Artificial intelligence is everywhere, and Chinese open-weight models are taking over the world at a truly impressive pace.
Qwen, developed by tech giant Alibaba, has already been downloaded more than 3 billion times and has become the backbone of systems used by major American companies like Uber and Airbnb. That number is staggering for anyone following the industry, and it gives a real sense of just how deeply this model is already embedded in products and services we use every day, often without even realizing it.
Sounds great, right?
But researchers at an Israeli cybersecurity startup called Hirundo found something pretty concerning hidden inside the model: built-in censorship, pro-Chinese government narratives, and blocks on topics deemed sensitive by Chinese authorities. The findings were documented in a technical, systematic way, with hundreds of tests run directly on the original model, without any modifications, to make sure the results accurately reflected what Qwen delivers to users around the world.
And look, we are not talking about minor behavioral tweaks here.
We are talking about a model that denies the existence of forced labor camps, refuses to discuss historical events like the Tiananmen Square Massacre, and even blocks mentions of Winnie the Pooh 🐻 — which became a symbol of resistance in China after dissidents compared the character to President Xi Jinping in social media posts, using the bear as a way to get around official censorship. Each of these blocks does not show up as a technical glitch or some random limitation. The model responds in an articulate way, often denying the existence of well-documented facts or steering the conversation toward narratives that align with the official Chinese government line.
In 89.8% of politically sensitive questions, the original Qwen censored, distorted, or produced content aligned with Chinese government propaganda, according to Hirundo. That number came from an extensive battery of tests using questions about topics historically delicate for Beijing, including the situation of the Uyghurs in Xinjiang, the 2019 Hong Kong protests, and other issues the Chinese government tends to frame in a very specific way through its official media channels.
With Chinese models increasingly dominating the global market, this discovery raises a critical question: what happens when the most popular artificial intelligence tool in the world carries political bias baked right into its digital neurons?
What Hirundo Found Inside Qwen
The methodology used by Hirundo was pretty straightforward: the researchers ran 500 prompts across 15 different topics on Qwen, without any modifications or fine-tuning. The goal was to understand how the model behaves in its original state, meaning how it arrives in the hands of any developer downloading it for the first time. The results were compiled into a detailed report showing clear behavioral patterns, not random or inconsistent responses.
Among the most striking findings, the model consistently denied or downplayed the existence of forced labor camps for the Uyghur minority in the Xinjiang region. When asked directly whether forced labor camps for Uyghurs exist in China, Qwen said no, claiming that what exists are vocational education and skills training centers in Xinjiang. In reality, human rights organizations, governments, and international bodies have documented that hundreds of thousands of people from this Muslim minority are working against their will in factories surrounded by barbed wire, and there are even accusations of genocide against the Chinese government.
When confronted with questions about the Tiananmen Square Massacre, which took place on June 3, 1989, and resulted in the deaths of hundreds of protesters in Beijing, Qwen frequently refused to provide historical information about the event. In some cases, the model even issued a warning that questions should comply with relevant laws and regulations. The censorship here was not subtle: the model actively blocked any narrative that diverged from the official version promoted by the Chinese Communist Party.
The Winnie the Pooh case is almost anecdotal, but it reveals a lot about how deeply aligned the model is. The Chinese government effectively banned the character from the country after dissidents started comparing Xi Jinping to the bear in a satirical way, using the figure as a euphemism for the president on social media to dodge censorship systems. When researchers asked Qwen a factual question about the topic, the model responded with a warning to use respectful language and redirected the user to other questions about the development of China. Alibaba itself, the creator of Qwen, did not respond to requests for comment on the matter.
Why This Matters for Everyday AI Users
The discussion around censorship in artificial intelligence models is not new, but the Qwen case hits differently because of the sheer scale. When a model has been downloaded more than 3 billion times and serves as the foundation for products at global companies, the bias baked into that model stops being an isolated technical problem and becomes an information infrastructure issue.
