Report: Only 3.6% of Chinese AI models disclose security test results

On Thursday (October 8), a research institution in the United States released a latest report pointing out that only a tiny fraction of AI models published by major Chinese AI developers disclosed specific security test results.

The report titled “Beijing Will Not Pace the Frontier: China’s Speed-First AI Safety Regime” was published by SemiAnalysis, a California-based technology research institution headquartered in the United States.

The institution reviewed 857 models released by nine major AI development enterprises in China from 2021 to September 15, 2026. These enterprises include Alibaba, ByteDance, Tencent, Baidu, DeepSeek, Moonshot, Z.AI, MiniMax, and StepFun.

According to the report, only 31 versions of AI models (3.6%) disclosed security assessment results corresponding to specific models, of which only 9 (1.1%) were provided at the time of release or prior to release. On the other hand, 813 versions of AI models did not disclose any security testing results, accounting for 94.9% of the total.

Among the 31 versions that published security assessment results, 16 were publicly disclosed after the release of the AI models, with an average delay of 42 days. Among them, the R1 model of DeepSeek had the longest delay in disclosing security assessment results, at 349 days.

Additionally, 93% of inference AI models did not disclose any security testing results. Inference AI models are a type of AI model that “thinks before answering,” conducting multiple steps of thinking before responding to questions, and demonstrating stronger abilities in mathematics, programming, complex problems, and more.

The report also stated that no Chinese developer disclosed safety testing results in areas such as network, biology, uncontrolled risk, and dangerous capabilities when releasing cutting-edge AI models.

The researchers at SemiAnalysis emphasized in the report that the investigation focused on public disclosure and did not rule out the possibility that companies may have conducted internal testing.

The evaluation criteria for the report examined whether AI developers publicly disclosed specific test results linked to specific models, including harmful outputs, “jailbreak” defense capabilities, toxicity, privacy, denial of service, or dangerous abilities. Vague claims of models being “safely trained” were not considered.

SemiAnalysis is an independent research institution focusing on the semiconductor and artificial intelligence industries, founded by Dylan Patel in 2020. The institution releases industry newsletters through the Substack platform for paid subscriptions.

The report also noted that by quarterly statistics, the number of AI models released by Chinese enterprises increased rapidly, from 3 in the first quarter of 2023 to 101 models by the third quarter of 2025. Since mid-2023, open-source weight AI models have accounted for over half each quarter.

In terms of enterprise type statistics, among the 317 AI model versions released by five Chinese startups, 20 disclosed safety testing results (approximately 6.3%), while among the 540 AI model versions from four large enterprises, only 11 disclosed safety testing results (approximately 2%).

The report mentioned that Z.AI is the only AI developer that has disclosed safety testing results annually since 2022.

SemiAnalysis pointed out that the current approach of the Chinese government in managing AI and formulating relevant regulations primarily focuses on “user usage of AI terminal products” and “the impact of AI products on users,” rather than requiring cutting-edge AI developers to evaluate or publicly disclose the safety and potential risks of their own models.

The report specifically mentioned that the “National Network Security Standardization Technical Committee (TC260)” of the Chinese Communist Party released the “Artificial Intelligence Security Governance Framework 3.0” on September 14.

At the beginning of this document, the core principles of AI regulation are clearly outlined: placing “encouraging innovation and development” at the highest priority. Meanwhile, it does not impose mandatory requirements or obligations for setting security reviews based on the strength of AI model capabilities.