Researchers Exposed Political Bias in Alibaba Qwen AI
The open-weight model exhibited censorship on nearly 90% of political prompts before undergoing modification.
Updated on Oct. 2, 2026 in Artificial Intelligence

Live Poll
Should American companies be allowed to use AI models developed under foreign government censorship rules?
Researchers have identified extensive political censorship and state-aligned narratives embedded within Alibaba's Qwen AI model. The model, which has surpassed 3 billion downloads globally, routinely denies historical events like the 1989 Tiananmen Square massacre and the existence of forced labor camps in China.
Why it matters
U.S. firms including Uber and Airbnb have integrated Qwen technology to cut costs, but internal reports now indicate the model produces code with significantly higher security vulnerabilities. This reliance creates a blind spot where critical infrastructure could be compromised by programmed political alignment.
Hirundo researchers tested 500 prompts across 15 topics, finding the original Qwen model exhibited political bias or censorship in 89.8% of cases. After modifying model weights, the error rate dropped to 2.8%.
The players
Alibaba
A Chinese conglomerate and cloud infrastructure provider that develops the Qwen series of open-weight artificial intelligence models.
Hirundo
An Israeli startup focused on AI safety and the technical remediation of biased model architectures.
Booz Allen
A U.S.-based management and information technology consulting firm that assesses security risks in software and AI-generated code.
The details
The Qwen model relies on weight-based alignment to adhere to Chinese censorship laws, which triggers denials regarding the 2019 Hong Kong protests or references to Falun Gong. Booz Allen researchers found that code generated by Qwen for U.S. projects contained 130% more security vulnerabilities than neutral alternatives. Israeli startup Hirundo attempted to mitigate these issues by modifying the underlying model weights to strip away the pre-programmed political narratives.
Timeline
June 1989: Chinese military personnel massacred protesters in Tiananmen Square.
Late 2024: Chinese open-weight models accounted for under 2% of global usage.
June 2026: Chinese models reached a 45% global usage share.
August 2026: The Qwen model exceeded 3 billion total global downloads.
The Tech Race
The rapid ascent of Chinese open-weight models from 2% global share in late 2024 to 45% by June 2026 reflects a drive for low-cost, high-capability AI infrastructure. The emergence of censorship-related security flaws now challenges this trajectory, threatening the adoption parity between domestic and foreign AI stacks.
Organizations currently using Qwen for code generation should evaluate their outputs for security vulnerabilities, which are 130% higher than alternatives. Developers are advised to treat the model's output on geopolitical topics as non-neutral, as it is hard-coded to mirror state narratives.
The takeaway
The reliance on foreign open-weight models for infrastructure requires rigorous auditing to prevent injected bias and security flaws. Users should monitor future releases from Hirundo, which plans to publish a sanitized Westernized version of the model to compete with original Qwen deployments.
Further reading
For more on how global research teams are testing safety, visit Artificial Intelligence.
Source note: This article includes information reported by CBS News.
Live Poll
Should American companies be allowed to use AI models developed under foreign government censorship rules?







