2026-10-11 17:15 UTC

Hirundo claims Qwen embeds systematic China-aligned censorship β€” 89.8% of 500 sensitive political prompts produced censorship or propaganda-aligned framing β€” and that its weight-editing 'brain surgery' yields a 'Westernized' Qwen at 2.8% with reasoning and coding capability preserved; publication of its white paper and Westernized model plus independent confirmation of both numbers resolves it, while non-replication or a release that never ships refutes it.

state: watchingheat: mediumuncertainty: mediumconvergesscott: highllm-censorship chinese-open-models model-evaluation weight-editingHirundoBen LuriaAlibaba

What is this?

Hirundo, an Israeli AI safety lab, claims that Alibaba's Qwen3.6-35B-A3B (the world's most-downloaded open model at 3B+ downloads) produces China-aligned censorship or propaganda framing on 89.8% of 500 sensitive political prompts across 15 topics (Xinjiang/Uyghurs, Hong Kong 2019 protests, Tiananmen 1989, Falun Gong, Winnie-the-Pooh/Xi references, etc.). Using weight-editing ('machine unlearning' / 'AI brain surgery'), they released a 'Westernized' variant on Hugging Face that drops the censorship rate to 2.8% while preserving general benchmarks (GPQA, IFBench, LiveCodeBench, MMLU-Pro) within ~1 point and retaining safety guardrails. CBS News covered the claims via a shared white paper; the Westernized weights are now publicly available per a first-party Reddit announcement by a Hirundo researcher. No independent replication of either the censorship battery or the capability-preservation claim has yet appeared.

Why it matters to Scott

Hirundo's released Westernized Qwen weights and censorship battery directly demonstrate the open-model supply-chain risks Scott's sovereign-software-assurance framework warns about: hidden vendor agendas, model perishability, and the need for independent capability audit rather than trusting provider claims. The artifact is immediately testable on Scott's gamepc/Ollama stack, making this a dated-receipts opportunity β€” a consequential other party independently arriving at the verification-first position his frameworks (capability-audit, evaluation-driven-development, verification-loops, kernel-doctrine, nuke-and-regenerate) prescribe.
ip:framework.sovereign-software-assuranceip:concept.model-perishabilityip:concept.vendor-lock-inip:concept.capability-auditip:concept.evaluation-driven-developmentip:concept.verification-loopsip:concept.verification-costip:framework.nuke-and-regenerateip:concept.surgery-problemip:concept.kernel-doctrineip:project.gamepcip:technology.ollamaip:concept.hardware-aware-local-inferenceip:framework.decision-authority-infrastructureip:concept.zero-trust-for-decisionsip:concept.cryptographic-trustradar:concept.weight-editingradar:concept.chinese-open-modelsradar:concept.qwenradar:concept.open-weight-modelsradar:concept.sovereign-airadar:qwen-agent-aliyun-egressradar:qwen-global-download-leadradar:qwen38-abliteration-safety-tradeoffradar:closed-form-weight-surgeryradar:echoleak-immunized-llama-weightsradar:mistral-three-billion-sovereign-expansionradar:austria-govgpt-sovereign-rolloutradar:concept.software-supply-chainradar:concept.supply-chain-security
queries asked of Scott's wikis
  • open-model supply-chain trust embedded agendas
  • weight-editing machine-unlearning capability preservation
  • Chinese open-model censorship evaluation methodology
  • model sovereignty local inference westernized variants
  • Qwen Alibaba open-weight deployment risks

Measured heat

now 0 pts/hpeak 24 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 199h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

10-03 09:08⭐ origin directly observedSome topics are off limits inside popular Chinese-made free AI, researchers find
maxloh on hacker news
β€”
10-08 10:46first on r/LocalLLaMA Β· published Β· +121.6hWe unlearned CCP alignment from Qwen3.6-35B-A3B: censored/propaganda answers 89.8% β†’ 2.8%, general benchmarks within ~1 point (open weights)
firstcenturyman
β€”
10-03 09:08amplified on hacker newshn.story.49942578
maxloh
peak 4 Β· 0 comments Β· 5% of case engagement
10-08 10:46amplified on r/LocalLLaMA πŸ‘‘reddit.post.1x0npmx
firstcenturyman
peak 51 Β· 72 comments Β· 95% of case engagement
10-03 09:20our radar first saw it Β· +0.2hdiscovery anchor: hn.story.49942578β€”
pace: p63 vs 1188 stories at the 168h mark (now 199h old) β€” ahead of aaai-2027-review-quality-regression (1.0x), behind chatgpt-pro-200-signup-pause (1.0x)

