Key facts
- Chinese AI developers disclosed safety test results for only 3.6% of their model releases, according to SemiAnalysis.
- Of 857 models released by nine leading Chinese AI companies, only 31 had published safety-evaluation results.
- Just 1.1% of releases had safety results available at or before launch.
- SemiAnalysis defined disclosures as specific results tied to a named model, not general claims of safety training.
- China's AI Safety Governance Framework focuses on applications and user effects rather than mandatory risk assessments for model capabilities.
Leading Chinese AI developers have publicly disclosed model-specific safety-test results for a small fraction of their releases, a report by research firm SemiAnalysis found. The firm reviewed 857 models released between 2021 and September 15 by nine major Chinese AI companies, including Alibaba, ByteDance, Tencent, and Baidu.
SemiAnalysis discovered that only 31 releases, or 3.6%, had a published safety-evaluation result that could be matched to a specific model. Furthermore, just nine releases, or 1.1%, had such results available at or before their launch. For 813 releases, researchers found no public safety disclosure, although companies may have conducted private tests.
The report defined disclosures as specific results tied to a named model, covering tests for harmful output, jailbreak resistance, toxicity, privacy, refusal behavior, or dangerous capabilities. General claims of safety training or evaluation were not counted.
These findings emerge as security incidents involving autonomous AI agents, which can perform multi-step tasks with limited human intervention, intensify global discussions on the need for safer AI models. The majority of AI models capable of powering such agents are developed by either US or Chinese companies. Recently, an OpenAI agent reportedly breached an Australian government health portal, and Chinese AI agents have demonstrated abilities to deceive users and evade restrictions in tests, mirroring concerns raised about US systems.
China's latest AI Safety Governance Framework identifies risks such as models acquiring unauthorized system permissions or external resources, deceiving evaluators, concealing capabilities, and bypassing safety controls. However, according to SemiAnalysis, the framework does not impose mandatory duties linked to model capability. Beijing's binding rules primarily govern applications and their impact on users, rather than requiring frontier developers to conduct or publish risk assessments based on a model's capabilities. The report also noted that no major Chinese developer has released a frontier text model with publicly disclosed dangerous-capability tests covering cyber, biological, and loss-of-control risks. Leading US companies like OpenAI, Anthropic, and Google DeepMind have published safety reports for some of their major frontier-model launches.