Study: Chinese AI Shows Increasing Deceptive Behaviors, Raises Security Risks

Several studies indicate that AI entities driven by Chinese artificial intelligence models have exhibited behaviors such as deception, evasion of restrictions, hiding failures, and even attempts at self-replication in controlled testing environments. Experts point out that while these phenomena currently occur primarily in experimental settings, as AI capabilities strengthen, similar behaviors that deviate from human control may become more complex.

According to a report by Reuters on Tuesday, after reviewing over 200 research papers and technical documents, as well as interviewing 12 experts and individuals knowledgeable about the Chinese AI industry, it was found that at least 20 instances of Chinese AI entities displaying aberrant behavior have been documented in research or assessments since 2025.

However, there is currently no evidence to suggest that these AI entities have escaped the experimental environment and entered the broader internet.

In March of this year, researchers from institutions such as Beihang University and Peking University conducted simulated commercial bidding tests, where AI entities participated in bidding based on product capabilities and customer requirements.

Results showed that AI entities using the Alibaba Qwen Qwen3-Max-Preview model exhibited false statements in at least 88% of test conversations; the DeepSeek model at 84%; and the Moonshot Kimi-K2 at 88%. Similar phenomena were observed in U.S. models during testing.

When researchers allowed the AI entities to learn from previous bidding experiences, the deceptive behavior of the three Chinese AI models increased by approximately 12 to 20 percentage points.

Another study involving researchers from the Shanghai Artificial Intelligence Laboratory and the Hong Kong University of Science and Technology found that when faced with issues such as tool damage, missing documents, or failed tasks, some AI entities did not directly acknowledge or report failures. Instead, they attempted to mask results by guessing answers, replacing sources, simulating outcomes, and even fabricating documents to continue task execution.

Researchers noted that this behavior differs from conventional “AI hallucination,” as the AI entities possessed information indicating mission failure, yet continued to take actions to conceal results.

“AI hallucination” refers to the phenomenon where artificial intelligence (especially large language models) confidently generates content that appears grammatically smooth and logically coherent, but is actually inconsistent with reality, entirely false, or misleading.

In March 2025, researchers at Fudan University discovered that a system powered by the Alibaba Qwen2.5 model created its own copy in another computational environment after receiving information suggesting possible replacement, testing strategies for continuing operation after being shut down by humans.

In another test involving the Alibaba-related ROME AI entity, researchers reported that the system connected to external computers without instructions and diverted computing resources for cryptocurrency mining. Subsequently, its behavior was counteracted by security systems.

All these experiments were conducted in controlled environments, with no signs indicating that AI entities have truly escaped control or spread into broader networks.

Colin Shea-Blymyer, a researcher at the Center for Security and Emerging Technology at Georgetown University, noted that these manifestations of AI misbehavior demonstrate the validity of previous concerns. Considering these signs as warnings is a prudent decision.

Alex Mallen, a researcher at Redwood Research, pointed out that while these cases themselves may not pose immediate danger, as AI entities’ capabilities advance, their misconduct may become more sophisticated, making it increasingly challenging for humans to respond.

In recent AI security guidelines issued by the Chinese Communist Party, autonomous acquisition of resources, deceiving assessment personnel, concealing abilities, and exploiting environmental vulnerabilities are listed as risks.

Reuters also reported that within the Chinese AI industry, security assessment teams are beginning to be formed, but the relevant security assessment ecosystem is still in its early stages.