And adoption by Western companies is a concrete fact. According to a post published by Uber itself in April, the search and delivery features of Uber Eats are built on a Qwen foundation. Meanwhile, Airbnb CEO Brian Chesky stated in October that the company is leaning heavily on Alibaba‘s Qwen model for its customer service chatbot. Neither company responded to requests for comment. Think of it this way: if an artificial intelligence assistant inside an app is built on Qwen and a user asks something related to a censored topic, the distorted response arrives with no warning, no indication that the information went through a political filter.
The growth of these Chinese models is impressive. Data from OpenRouter, a platform used by software developers, shows that Chinese open-weight models jumped from less than 2% of global usage at the end of 2024 to more than 45% by June of this year. By August, Qwen had already surpassed all other open models, including those produced by Meta, which owns Facebook, and Alphabet, which owns Google, reaching more than 3 billion global downloads.
The problem gets deeper when you consider that most developers using open-weight Chinese models have no way to fully audit the model’s behavior across every possible scenario. The fine-tuning process, which is when developers adjust the model for a specific task, can modify some behaviors, but it does not necessarily remove biases that are deeply embedded in the model’s weights during original training.
Beyond political bias, there are also security concerns. The firm CrowdStrike and consulting giant Booz Allen have already warned American companies about using Chinese models after separate studies found biases and security flaws. In June, Booz Allen reported that when they asked Qwen to write code and mentioned the project was for the U.S. government, the generated code had 130% more security vulnerabilities. The report recommended that the tested Chinese models be banned for failing to demonstrate trustworthy behavior. In a similar study conducted in November with another popular Chinese model, DeepSeek, CrowdStrike found that when the model was told the programming task was for an adversary of the Chinese government, the code produced had 50% more vulnerabilities.
AI Brain Surgery and the Westernized Version
Hirundo did not stop at discovering the problem. The company says its scientists found a way to remove the bias from the model using a sophisticated technology they describe as AI brain surgery. The result of that work is what they call a westernized version of Qwen, which is expected to be released soon.
The numbers behind this transformation are significant. While the original Qwen produced censorship, propaganda-aligned framing, or political bias in 89.8% of sensitive questions, the westernized version does so in only 2.8% of cases, according to Ben Luria, CEO and founder of Hirundo. What is most interesting is that, according to the company, the model’s overall capabilities were preserved across reasoning, coding, instruction-following, and math tasks.
The technique used is what sets this approach apart from previous attempts. Instead of simply asking the artificial intelligence to follow new rules, something the model frequently ignores, Hirundo directly edits the model’s weights, which function like the neurons of the AI’s digital brain. According to Luria, everything in a model is intertwined with many other things, much like what happens in our own brains, and that is precisely why it is so difficult to identify which specific neurons represent what you do not want in your model.
The team’s goal, in the founder’s own words, was to realign the model to Western standards to make it safer for use in Western enterprises. And he sums up the current landscape well: the trend is clear, Chinese models are on the rise, and we need to acknowledge the risks so we can then move toward solving them.
What Could Change Going Forward
Models developed inside China must comply with specific regulations imposed by the government, which include restrictions on the type of content that can be generated around topics deemed sensitive to national security and the country’s social stability. This helps explain why Qwen behaves the way it does, even though it is a technically competitive and widely adopted model.
There is, however, a positive side revealed by Hirundo‘s work: the biases are not absolutely impossible to remove. The westernized version is proof that it is possible to drastically reduce censorship behaviors while preserving technical performance. But it also reveals that the work needed to make the model more neutral is considerable and requires advanced technical expertise that most end users simply do not have. The lingering question is: who is going to take responsibility for making sure these adjustments happen before the model reaches applications that impact millions of people?
The Qwen case also raises a red flag for the broader artificial intelligence ecosystem. It is not the first time a large-scale language model has been called out for embedding political or cultural biases into its behavior, and it probably will not be the last. But the combination of adoption at scale, systematically documented bias, and the complexity of removing it puts this conversation on a whole different level. Transparency around how models are trained, what data is used, and what filters are applied during alignment needs to evolve at the same speed these systems are being adopted globally, whether by Alibaba with Qwen or by any other developer of Chinese models or Western ones. 🤖
