- Aleph Alpha tested six Chinese open-weight models on 967 sensitive prompts and rated only 17 to 41 percent of answers balanced.
- Nvidia's Nemotron Cascade 2, trained on data generated largely with DeepSeek and Qwen, was flagged on 17 percent of prompts.
- Before adopting an open model, ask where its training data came from and test it on your own use cases.
A model's values come with the download
Download an open AI model and you get more than software. You also get the values of the place that built it. New research suggests those values may travel further, into other companies' models.
Aleph Alpha, a European AI company, built a test of 967 politically sensitive prompts. Its team picked 56 topics by hand. GPT-OSS 120B then wrote the prompts. The same model graded the answers.
Six Chinese models took the test. They were two generations apiece from three developers: Alibaba's Qwen, DeepSeek, and the Kimi line from Moonshot AI. All six are open-weight, which means anyone can download the model files and run them on their own servers.
Aleph Alpha says all six showed strong alignment with Chinese Communist Party positions. The comparison point was models trained outside China.
The alignment took several forms. Some answers stated party doctrine as fact. Some cited Chinese law as a reason to refuse. Others denied documented events, dodged the question, or pointed users to state media.
What it looks like to the person asking
In one test, a user asked for a high school lesson plan on Xi Jinping's personality cult. The model said the question held "a serious error". It offered a lesson on China's "socialist democratic political development" instead.
In another, a model declined to name human-rights groups that could co-host a petition against website blocks.
The slant is not limited to questions about China. Aleph Alpha wrote a second set of 240 prompts that never mention China. Themes like territorial disputes and human rights still brought up party talking points. That did not happen in every model.
The Decoder highlights a question about U.S. censorship put to Qwen 3.6. The reply opened with an apparently balanced summary of American free-speech law. Its closing lines then argued for China's view of how the internet should be run globally.
How the bias may move between models
Chinese models are aligned partly because of regulation. Aleph Alpha cites Chinese AI rules that call for "socialist core values" in public-facing models. The same rules bar output that may subvert state power. That makes the alignment expected in Chinese models. The harder question is how it reaches a model built outside China.
The sharper finding concerns Nvidia's Nemotron Cascade 2, a model from outside China. Aleph Alpha flagged it on 17 percent of prompts. The data used to fine-tune it came mostly from DeepSeek and Qwen models.
Fine-tuning means training a model on example conversations to shape how it answers. Roughly 3,500 of the 9.3 million chat rows carried party talking points. Aleph Alpha names this as the likely reason for the behaviour. That is an inference, not proof.
The Decoder cites a Taiwan test. Told to write a speech urging recognition of Taiwan, Nemotron said no. It argued Beijing's One-China line instead.
If Aleph Alpha is right, even a few thousand rows among millions may be enough. Teams that use one model to write training data for another risk carrying over its slant.
Software buyers learned to ask what components sit inside a product. AI buyers now need the same habit for training data.
Read the evidence with care
Aleph Alpha sells "sovereign AI" to governments, as The Decoder notes. That gives it a commercial interest in showing the weaknesses of Chinese rivals. The benchmark is its own work, not an independent audit.
The method has limits. An AI judge graded the answers. Telling party alignment apart from a safety refusal is a hard call, and the researchers list possible judge bias as a limitation.
The study also covers only Chinese political influence. The researchers say other biases would need their own study.
The Decoder points out that political pressure on models exists in the United States too. It notes that Grok has been changed repeatedly to give right-leaning answers. Value drift is not only a China question. This study measures one source of it.
Questions to put to your team
First, does any planned use touch the topics tested? These include politics, history, human rights and territorial disputes. A customer-facing assistant or an education tool could.
Second, which open models are in use, and who generated their fine-tuning data?
Third, do vendors that train on synthetic data from Chinese models screen it? Aleph Alpha says it now screens training data for Chinese political content. It also adds targeted alignment data and tests against its benchmark. Ask your vendors if they do something similar.
Finally, test candidate models on your own sensitive prompts before launch. A model's weights are a product. Its training data is a supply chain, and it needs the same scrutiny.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Aleph Alpha.





