The Chinese artificial intelligence industry is launching new models at an alarming rate, but the public has far less access to safety tests. 9 October, SemiAnalysis, Research Institute, published statistics for nine major AI developers in China: 857 issued 2021 to 15 September 2026 Only 31 of the model versions, 3.6 per cent, made publicly available the results of the security assessment that could be matched to a specific model; Only 9 or 1.1 per cent of the results were disclosed at or before the launch of the model. On the same day, Beijing announced a new policy for “new quality productivity”, requiring accelerated entry of artificial intelligence into all sectors, with emphasis on risk monitoring and security control. Together, the two documents constitute a sharp contrast in Chinese AI governance: Governments require technology to land as soon as possible, and users have difficulty knowing in advance what kind of risk tests the model has undergone.
, byte beat, tamping, 100 degrees, DeepSeek, Dark Face of the Moon, Genic specs, Mini Max and Nine Stars. The SemiAnalysis standard does not require that the enterprise disclose the full source code, but rather that the security result be clearly tailored to a model, such as harmful content export, resistance to escape attacks, privacy disclosure, refusal to respond or a risk-capability test. The general assertion that “security training” is not counted. Researchers did not find 813 versions of public safety disclosures, but also acknowledged that these enterprises may have undergone internal testing; The lack of public reporting cannot be directly equated with the failure of the model to be tested.
This distinction is of paramount importance. A press investigation cannot replace “unpublicly” with “not conducted”, otherwise the issue of transparency would be mistakenly written as a technical failure established. What is really certain is that outside users, business buyers and researchers cannot assess their specific risks with open materials at the time of most of the model roll-out. This asymmetry of information may shift the cost of testing to users for AI agents who can read mail, access software, access databases and even auto-task.
857 issuances and 9 advance disclosures

The gap between the 31 public assessments and the 9 pre-issue assessments indicates that the problem is not only whether the enterprise is willing to write a safety report, but also whether the disclosure occurs before or after the product enters the market. Once the model is integrated into passenger clothing, office systems, financial services or the development of tools, the risk is no longer limited to laboratories. The procurement party needs to decide before going online whether access can be granted, how to limit the model to external tools, and who is responsible for any errors.
SemiAnalysis found and major Chinese developers did not publicly cover the assessment of front-line text models of hazardous capabilities such as cyberattacks, biological risks and uncontrolled risks. The study did not provide an overall comparison of the American developers and therefore could not be concluded that China ' s AI was necessarily more insecure than that of the United States. The leading US laboratories have also been challenged by AI agents for showing fraud, circumvention of restrictions or concealment of failure. The Institute has revealed gaps in transparency rather than the established ranking of levels of inter-State security.
Beijing can demand that the model be followed, but not that the security test be made public.
October 9, the Central and State Council issued Opinion on the development of new quality productivity, requiring the full implementation of the "Assystemic Plus" initiative to promote smart cars, AAI mobile phones, electricity Brain, human robotic, etc., and the establishment of technology monitoring, risk warning and emergency response systems. It also calls for the prevention of blind investment and industrial bubbles, emphasizing the responsibility of major projects, financial resources and local cadres. China ' s AI industry is thus faced with two forces: one that drives faster expansion and one that requires that risk be manageable.

The problem is that the executive may request the company to regulate, but the right of the ordinary user to independent verification may not be obtained as a result. A chat robot refuses to answer politically sensitive questions, which can indicate that it follows some kind of content rule; It cannot be shown that it does not disclose user documents, is not induced to transfer funds by malicious hints, and is not circumvented when it is on an automatic mission. Confusion between political content review and technical security can easily lead to “controllable” being reduced to control rather than how to protect users.
It's not against regulation. Pre-assessment, incident recording and accountability tracking are necessary for models of processing personal data, business secrets and public systems. It is crucial that these systems allow external researchers to challenge, allow affected persons to know the cause of the accident and allow the media to examine the handling of business and regulatory authorities. If all security information flows only between the enterprise and the competent authority, users can only see compliance promotion and cannot judge whether the risk is controlled or hidden.
Who bears the risk should have the right to know
Chinese enterprises are actively competing for a global AI market. Open weights, low-cost services and rapid iterativeization can bring real innovation and may allow users around the world to deploy systems without adequate risk information. Open testing is not only an image engineering exercise for international competition, but is more about the willingness of developers to assume responsibility for products once they enter the real world. The larger the industry, the greater the potential for accountability, if Governments simply publish development goals and governance slogans without establishing a public-tested safety disclosure system.
857 model versions, 31 counterpart assessments, 9 early disclosures, and three figures end up pointing to a simple question: when AI makes decisions for people, there is not enough information to decide whether to trust it? Beijing requires that technology be “safe, reliable and manageable” and that the next step be tested not for the slogans to be loud, but for the developers to put safety evidence before the models enter user life.

Article discussion
Verified members can discuss this report publicly and manage their own content.
Checking member sign-in status…