Party Line in the Model: What Aleph Alpha’s Test of Chinese AI Shows

Rote Laternen über einer Straße in einer chinesischen Stadt
Photo by Alex Preusser on Unsplash

Open AI models from China are among the most capable models anyone can download for free, and they have long since found their way into products from Western companies. A study by Heidelberg-based AI company Aleph Alpha now shows how closely models from Alibaba, DeepSeek and Moonshot AI follow Beijing’s line on politically sensitive questions. It also shows that this slant can carry over into other vendors’ models through training data. Anyone using Chinese models does not have to avoid them, but should know what they are good for.

Key takeaways

  • Aleph Alpha tested six Chinese models with 967 politically sensitive prompts; only 17 to 41 percent of the answers were balanced.
  • The remaining answers echoed positions of the Chinese Communist Party or refused to respond. DeepSeek V4 Pro declined about two-thirds of the prompts.
  • Nvidia’s Nemotron Cascade 2 also showed party-aligned patterns on about 17 percent of prompts, likely inherited from training data generated with DeepSeek and Qwen.
  • Claude Sonnet 5 and Mistral Small adopted the party’s view in only 2.8 and 8 percent of cases, respectively.
  • Aleph Alpha is not a neutral party: the company released its own open model on October 3 and is merging with Canadian AI firm Cohere.

What Aleph Alpha measured

The report is titled “Training on the Party Line” and was published on September 28, written by Bastian Boll. It is based on a custom set of prompts. Aleph Alpha picked 56 politically sensitive topics, including Taiwan, Xinjiang, the Tiananmen Square massacre and censorship, and had the open model GPT-OSS 120B turn them into 967 concrete tasks. One example asks for a lesson plan about Xi Jinping’s personality cult. The same GPT-OSS model then sorted the answers into three groups: echoes the party’s framing, answers in a balanced way, or refuses.

The results are stark. Qwen 3.6 in its 35B-A3B version gave a balanced answer only 17 percent of the time and adopted the party’s view 80 percent of the time. DeepSeek R1 in its May 2025 release reached 22 percent balanced answers. The much larger Qwen 3.8 came in at 19 percent. Moonshot AI’s models did better: Kimi K2.5 reached 37 percent, the current Kimi K3 41 percent. DeepSeek V4 Pro took a different route. It adopted the party line in only 16 percent of cases but refused 66 percent of the prompts. For comparison, Claude Sonnet 5 answered in a balanced way 70 percent of the time and declined 27 percent, while Mistral Small gave balanced answers 92 percent of the time.

A second test with 240 prompts that do not mention China at all turned out far less problematic for most models, which mostly answered in a balanced way. The standout is Kimi K3, which according to Aleph Alpha adopted the party’s framing in 93 percent of these cases as well. The report offers no explanation for this outlier.

How the party line spreads to other models

The most interesting finding does not concern a Chinese model. Nvidia’s Nemotron Cascade 2 echoed the party’s view on about 17 percent of prompts. Aleph Alpha looked into where that might come from: Nvidia has published its fine-tuning data, and much of it was generated with DeepSeek and Qwen. Among 9.3 million chat rows, roughly 3,500 carried party positions. A tiny share, yet one with a measurable effect.

This matters in practice because it is common to train smaller models on the output of larger ones or to build on top of them. Cloudflare’s new Clef decision models, for example, are also based on Qwen. Whether such a derivative keeps the political slant depends on what it was built for and how it was further trained. A model that sorts support tickets will never be asked about Taiwan. But knowing where a model comes from is becoming basic due diligence.

A finding with a sender

The numbers are plausible, but they do not come from a neutral source. Aleph Alpha markets itself as a provider of “sovereign” AI for government and industry, and on October 3 it released its open model Kolibri, with 78 billion parameters under the Apache 2.0 license. In September, the company also signed its merger agreement with Canadian AI firm Cohere, which still needs regulatory approval. A study showing Chinese competitors as politically compromised fits neatly into that narrative. There is also a methodological caveat that Aleph Alpha itself acknowledges: an AI model generated the prompts and judged the answers, and on difficult judgment calls such a judge can introduce bias. The report lists the 56 topics in an appendix but does not link to the full prompt set.

Independent research backs up the finding. In July, the Slovak research institute CEIAS put 5,760 questions about 37 countries and 40 topics to DeepSeek V3.2, Kimi K2.5, Qwen 3.5 and GLM-5. On sensitive topics, Kimi steered roughly one in three answers toward Chinese government messaging and DeepSeek roughly one in four, even when the question was about entirely different countries. In Mandarin, the effect on the ten most affected topics was more than twice as strong as in English: 59 versus 24 percent.

What users should take from this

For most everyday tasks, the political slant does not matter. If you code, summarize text or analyze data with DeepSeek or Kimi, you get the strengths of these models, often at a fraction of the cost of Western offerings. Through Ollama, for example, DeepSeek V4 Pro and Kimi K3 are available in the cloud, and smaller variants can run locally. Things look different as soon as a model is used to put news in context, create teaching materials, answer citizens’ inquiries or otherwise deal with politics, history and human rights. In those cases, a Western or European model belongs on the shortlist, or at least a quick test with a handful of sensitive questions before a system goes live.

Aleph Alpha recommends three steps for developers: screen training data for Chinese political content, add targeted data that defines the desired behavior, and test models against evaluation sets like its own. That advice holds for anyone who uses other models’ answers as training material.

Bottom line: origin becomes a product feature

The study makes visible what had mostly circulated as a suspicion: the rules Beijing imposes on its AI providers travel around the world with the model weights and can even seep into American models through training data. That does not call for a blanket ban, but it does create a new duty of care. When choosing an open model, it is no longer enough to compare benchmarks for code and math. It also pays to ask where a model comes from and what it was trained on. A publicly available, independently maintained evaluation set for such questions would be the logical next step, ideally not run by a vendor that sells models of its own.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top