ThinkFacility Sign in
  1. Home
  2. News
  3. AI safety

Chinese AI labs published safety results for 3.6% of 857 models, SemiAnalysis finds

Only one of the nine developers, Zhipu, has published a safety result every year since 2022.

On October 8, 2026, SemiAnalysis published Beijing Will Not Pace the Frontier, a study of what China's government and its nine leading AI developers actually do about safety. Mark Chen, Doug and Dylan Patel built a dataset of 857 model releases from those nine, running from 2021 to September 15, 2026.

Only 31 of the releases ever came with a published safety result from the developer. Just 9 had one at or before launch.

Releases counted
857, from 2021 to 15 September 2026
With any safety result
31, or 3.6%
Result at launch
9, or 1.1%
No safety disclosure
813 releases, 94.9%

Who was counted

The nine are four hyperscalers (ByteDance, Alibaba, Tencent and Baidu) and five startups: DeepSeek, Moonshot, Zhipu (Z.ai), MiniMax and StepFun. The bar is strict. A result has to be a real finding on harmful output, jailbreaks, refusals or dangerous capability, tied to the named model, and a line saying a model was "safety-trained" doesn't count.

A glass visitor center and a tall glass office tower behind a paved plaza, with a red Alibaba sign and the Olympic rings on a low wall between them
Alibaba's Chaoyang Technology Park in Beijing. Alibaba had the most releases in the count, 238. Photo: HoweyYuan, CC BY-SA 4.0, via Wikimedia Commons

The authors are careful about what a gap means. "Not found" covers only the model cards, release notes and reports they checked. (It's a count of what was published, so a lab that tests and keeps quiet looks the same as one that doesn't test.) Alibaba's total is also inflated by naming, since every Qwen size and snapshot counts as a release.

Releases rose, disclosures didn't

Releases went from 3 in the first quarter of 2023 to 101 in the third quarter of 2025. Releases with any safety result never passed 7 in a quarter.

No company reports as a matter of routine. Alibaba has 7 releases with a result out of 238, Tencent 1 of 133 and ByteDance 2 of 120. The startups do better than the giants, at 6.3% against 2%, and Zhipu is the only developer with a result every year since 2022.

Every 2026 frontier release the authors list, from the DeepSeek V4 family to Qwen3.8-Max, shipped with nothing at launch. GLM-5.3 was the one exception, with a capability evaluation note.

Reasoning models, the fastest-advancing category, are 93% without any published results.

From Beijing Will Not Pace the Frontier: China’s Speed-First AI Safety Regime

What the people in charge say

The team also gathered 65 public statements on safety from the people running the nine labs, January 2023 to September 21, 2026. Just fifteen statements by founders, CEOs or chief scientists engage with frontier safety. Of the nine that raise a concern and propose something, six come from Zhipu.

At five of the nine labs the founder or CEO has said nothing on it. DeepSeek's Liang Wenfeng has made no public statement on safety or regulation in four years, the authors write.

Moonshot's Yang Zhilin did acknowledge the risk, then kept going. In January 2026 he said that giving up development "means giving up the pursuit of the ceiling of human civilization."

Where Beijing's rules stop

China's rules are tight on content labeling, minors and AI companions, which govern what AI says and does to people. None of them sets a duty triggered by training compute or model capability, so a lab can meet all of them without running a dangerous-capability evaluation.

The authors turn the point back on Anthropic too. Dario Amodei asked the labs to pace the frontier on September 12, and the Claude Opus 5.5 launch post later framed pacing as a way of "remaining competitive with China."

Nobody paces alone, not even the man who wrote the essay.

Beijing Will Not Pace the Frontier: China’s Speed-First AI Safety Regime

The rest of the report, on the Trump-Xi summit and the tests over the next six months that would change the authors' minds, sits behind SemiAnalysis's paywall.

More on AI safety

All AI safety stories