By Eduardo Baptista
BEIJING, Oct 9 (Reuters) – China’s leading AI developers have publicly disclosed model-specific safety-test results for only a small fraction of their releases, a report by research firm SemiAnalysis said, as concerns about the risks posed by advanced AI systems increase worldwide.
California-based SemiAnalysis, a technology research firm, reviewed 857 models released between 2021 and September 15 by nine leading Chinese AI companies — Alibaba, ByteDance, Tencent, Baidu, DeepSeek, Moonshot, Z.AI, MiniMax and StepFun.
It found that 31 releases, or 3.6%, had a published safety-evaluation result that could be matched to a specific model. Just nine, or 1.1%, had such results available at or before launch, it said. Researchers found no safety disclosure for 813 releases, though companies could have conducted tests privately.
SemiAnalysis said it defined disclosures as specific results tied to a named model — including tests of harmful output, jailbreak resistance, toxicity, privacy, refusal behaviour or dangerous capabilities — and did not count general claims that a model had been safety-trained or evaluated.
The findings come as security incidents involving autonomous AI agents — systems that undertake multistep tasks with limited human intervention — have intensified global debate over whether companies should slow down to build safer models.
The vast majority of AI models capable of powering agents that could autonomously carry out cyber breaches are made by either US or Chinese developers.
Australia said last month an OpenAI agent breached a government health portal.
Reuters reported last week that Chinese AI agents had shown an ability to deceive users, evade restrictions and conceal failures in tests, echoing concerns raised about advanced US systems.
China’s latest AI Safety Governance Framework identifies risks including models acquiring system permissions or external resources without authorization, deceiving evaluators, concealing capabilities and bypassing safety controls. But it does not impose mandatory duties linked to model capability, according to SemiAnalysis.
The report said Beijing’s binding rules principally govern applications and their effects on users rather than requiring frontier developers to conduct or publish risk assessments based on a model’s capabilities.
The US research firm added that no major Chinese developer had released a frontier text model with publicly disclosed dangerous-capability tests spanning cyber, biological and loss-of-control risks.
The report did not provide comparable figures for US AI developers. Leading US companies including OpenAI, Anthropic and Google DeepMind have published safety reports, system cards or model cards for some major frontier-model launches.
(Reporting by Eduardo Baptista, Editing by Louise Heavens)