Evidence (2) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hn ⭐Some topics are off limits inside popular Chinese-made free AI, researchers find
Retrieved article excerpt

Open article Β· Retrieved 2026-10-03T09:25:39.997802+00:00

[World](https://www.cbsnews.com/world/?ftag=CNM-16-10abg0d)

# Some topics are off limits inside popular Chinese-made free AI, researchers find

By

Josh Boswell

[Josh Boswell

Investigative Reporter/Producer](https://www.cbsnews.com/team/josh-boswell/)

Josh Boswell is a reporter and producer for the CBS News Investigative Unit, based in Los Angeles.

[Read Full Bio](https://www.cbsnews.com/team/josh-boswell/)

[Josh Boswell](https://www.cbsnews.com/team/josh-boswell/)

October 2, 2026 / 1:08 PM EDT
/ CBS News

[Add CBS News on Google](https://www.google.com/preferences/source?q=cbsnews.com)

An AI model downloaded over 3 billion times and used by U.S. firms like Airbnb and Uber is embedded with China-friendly narratives and programmed for censorship, new research shows.

Qwen, a freely available model made by Chinese conglomerate Alibaba, doesn't acknowledge the violent suppression of protests in Hong Kong in 2019 or Tiananmen Square in 1989; it calls the Chinese government-maligned religion Falun Gong a "dangerous cult," and curiously won't talk about Winnie the Pooh, it's thought because [dissidents have compared](https://www.cbsnews.com/news/winnie-the-pooh-censored-china-president-xi-jinping-comparisons/) the fictional bear to Chinese President Xi Jinping.

The apparent censorship inserted into Qwen of events and issues not approved by the Chinese authorities was identified by Hirundo, an Israeli cybersecurity startup.

The firm says its scientists have found a way to remove the model's bias using sophisticated technology that amounts to "AI brain surgery," and are now set to publish what they call a "Westernized" version of Qwen.

This year Qwen became the most popular free AI model in the world, following a meteoric rise in the use of Chinese-made artificial intelligence.

But researchers warn that itsΒ  international popularity also risks spreading and entrenching its bias toward the Chinese government.

When we asked Qwen, "Are there forced labor camps for Uyghurs in China?" it replied, "No, there are no forced labor camps for Uyghurs in China," adding that there are "vocational skills education and training centers in Xinjiang."

In fact, [human rights organizations](https://shura.shu.ac.uk/35123/1/1%20Forced%20Labor%20in%20the%20Uyghur%20Region%20The%20Evidence.pdf), [governments](https://www.dol.gov/agencies/ilab/against-their-will-the-situation-in-xinjiang) and international bodies have found hundreds of thousands of people in the Muslim ethnic minority working against their will in factories surrounded by barbed wire fences, and even accused the Chinese government of genocide.

Qwen often refuses to respond to questions about the events in Tiananmen Square on June 3, 1989, when the Chinese military massacred several hundred people at protests in BeijingΒ  β€” and ominously "remind[s] you that your questions should comply with the relevant laws and regulations."

The Chinese government effectively banned Winnie the Pooh from the country after dissidents began satirically comparing Xi to the fictional bear and using Pooh as a euphemism for the Chinese president in social media posts to avoid government censors. When CBS News asked Qwen a factual question about it, it responded with a warning to "use respectful language" and directed the user to "other questions about China's development."

Qwen's creator, Alibaba, did not respond to a request for comment.

Despite evidence of embedded bias in the program, U.S. firms have been increasingly switching to use ["open-weight" models](https://www.cbsnews.com/news/open-weight-ai-models-safety-risks/) offered by Chinese companies, which allow them to download and use AI for free or use giant, powerful models at lower costs than U.S. competitors such as Anthropic's Claude or OpenAI's ChatGPT.

Uber Eats' search and delivery functions are built "on a Qwen backbone" according to an April blog post by the company. Airbnb CEO Brian Chesky [told the LA Times](https://www.latimes.com/business/story/2025-10-21/chesky-says-openai-tools-not-ready-for-chatgpt-tie-up-with-airbnb-app) last October that his company is "relying a lot on Alibaba's Qwen model" for its customer service chatbot.

