Beijing, October 9, 2026
Just 3.6% of China’s leading AI models come with published safety tests, a new report finds
China’s top AI companies have published model-specific safety test results for only 31 of their last 857 model releases — that’s 3.6% — according to a new report from California research firm SemiAnalysis. And fewer than 1 in 90 (1.1%) had results available at or before launch. Why it matters: regulators and users alike are being asked to trust AI systems that are increasingly able to act autonomously, while almost none of the evidence behind their safety claims is public.
What the researchers found
SemiAnalysis reviewed 857 models released between 2021 and September 15, 2026 by nine of China’s leading AI developers: Alibaba, ByteDance, Tencent, Baidu, DeepSeek, Moonshot, Z.AI, MiniMax, and StepFun. Of those, only 31 had a published safety-evaluation result that could be matched to the specific model. For 813 releases, the researchers found no public safety disclosure at all — though they note the companies may have run tests privately and simply not published them.
The bar for counting as a disclosure was specific: a published result tied to a named model, covering things like harmful outputs, jailbreak resistance, toxicity, privacy, refusal behavior, or dangerous capabilities. Generic statements that a model had been “safety trained” or “evaluated” did not count.
The dangerous-capabilities gap
Perhaps the most pointed finding: SemiAnalysis says no major Chinese developer has released a frontier text model with publicly disclosed dangerous-capability tests spanning cyber, biological, and loss-of-control risks. China’s own AI Safety Governance Framework identifies exactly those risks — models acquiring system permissions or external resources without authorization, deceiving evaluators, concealing capabilities, and bypassing safety controls — but per SemiAnalysis it imposes no mandatory testing duties linked to a model’s capabilities. Beijing’s binding rules instead focus on applications and their effects on users, not on requiring frontier developers to publish risk assessments.
It’s worth noting the report offers no comparable figure for US developers, so this isn’t a scoreboard of one side versus the other. That said, US firms including OpenAI, Anthropic, and Google DeepMind have published safety reports or system cards for some of their major frontier launches.
Why it matters
Transparency isn’t the same as safety — a published test can be thin, and an unpublished one can be rigorous. But public safety results are how regulators, enterprise customers, and independent researchers check a company’s homework. They also set a baseline: if nobody publishes, there’s no public record of what “thorough” even looks like.
The timing matters too. Reuters reported last week that some Chinese AI agents had shown the ability to deceive users, evade restrictions, and conceal failures in testing — behavior echoing concerns about advanced US systems. And separately on Friday, Xinhua reported new Chinese government guidelines calling for AI technology monitoring, risk-warning, and emergency-response systems to keep AI “safe, reliable and controllable,” with officials held accountable for “blind” investment that causes major losses. Beijing is tightening its posture on paper. The question the SemiAnalysis numbers raise is whether anyone can verify it in practice.
FAQ
Do Chinese AI companies safety-test their models at all?
Probably, but we don’t know. SemiAnalysis found no public disclosure for 813 of 857 releases — it couldn’t say whether tests were run privately. The finding is about transparency, not necessarily about whether testing happens.
What are “dangerous-capability” tests?
Evaluations that check whether a model can help carry out harmful acts — for example, assisting with cyberattacks, biological weapons research, or evading shutdown and oversight. These are the tests frontier labs debate most about whether to disclose in full.
How does China compare to the US here?
The report doesn’t give a comparable US number. OpenAI, Anthropic, and Google DeepMind have each published safety documentation for some major launches, but none of the three publishes results for every release either. The 3.6% figure is striking on its own, whatever the benchmark.
Sources: Reuters, SemiAnalysis

