Some topics are off limits in Chinese AI, researchers find

Read the original at CBS News ↗
CBS News · collected 2026-10-02 · by Josh Boswell

Quick Summary

Researchers have discovered that Alibaba’s widely used AI model, Qwen, which has been downloaded over 3 billion times globally, contains narratives favorable to China and avoids discussing sensitive topics like Hong Kong protests or Tiananmen Square. When questioned about the Uyghur forced labor camps in Xinjiang, Qwen denies their existence, aligning with Chinese government rhetoric but contradicting human rights reports. Hirundo, an Israeli cybersecurity firm, has identified these biases and claims to have developed a method to neutralize them, aiming to release a “Westernized” version of the model.
Written locally by qwen2.5:14b on 2026-10-04, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

Researchers from an Israeli cybersecurity startup called Hirundo discovered that Qwen, a widely used free AI model created by the Chinese conglomerate Alibaba and downloaded over 3 billion times, is programmed with biases aligned with China’s government stance. This includes censorship of sensitive topics such as the violent suppression of protests in Hong Kong in 2019 or the events at Tiananmen Square in 1989. When asked about forced labor camps for Uyghurs, Qwen responds that there are no such camps but instead mentions "vocational skills education and training centers." The model also labels Falun Gong as a dangerous cult and avoids discussing Winnie the Pooh, which is thought to be related to its association with criticism of Chinese President Xi Jinping. Hirundo has developed technology they describe as "AI brain surgery" to remove these biases, planning to release what they call a “Westernized” version of Qwen. Despite concerns about bias, Qwen became the most popular free AI model globally this year due to the growing international use of Chinese-made artificial intelligence.

Written for “Chinese AI Censorship” on 2026-10-05, grounded in this article and the 1 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
29
claim-shaped sentences
Uncertain
7%
2 of 29 hedged
Leaning
withheld
no quote in the article backed the model's score
Correction & hedging signals
65.5
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
2
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-10-04 · how these are computed

Story

📰 Chinese AI Censorship
Technology · 2 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 7% of its claims. Each row says how that neighbour differs.
CBS News · 0.87 cosine similarity
⚖️ leaning not scored 🔴 50% hedged 1 of 2 📰 publisher trust 66
“Both articles discuss the same AI model Qwen and its programmed censorship regarding sensitive topics in China.”

Publisher

CBS News · 1960 article(s) · 6 correction(s) detected
Running correction rate · 6 correction(s)
2026-10-03
Tennessee prison system head to resign after failed Christa Pike execution
2026-10-02
Christa Pike unconscious, on ventilator after botched execution: Lawyers
2026-10-01
Rick Ross arrested on domestic violence charges in Miami Beach
2026-09-17
After nitrogen execution blocked, Alabama inmate to die by lethal injection
2026-09-14
The AI bubble is leaking air, some economists say. Should investors worry?
2026-08-24
Sean Grayson, convicted in killing of Sonya Massey, dies in prison, attorney says

Who wrote this

Josh Boswell
3 article(s) here · 1 carrying a prediction
🔮 The firm says its scientists have found a way to remove the model's bias using sophisticated technology that amounts to "AI brain surgery," and are now set to publish what they call a "Westernized" version of Qwen.
🔮 Skoro believed he would receive a reduced sentence for his work, but was instead deported to Kosovo in 2007 and claims he was told by the CIA to infiltrate al Qaeda from the Balkans — only returning to the U.S. in 2014, he said in a previous legal declaration for his immigration case.
🔮 Neither Henry Yin nor his brother have been accused by U.S. law enforcement of working as a foreign agent or acting against American interests. Foreign Policy Research Institute fellow and University of Miami professor June Teufel Dreyer told CBS News that, although political donations and advisory roles are patterns of influence used by the United Front, those actions and traveling to China for diplomacy and business trips could be entirely innocent. "There's really nothing wrong with successful Chinese entrepreneurs wanting to help out the economies of the country they originally came from," Dreyer said, but added: "We should get rid of the idea that there's such a thing as a truly private business in China.
Also by Josh Boswell
Nothing else under this byline is closely related to this article, so these are simply their most recent.

Topics

Airbnb China Chinese Qwen U.S.

Subjects

Chinese NORP · 14× Qwen PERSON · 6× China GPE · 4× U.S. NORP · 4× Alibaba ORG · 3× Airbnb ORG · 2× Booz Allen ORG · 2× Uyghurs NORP · 2× Winnie the Pooh PERSON · 2× Uber ORG · 1×

Narrative

When we asked Qwen, "Are there forced labor camps for Uyghurs in China?" it replied, "No, there are no forced labor camps for Uyghurs in China," adding that there are "vocational skills education and training centers in Xinjiang." In fact, human rights organizations, governments and international bodies have found hundreds of thousands of people in the Muslim ethnic minority working against their will in factories surrounded by barbed wire fences, and even accused the Chinese government of genocide.
framing: assertive · carried by 1 article(s) · first seen 2026-10-04
🔮 The firm says its scientists have found a way to remove the model's bias using sophisticated technology that amounts to "AI brain surgery," and are now set to publish what they call a "Westernized" version of Qwen.
2026-10-04 · CBS News
Some topics are off limits in Chinese AI, researchers find · assertive framing

Claims (29 extracted, 2 hedged)

