontier", checked every release from nine Chinese developers between 2021 and September 15, 2026 against their own model cards, release notes and technical reports. Its conclusion is blunt: China's approach to AI safety is "speed-based, not safety-based".

31 releases out of 857

Across all 857 releases, only 31 (3.6%) were ever accompanied by a published safety result from the developer. Nine of those were available at or before launch. Another 16 appeared later, with a median delay of 42 days. The longest gap was DeepSeek-R1, whose safety appendix dates to January 2026, 349 days after the model came out. The remaining six could not be matched to a release date or a specific model.

To count, a document had to give a real finding on harmful output, jailbreaks, toxicity, privacy, refusals or dangerous capabilities, tied to a named model. Saying a model was "safety-trained" was not enough. In total, 813 releases (94.9%) had no safety disclosure at all.

Releases soared from 3 a quarter in early 2023 to 101 a quarter by mid-2025, but disclosure did not follow: in nine of the last 15 quarters, not one model shipped with a safety result.

Zhipu stands out, DeepSeek slipped

The four tech giants did worst. Alibaba published results for 7 of its 238 releases, ByteDance for 2 of 120, and Tencent and Baidu for one each, out of 133 and 49. Together that is 11 of 540, or 2%. The five startups (DeepSeek, Moonshot, Zhipu, MiniMax and StepFun) managed 20 of 317.

Zhipu, which sells its models as Z.ai, is the only developer with a published result every year since 2022. DeepSeek documented its V3 model at launch, but not R1, V3.1 or the V4 family. Only three documents in the whole dataset tested for cyber-offence or biological risk, all for Zhipu's GLM-5.2 and GLM-5.3 and Moonshot's Kimi K2. Reasoning models, the fastest-moving category, were 93% undocumented. The authors say the per-company figures are indicative, not a ranking.

The report stresses that it measures what companies publish, not what they test in private: a model with no result "does not mean 'not tested.'"

"The self-control of AI developers is an illusion"

China does regulate AI, but mostly at the application layer: content labelling, minors, AI companions, agents and data. Its new AI Safety Governance Framework 3.0, issued on September 14 by the national standards committee TC260, warns of AI that improves itself, yet still lists innovation and development as "the first priority". Its standards are recommended rather than binding, and a promised national AI law was shelved in 2025. By contrast, the EU attaches duties to models trained with more than 1025 operations and California's SB 53 does the same above 1026.

The report counts 13 Chinese expert texts calling for binding rules such as compute registration, pre-release safety cases and outside audits. None has been adopted. Four leading scientists put it this way in an April editorial in National Science Review:

The progress of AI governance is alarmingly slow, and the self-control of AI developers is an illusion.

Zeng Yi, Huang Tiejun, Jiang Yugang and Poo Mu-ming, National Science Review (as translated in the report)

Not everyone agrees. Zhu Songchun, director of the Beijing Institute for General Artificial Intelligence, told this year's World AI Conference that warnings of extinction amount to "Oppenheimer-style marketing" with "the logic of capital behind it". The report's verdict on the debate: "The sad truth is neither camp decides anything. The top leadership does."

A message for Washington

The title answers a question at the heart of the US argument over slowing down. Anthropic chief executive Dario Amodei called on labs to "pace the frontier" in September, and Xi Jinping told Donald Trump last month that AI must stay "under human control". The authors argue Beijing will not slow its own labs to match, and note that Anthropic shipped Claude Opus 5.5 four days after its call, framing it as a way of "remaining competitive with China".

Why it matters

Chinese open models such as DeepSeek, Qwen and Kimi are used by developers worldwide, and this is the first full count of how rarely they ship with public safety evidence. Whatever happens in private testing, outsiders can rarely check, and the report finds no sign that Beijing's own rules have changed that.

Sources: SemiAnalysis, "Beijing Will Not Pace the Frontier: China's Speed-First AI Safety Regime" (October 8, 2026).

Latest Policy & Safety news

More Policy & Safety news