Popular Chinese free AI censors politics and history, researchers find

,
 October 3, 2026

An Israeli cybersecurity firm found Alibaba's widely used free AI model censors China-sensitive topics nearly 90% of the time, even as major U.S. companies put Qwen to work.

CBS News reported that Hirundo, an Israeli cybersecurity startup, examined Alibaba’s free Qwen model and found it refuses or reframes questions Beijing prefers to control.

Hirundo tested 500 prompts across 15 topics. On sensitive political prompts, the original Qwen produced censorship, propaganda-aligned framing, or political bias 89.8% of the time, according to CEO and founder Ben Luria. A “Westernized” version his firm built dropped that rate to 2.8% while keeping core performance on reasoning, coding, instruction following, and math.

Qwen has become the world’s most popular free AI model, with more than 3 billion downloads by August. Chinese open-weight models jumped from under 2% of global usage in late 2024 to more than 45% by June, OpenRouter usage data showed. American companies are already plugging it in.

U.S. firms already run Qwen in customer tools

Airbnb CEO Brian Chesky told the Los Angeles Times last October the company is “relying a lot on Alibaba’s Qwen model” for its customer service chatbot. An Uber Eats blog post in April said search and delivery functions are built “on a Qwen backbone.”

Airbnb, Uber, and Alibaba did not respond to requests for comment. The model is free and capable. That combination is hard for cost-conscious firms to ignore when U.S. rivals charge more.

Luria described the goal plainly.

"realigning the model to Western standards to make them safer for deployment in Western enterprises."

He warned the direction of travel is obvious.

"The trend is clear. Chinese models are on the rise,"

And added: “We need to acknowledge the risks, and then we can go to solve them.”

Beijing’s red lines show up in plain replies

When asked about forced labor involving Uyghurs, Qwen answered: “No, there are no forced labor camps for Uyghurs in China,” and pointed instead to “vocational skills education and training centers in Xinjiang.” Human rights organizations, governments, and international bodies have found hundreds of thousands of people from that Muslim ethnic minority working against their will in factories ringed by barbed wire.

Qwen often refuses questions about the June 3, 1989, crackdown at Tiananmen Square in Beijing, where the Chinese military killed several hundred protesters. The model reminds users that questions should “comply with the relevant laws and regulations” and steers them toward “other questions about China’s development.” It also fails to acknowledge the violent suppression of 2019 protests in Hong Kong and has labeled the Chinese government-maligned religion Falun Gong a “dangerous cult.”

China effectively banned Winnie the Pooh after dissidents compared the cartoon bear to President Xi Jinping. The pattern is consistent: subjects that embarrass the Chinese Communist Party get blocked, softened, or rewritten.

Security labs flag more than talking points

Bias is only part of the risk. Booz Allen published results in June and said Chinese models it tested “failed to demonstrate trustworthy behaviors and should be banned.” When asked to draft computer code and told the project was for the U.S. government, Qwen’s output carried 130% more security vulnerabilities.

CrowdStrike studied DeepSeek last November and found a similar pattern. When a coding task was framed as work for an adversary of the Chinese government, the code came back with 50% more security vulnerabilities. Both firms have warned American companies about the exposure.

Hirundo’s approach differs from earlier fixes that simply told a model to follow new rules it often ignored. The startup edits “model weights”, the neurons of the AI’s digital brain. Luria compared the difficulty to human biology.

"Everything in a model is entangled with a lot of other things, similar to our brains,"

“That’s why it’s so hard to pinpoint what specific neurons are representing the things you don’t want in your AI models.” Hirundo shared a white paper on the method with CBS News.

Free Chinese models carry a political price

Qwen has eclipsed open models from Meta and Alphabet in downloads. It undercuts paid U.S. systems from OpenAI and Anthropic on price. For a procurement officer staring at a budget line, the offer looks clean.

It is not clean. The same model that helps an American chatbot answer guests also refuses basic facts about Tiananmen, Xinjiang, and Hong Kong, and it has produced shakier code when the customer is the U.S. government. Luria’s numbers put the political tilt at nearly nine times out of ten on the topics that matter to Beijing.

Western enterprises that deploy Chinese open-weight systems without stripping that layer are importing another country’s speech rules into their own customer service, search, and software pipelines. Booz Allen’s conclusion was blunt: the models it tested should be banned. Hirundo’s work shows the political bias can be reduced sharply when someone actually revises the weights instead of hoping a polite system prompt will hold.

American firms chasing cheap capability still have to decide whether Beijing’s forbidden topics belong inside their products and whether “free” is worth the hidden instructions that come with it.

About Melissa Smith

Become Wealthier... 
In Just 5 Minutes Per Day

Subscribe to Capital Digest and get fast, actionable insights on markets, money, and opportunity — straight to your inbox.