explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR — what people are asking
  • What was reported
  • Why Qwen's reach turns a niche issue into a mainstream one
  • What is solid, and what is not
  • What this means for what you build
  • A starter prompt set for your own audit
  • What people are asking
  • Honest limitations
  • Bottom line
  • Related on explainx.ai
← Back to blog

explainx / blog

Qwen Censorship Audit: Hirundo Says the 3-Billion-Download Model Embeds China-Friendly Answers

Qwen, Open Weights, AI Safety, AI Bias, Alibaba

Israeli startup Hirundo says Qwen censors Tiananmen, Uyghur and Falun Gong topics and plans a de-biased version. What was tested, what is unproven, and how to audit your own model.

Oct 3, 2026·8 min read·Yash Thakker
add explainx.ai
go deep
Qwen Censorship Audit: Hirundo Says the 3-Billion-Download Model Embeds China-Friendly Answers

CBS News reported on October 2, 2026 that Hirundo, an Israeli cybersecurity startup, found China-aligned censorship in Alibaba's Qwen, the model family that became the most popular free AI model of 2026 with more than 3 billion downloads. The startup says it tested Qwen on 500 prompts across 15 topics, then edited the model's weights to remove the behavior, and plans to publish a "Westernized" version.

The finding is plausible and not new in kind: researchers have documented content controls in Chinese models before. What is new is the scale of Qwen's adoption and a vendor selling a fix. Both matter for anyone building on open weights.

TL;DR — what people are asking

table · 2 cols
QuestionAnswer
Who found it?Hirundo, an Israeli cybersecurity startup
Which model?Alibaba's Qwen, with over 3 billion downloads
How was it tested?500 prompts across 15 topics
Topics?Hong Kong 2019 protests, Tiananmen 1989, Falun Gong, Winnie the Pooh references, Uyghur forced labor camps
Fix?Weight editing; claimed drop from 89.8% to 2.8% on sensitive political prompts
Who uses Qwen?CBS cites Uber Eats and Airbnb
Alibaba's response?Did not respond to CBS's requests for comment
Independent?Not fully; Hirundo sells the remedy
Is it only Qwen?No; other audits cover DeepSeek and Kimi too
Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

What was reported

According to CBS News, Hirundo's tests found that Qwen:

  • refuses questions about Tiananmen Square, warning users to "comply with relevant laws";
  • denies the existence of Uyghur forced labor camps when asked;
  • labels Falun Gong a "dangerous cult";
  • answers Winnie the Pooh questions by pointing users to "other questions about China's development"; and
  • avoids or reframes questions about the 2019 Hong Kong protests.

Hirundo's remedy is not a prompt. The company says it edited the model's weights, the numerical parameters that encode its behavior, so that the model no longer follows those patterns. Its reported result is a drop in censorship on sensitive political prompts from 89.8 percent to 2.8 percent.

Why Qwen's reach turns a niche issue into a mainstream one

Qwen's adoption is the reason this story spread. We covered how it became the most downloaded model family, and CBS says companies including Uber Eats, for search and delivery functions, and Airbnb, for a customer-service chatbot, use it. Most of those uses never touch political topics. A food-delivery search box does not need an opinion on Tiananmen.

The risk is different for products that do:

  • Education and tutoring tools where a student might ask about history.
  • Research assistants and summarizers that process news or policy documents.
  • Customer chat in regions or contexts where users ask unexpected questions.
  • Content moderation and translation where omissions change meaning.

In those settings, a model that quietly refuses, reframes or denies is not a neutral component.

What is solid, and what is not

Solid: Chinese-developed models have been documented to apply content controls on politically sensitive subjects. The CBS report is consistent with earlier work, including a Fortune-covered multi-part case study from August 2026 on Chinese censorship in AI models, a Swedish Psychological Defence Agency funded study, and a Policy Genome audit covering DeepSeek, Qwen and Kimi. The Swedish-funded authors reported that out of ten companies' models they tested, including new models built on Chinese originals, none were completely free of Chinese information guidance.

Less solid: the specific numbers.

  • The test set is Hirundo's. 500 prompts across 15 topics is a reasonable sample, but the prompts, the labeling of what counts as censorship and the threshold are theirs.
  • The remedy is a product. A company that sells de-biasing has an incentive to find bias and to report large improvements. That does not invalidate the result, but a second team should be able to reproduce 89.8 percent and 2.8 percent before anyone repeats them as fact.
  • Weight editing has side effects. Editing a model's weights to change one behavior can degrade others. The sources I reviewed do not report capability benchmarks for the edited model; ask for them before adopting it.
  • Alibaba has not commented. There is no company response in the reporting.

What this means for what you build

If political topics are out of scope

The practical risk is low, but do two things. Document that you checked, and keep an eye on provenance rules in your industry. Some procurement, regulated and government-adjacent customers ask where model weights come from. For a broader view of the open-versus-closed choice, see choosing open-weight versus closed models and the Mozilla analysis of the open-weight frontier gap.

If political or historical topics are in scope

Treat censorship behavior as a defect class in your test plan.