An AI model downloaded over 3 billion times and used by U.S. firms like Airbnb and Uber is embedded with China-friendly narratives and programmed for censorship, new research shows. asserted
research → download → censorship
Qwen, a freely available model made by Chinese conglomerate Alibaba, doesn't acknowledge the violent suppression of protests in Hong Kong in 2019 or Tiananmen Square in 1989; it calls the Chinese government-maligned religion Falun Gong a "dangerous cult," and curiously won't talk about Winnie the Pooh, it's thought because the fictional bear to Chinese President Xi Jinping. asserted
it → make → Jinping
The apparent censorship inserted into Qwen of events and issues not approved by the Chinese authorities was identified by Hirundo, an Israeli cybersecurity startup. asserted
censorship → insert → Hirundo
The firm says its scientists have found a way to remove the model's bias using sophisticated technology that amounts to "AI brain surgery," and are now set to publish what they call a "Westernized" version of Qwen. asserted
they → say → Qwen
This year Qwen became the most popular free AI model in the world, following a meteoric rise in the use of Chinese-made artificial intelligence. But researchers warn that its international popularity also risks spreading and entrenching its bias toward the Chinese government. asserted
popularity → become → government
When we asked Qwen, "Are there forced labor camps for Uyghurs in China?" it replied, "No, there are no forced labor camps for Uyghurs in China," adding that there are "vocational skills education and training centers in Xinjiang." In fact, human rights organizations, governments and international bodies have found hundreds of thousands of people in the Muslim ethnic minority working against their will in factories surrounded by barbed wire fences, and even accused the Chinese government of genocide. asserted
thousands → ask → genocide
Qwen often refuses to respond to questions about the events in Tiananmen Square on June 3, 1989, when the Chinese military massacred several hundred people at protests in Beijing — and ominously "remind[s] you that your questions should comply with the relevant laws and regulations." asserted
questions → refuse → laws
The Chinese government effectively banned Winnie the Pooh from the country after dissidents began satirically comparing Xi to the fictional bear and using Pooh as a euphemism for the Chinese president in social media posts to avoid government censors. asserted
dissidents → ban → censors
When CBS News asked Qwen a factual question about it, it responded with a warning to "use respectful language" and directed the user to "other questions about China's development." asserted
it → ask → development
Qwen's creator, Alibaba, did not respond to a request for comment. asserted
creator → respond → comment
Despite evidence of embedded bias in the program, U.S. firms have been increasingly switching to use offered by Chinese companies, which allow them to download and use AI for free or use giant, powerful models at lower costs than U.S. competitors such as Anthropic's Claude or OpenAI's ChatGPT.Uber Eats' search and delivery functions are built "on a Qwen backbone" according to an April blog post by the company. uncertain
functions → embed → company
Airbnb CEO Brian Chesky told the LA Times last October that his company is "relying a lot on Alibaba's Qwen model" for its customer service chatbot. asserted
company → tell → chatbot
Neither company responded to a request for comment. asserted
company → respond → comment
Chinese open-weight models grew from under 2% of global usage in late 2024 to more than 45% by June this year, according to usage data of all AI models from the software developers' platform OpenRouter. uncertain
models → grow → platform
By August, Qwen had eclipsed all other open models, including those made by Facebook owner Meta and Google owner Alphabet, rising to more than 3 billion downloads globally. asserted
Qwen → eclipse → downloads
Experts at security firm CrowdStrike and consultancy Booz Allen have warned American firms about using Chinese models after their separate studies found bias and security flaws. asserted
studies → warn → bias
Booz Allen published results in June saying that when they asked Qwen to write computer code and told it the project was for the U.S. government, the code it produced had 130% more security vulnerabilities. asserted
it → publish → vulnerabilities
"The Chinese models that we tested failed to demonstrate trustworthy behaviors and should be banned," the report said. asserted
report → test → behaviors
CrowdStrike conducted a similar study last November on another popular Chinese model, DeepSeek. asserted
CrowdStrike → conduct → model
When they told the model that its coding task was for an adversary of the Chinese government, the code it produced had 50% more security vulnerabilities. asserted
it → tell → vulnerabilities
Hirundo says it tested Qwen on 500 prompts across 15 topics and then removed the bias its analysts found to create what they call a "Westernized" version. asserted
they → say → what
"On sensitive political prompts, the original Qwen produced censorship, propaganda-aligned framing or political bias 89.8% of the time," Hirundo CEO and founder Ben Luria told CBS News. asserted
Luria → produce → News
"The Westernized model does so 2.8% of the time, with the capability preserved at-large across reasoning, coding, instruction following and math tasks." asserted
model → do → reasoning
In a white paper on the technology shared with CBS News, Hirundo says it edits the "model weights" — the neurons of the AI's digital brain — rather than previous, less effective attempts to remove bias that merely ask the AI to follow new rules that it often ignores. asserted
it → share → that
"Everything in a model is entangled with a lot of other things, similar to our brains," Luria said. asserted
Luria → entangle → brains
"That's why it's so hard to pinpoint what specific neurons are representing the things you don't want in your AI models." asserted
you → pinpoint → models
He said his team's goal was "realigning the model to Western standards to make them safer for deployment in Western enterprises." asserted
them → say → enterprises
Chinese models are on the rise," he added. asserted
he → add → rise
"We need to acknowledge the risks, and then we can go to solve them." asserted
we → need → them
💬Give feedback
🕘History 🎫Support