Popular Chinese AI Model Qwen Found Embedding State Censorship and Bias
New research reveals Alibaba's Qwen AI model embeds Chinese state narratives and censorship, raising security concerns for major U.S. firms using the tech.
POLICY WIRE — Washington, USA — A widely used artificial intelligence model developed by the Chinese conglomerate Alibaba has come under scrutiny for embedding state-aligned narratives and censorship protocols. Known as Qwen, the model has been downloaded over 3 billion times and is currently utilized by major American corporations, including Uber and Airbnb.
Investigations by the Israeli cybersecurity startup Hirundo revealed that Qwen systematically avoids or distorts sensitive historical and political topics. The model refuses to discuss the 1989 Tiananmen Square massacre or the 2019 Hong Kong protests, labels the Falun Gong movement as a dangerous cult, and avoids references to Winnie the Pooh, a character often used by dissidents to satirize Chinese President Xi Jinping.
When queried about the existence of forced labor camps for Uyghurs in China, Qwen denied their existence, instead characterizing the facilities as vocational skills education and training centers in Xinjiang. This stance contradicts findings from international bodies and human rights organizations that have accused the Chinese government of genocide and the forced detention of hundreds of thousands of people from the Muslim ethnic minority.
Despite these findings, U.S. companies continue to integrate Qwen into their operations due to its low cost and high performance compared to domestic alternatives like OpenAI’s ChatGPT or Anthropic’s Claude. Uber Eats utilizes a Qwen backbone for its delivery functions, while Airbnb CEO Brian Chesky confirmed last October that the company relies on the model for its customer service chatbot.
📄 POLICY WIRE WHITEPAPER PUBLISHED: PAKISTAN’S NATIONAL SECURITY POLICY PRIORITIES
Data from the software platform OpenRouter indicates that Chinese open-weight models surged from less than 2% of global usage in late 2024 to over 45% by June of this year. By August, Qwen had surpassed models from Meta and Google to become the most popular free AI model worldwide.
Security experts from firms such as CrowdStrike and Booz Allen have issued warnings regarding the integration of these models into American infrastructure. A June report from Booz Allen found that when Qwen was tasked with writing code for the U.S. government, the output contained 130% more security vulnerabilities than expected. A similar study by CrowdStrike on the Chinese model DeepSeek found a 50% increase in vulnerabilities when the AI was told the task was for an adversary of the Chinese government.
In response to these risks, Hirundo researchers have developed a method they describe as AI brain surgery to remove biased data from the model. Luria, a representative for the firm, stated that the team successfully tested Qwen across 500 prompts and 15 topics to create a Westernized version of the software. The goal, according to Luria, is to realign the model with Western standards to ensure safer deployment for enterprises.
Alibaba did not provide a response to requests for comment regarding the research findings. Neither Uber nor Airbnb responded to inquiries regarding their continued use of the model.
Reporting by Policy-Wire (PW)