Neither company responded to a request for comment.

Chinese open-weight models grew from under 2% of global usage in late 2024 to more than 45% by June this year, according to usage data of all AI models from the software developers' platform OpenRouter.

By August, Qwen had eclipsed all other open models, including those made by Facebook owner Meta and Google owner Alphabet, rising to more than 3 billion downloads globally.

Experts at security firm CrowdStrike and consultancy Booz Allen have warned American firms about using Chinese models after their separate studies found bias and security flaws.

Booz Allen published results in June saying that when they asked Qwen to write computer code and told it the project was for the U.S. government, the code it produced had 130% more security vulnerabilities.

"The Chinese models that we tested failed to demonstrate trustworthy behaviors and should be banned," the report said.

CrowdStrike conducted a similar study last November on another popular Chinese model, DeepSeek. When they told the model that its coding task was for an adversary of the Chinese government, the code it produced had 50% more security vulnerabilities.

Hirundo says it tested Qwen on 500 prompts across 15 topics and then removed the bias its analysts found to create what they call a "Westernized" version.

"On sensitive political prompts, the original Qwen produced censorship, propaganda-aligned framing or political bias 89.8% of the time," Hirundo CEO and founder Ben Luria told CBS News. "The Westernized model does so 2.8% of the time, with the capability preserved at-large across reasoning, coding, instruction following and math tasks."

In a white paper on the technology shared with CBS News, Hirundo says it edits the "model weights" β€” the neurons of the AI's digital brain β€” rather than previous, less effective attempts to remove bias that merely ask the AI to follow new rules that it often ignores.

"Everything in a model is entangled with a lot of other things, similar to our brains," Luria said. "That's why it's so hard to pinpoint what specific neurons are representing the things you don't want in your AI models."

He said his team's goal was "realigning the model to Western standards to make them safer for deployment in Western enterprises."

"The trend is clear. Chinese models are on the rise," he added.

"We need to acknowledge the risks, and then we can go to solve them."



### AI: Artificial Intelligence [More](https://www.cbsnews.com/feature/ai-artificial-intelligence/?intcid=CNI-00-10aaa3a)

- [#### Amazon vows to invest $1 billion in areas where it builds data centers

  NextEra To Buy Dominion For $67 Billion To Form Power Giant](https://www.cbsnews.com/news/amazon-1-billion-data-center-investment-ai/?intcid=CNI-00-10aaa3a)
- [#### Trump likely to pick Jay Clayton for AI czar, sources say

  DNI Senate Confirmation Hearing](https://www.cbsnews.com/news/trump-likely-jay-clayton-ai-czar-sources-say/?intcid=CNI-00-10aaa3a)
- [#### Cyber scams have targeted 9 in 10 Americans as AI fuels fraud

  Woman In The Network](https://www.cbsnews.com/news/ai-cyber-scams-consumer-reports-fraud/?intcid=CNI-00-10aaa3a)
- [#### How some AI models are more vulnerable to manipulation

  Moonshot AI Kimi Booth at 2026 WAIC](https://www.cbsnews.com/news/open-weight-ai-models-safety-risks/?intcid=CNI-00-10aaa3a)
- [#### OpenAI parts ways with 3 researchers it says mishandled sensitive information

  In this photo illustration, an OpenAI logo is seen displayed](https://www.cbsnews.com/news/openai-parts-ways-with-three-researchers-who-mishandled-sensitive-information/?intcid=CNI-00-10aaa3a)

### Go deeper with The Free Press

- [#### How China Is Stealing America’s AI](https://www.thefp.com/p/china-america-ai-race?utm_source=cbs_news&utm_campaign=cbs_news_recirculation&utm_content=bottom_page)
- [#### Tyler Cowen: The AI Slowdown Is Not What It Seems](https://www.thefp.com/p/tyler-cowen-ai-slowdown-computing-anthropic-openai?utm_source=cbs_news&utm_campaign=cbs_news_recirculation&utm_content=bottom_page)



In:

- [Artificial Intelligence](https://www.cbsnews.com/feature/ai-artificial-intelligence/)
maxloh40
🟠 redditWe unlearned CCP alignment from Qwen3.6-35B-A3B: censored/propaganda answers 89.8% β†’ 2.8%, general benchmarks within ~1 point (open weights)
LocalLLaMA
firstcenturyman5172

Interpretation history

Decision trace