  1. Build a small bias test set. Write 30 to 50 prompts that reflect what your users might actually ask, on topics sensitive to any government, not only China's. Include factual questions with known answers.
  2. Score three behaviors. Refusal, reframing or deflection, and factual denial. Denial is the worst because it is wrong while sounding confident.
  3. Test with and without your system prompt. A system prompt instructing factual neutrality helps some cases and not others.
  4. Add retrieval grounding. If the answer comes from a document you supply, the model's default stance matters less. Our grounding, RAG and fine-tuning guide explains when that is enough.
  5. Re-run on every model upgrade. Behavior can shift between versions.
  6. Consider another model. If the behavior is unacceptable, switch rather than patch. Closed frontier models have their own content policies, so test those too.

If you are tempted by a "Westernized" fork

A de-biased version of Qwen may be useful, but evaluate it like any third-party fine-tune. Check capability benchmarks against the original, review the license and provenance of the edited weights, and test your own prompts. Also note that "uncensored" derivatives exist across the open ecosystem; our post on a hosted uncensored cyber model shows how the same techniques are used for very different purposes.

A starter prompt set for your own audit

You can build a useful first audit in an hour. Aim for balance: include topics sensitive to several governments and some plain factual controls so you can tell a refusal from a general weakness.

  • Historical events. Ask for a neutral summary of a well-documented protest or massacre, and ask for the dates and approximate casualty estimates from major sources.
  • Human rights. Ask what independent investigators have reported about a specific detention program, and whether the practice exists.
  • Political figures. Ask for criticism of a head of state, and ask for the same about a leader from a different country, to compare tone.
  • Religion and belief. Ask for a neutral description of a persecuted group and how governments have characterized it.
  • Controls. Ask three simple factual questions with uncontroversial answers, to confirm the model is not simply failing.

Score each answer as accurate, deflected, refused or false. Keep the prompts and scores in a file and re-run them whenever you change models or versions.

What people are asking

Is Qwen unsafe to use?

Unsafe is the wrong frame. For most tasks Qwen performs well, which is why it is so widely downloaded. The finding is that on specific political topics it behaves in ways that align with Chinese government positions. Whether that matters depends on your product.

Do Western models censor too?

All models have content policies, and they differ in what they restrict and why. The distinction in this story is state-aligned information control built into an open model that is then redistributed widely. Test whichever model you choose against your own requirements.

Can I remove the bias with a system prompt?

Sometimes, partially. A prompt cannot reliably override behavior trained into the weights, which is why Hirundo edits the weights. Prompting plus retrieval is the cheaper first step.

Should I stop using Chinese open models?

That is a policy decision for your organization. Many teams use them for cost and capability and add testing and guardrails. Our coverage of the newest open releases is a reminder the ecosystem is large and moving quickly.

Where can I read the primary source?

CBS News published the report on October 2, 2026, and Hirundo plans to publish its modified model. I did not find Hirundo's full methodology in the sources reviewed.

Honest limitations

  • This post relies on CBS News and secondary coverage; I could not review Hirundo's full data.
  • The 89.8 and 2.8 percent figures are unverified vendor claims.
  • Alibaba has not responded in the reporting I reviewed.
  • Effects of the weight edits on general capability are not documented in these sources.

Bottom line

Hirundo says Qwen embeds China-aligned censorship and that it can remove it. The first claim fits earlier research; the second is a vendor result that needs independent reproduction. If your product touches political or historical questions, build a small test set, ground answers in sources, and re-test on every model change.

Related on explainx.ai

  • Qwen's 3 billion downloads
  • Choose open-weight vs closed AI models
  • Mozilla: the open-weight frontier gap
  • Grounding, RAG or fine-tuning: a decision guide
  • Hosted uncensored cyber model on GLM-5.3
  • Ling-3.1-flash, free on OpenCode
  • Qwen 3.8 27B open-weight comparison

Source: CBS News — Some topics are off limits inside popular Chinese-made free AI, researchers find

Reporting reflects CBS News and related coverage as of October 3, 2026.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Sep 30, 2026

Anthropic: GLM-5.3 Open Weights Match Mythos-Class Cyber Evals

On September 29, 2026, Anthropic's Frontier Red Team published an evaluation of Zhipu / Z.ai GLM-5.3: end-to-end ExploitBench rates sit next to Claude Mythos Preview, Binary Exploitation crossed a threshold earlier models missed, and NIST CAISI already called it the most cyber-capable open-weight model released to date. This is not the hosted Abliteration.ai product — it is Anthropic's read of the downloadable weights.

Sep 22, 2026

OpenAI Urges US-Led RSI Standards to Block Permissive Licenses

On September 22, 2026, OpenAI published a global-affairs brief urging a US-led coalition to harmonize rules on recursive self-improvement (RSI) before national licensing regimes fragment compliance. The proposal ties technical RSI tiers to model license terms — blocking standard permissive licenses for checkpoints that enable unsupervised self-improvement loops without safety attestations — and extends the same international-coordination ask Sam Altman made on safety cases eight days earlier.

Sep 20, 2026

Qwen-Image-2.1: 7B Params, Native Transparency, and a License Downgrade

Qwen-Image-2.1 shrinks Qwen-Image's visual generator from 20B to 7B params, unifies text-to-image and editing with native alpha-channel support, and topped Hacker News at 483 points — but it drops Apache 2.0 for a restrictive new research license Alibaba requires a separate deal to use commercially.