Chinese AI developers published safety results for 3.6% of reviewed releases, study finds
The review measures public disclosure, not whether testing happened privately. It also finds that China’s binding rules focus on applications rather than duties triggered by advanced model capabilities.
SemiAnalysis counted public safety findings only when they could be tied to a named model, excluding general claims of testing or safety training. That standard yielded 31 qualifying disclosures among 857 releases reviewed from nine Chinese developers between 2021 and September 15, 2026; just nine were public by launch, and the review identified no disclosure for 813. The study also found no major Chinese developer had publicly disclosed a frontier text model test spanning cyber, biological and loss-of-control risks; it offers no comparable U.S. release-level rate.
01
Qualifying findings could cover harmful output, jailbreak resistance, toxicity, privacy, refusal behavior or dangerous capabilities.
02
The 813 releases without an identified public result may still have been tested privately; the review measured disclosure, not internal work or model safety.
03
SemiAnalysis says China’s binding rules focus mainly on applications and user effects, without mandatory developer duties tied to model capabilities.
Public safety results accompanied only a small share of releases from nine leading Chinese AI developers, a SemiAnalysis study found. Of 857 releases reviewed, 31 had published results tied to a specific model. Only nine had those results available by launch—a narrower measure of what users could know when a model first became available.
The review covered releases between 2021 and September 15, 2026, from Alibaba, ByteDance, Tencent, Baidu, DeepSeek, Moonshot, Z.AI, MiniMax and StepFun. Its findings, covered by Reuters on October 9, put numbers on a disclosure gap across that group. They do not show that every release without a public result went untested.
A safety claim is not a published result
SemiAnalysis used a specific threshold: a disclosure needed to contain safety findings that could be matched to a named model. General statements that a model had received safety training or undergone evaluation did not qualify. That distinction separates an assurance about a development process from a result someone outside the company can inspect.
Qualifying results could address harmful output, resistance to jailbreaks—attempts to bypass a model’s restrictions—toxicity, privacy, refusal behavior or dangerous capabilities. The measure therefore was not limited to the most severe risks. A model-specific finding about harmful responses could count, as could an assessment of capabilities that might enable more serious harm.
Researchers found no safety disclosure for 813 releases in the materials they reviewed. Companies may have tested those systems privately. The finding is about visibility: the review could not identify a public disclosure for those releases, rather than establish what work developers did internally or whether a particular model was safe.
Public results were rarer at release
3.6%Published model-specific results
SemiAnalysis matched published safety results to 31 of the 857 reviewed releases.
1.1%Results available by launch
Nine releases had model-specific safety results available at or before launch.
Application controls versus model-capability duties
The study also examines a different gap: the distance between recognizing advanced AI risks and imposing duties on developers because of a model’s capabilities. China’s latest AI Safety Governance Framework identifies risks including models obtaining system permissions or outside resources without authorization, deceiving evaluators, concealing capabilities and bypassing safety controls.
But the framework does not impose mandatory duties linked to model capability, according to SemiAnalysis. Its account of Beijing’s binding rules describes a regime principally concerned with applications and their effects on users. That differs from requiring developers of frontier models—the most advanced systems—to conduct or publish risk assessments based on what those models can do.
The distinction becomes sharper for dangerous-capability testing. SemiAnalysis found that no major Chinese developer had released a frontier text model with publicly disclosed tests spanning cyber, biological and loss-of-control risks. That is a broader assessment than testing whether a chatbot produces harmful language or refuses a prohibited request; the report treats those as different kinds of safety evidence.
No equivalent U.S. disclosure rate
There is an important limit to any cross-border comparison. OpenAI, Anthropic and Google DeepMind have published safety reports, system cards or model cards for some major frontier-model launches, Reuters notes. Those documents provide public information about particular systems. But SemiAnalysis did not supply comparable release-by-release figures for U.S. developers, so the study cannot support a numerical ranking of the two countries’ disclosure rates.
Sources
rmb.reuters.comChina AI developers publish safety tests for just 3.6% of model releases, report finds
Reader comments
Newest comments first. Replies stay oldest first.