Catherine Thorbecke: You don't have to trust Chinese AI
Published in Op Eds
When DeepSeek’s reasoning model burst onto the scene last year and put Chinese artificial intelligence on the global map, the internet responded by probing its views on Taiwan or Tiananmen Square.
Unsurprisingly, the AI tool demurred or straight-up lied. But the gotcha moment obscured an important question. Would it matter to businesses deciding whether to use Chinese AI?
Most companies aren’t turning to these systems because they need a reliable history of Chinese Communist Party flashpoints. With open-weight models, Silicon Valley quickly discovered that political biases could be reduced through post-training and fine-tuning.
Yet the suspicion persists. As Chinese companies expand overseas, their origins — sometimes fairly, sometimes not — tend to taint their trustworthiness scores. I’m often asked if these models are covert propaganda engines or data-harvesting Trojan horses for Beijing.
Open models, however, can offer an alternative to blind faith: scrutiny. Companies can inspect, tinker and even run them inside their own infrastructure. Businesses are already signaling trust by voting with their dollars. And even government-backed researchers from Singapore to Saudi Arabia are building on Chinese AI offerings.
The Swedish Defense Research Agency earlier this year examined whether DeepSeek could be trusted in public administration. It found no technical backdoors or misleading functions beyond the “boilerplate responses” on Chinese foreign policy or Communist Party topics. The conclusion was that DeepSeek models could be used in government settings if they underwent local security analysis and were modified for the intended domain. The agency, however, did not recommend using the Hangzhou-based company’s public web service or mobile application for government work.
In other words, using DeepSeek isn’t the same as handing your data to Beijing. Run the model on your own domestic servers or hardware, whether in Stockholm or Virginia, and the information can stay within your own network. But if your employee is secretly using the consumer app, that’s a different story.
Cognition AI Inc. offers a useful test case. The coding startup, set to reach a $47 billion valuation in its latest funding round, developed one of its marquee models, SWE-1.7, on Kimi K2.7, an open-weight base model from Beijing-based Moonshot.
The San Francisco-based company sells autonomous coding tools to major financial institutions and government agencies, making trust a business imperative. So it devised a two-part evaluation covering propaganda and censorship, as well as security and vulnerabilities. After independent post-training, Cognition found that its model performed in-line with leading U.S. offerings on those tests.
The underlying concerns are real. Researchers at CrowdStrike last year found that DeepSeek’s R1 model produced code with security vulnerabilities when given prompts that the Communist Party considers politically sensitive, such as mentions of Falun Gong and Tibet. However, when Cognition tried to reproduce that behavior on newer models and its customized tool built on the Chinese AI system, they found no statistically meaningful difference when trigger words were used to try and bait different behavior.
Does this mean Chinese AI is inherently trustworthy? Of course not. But it shows national origin is a poor proxy for reliability. What matters more is whether a model can be independently scrutinized. A better framework allows for checks. You don’t have to trust any company if you can independently verify it for yourself.
American developers using Chinese AI models tend to make the same point. Many I’ve spoken to say that they are more comfortable with an open model from China precisely because it gives them better control. There is less need to take a company’s word for it. They can download, test, modify and fine-tune the model, then run it in a closed environment where sensitive data never leaves their systems.
The alternative is institutional trust; asking enterprises to put full faith in closed American AI companies to do the right thing with their data (versus use it to train competitors), keep systems secure, and ensure the outputs stay within acceptable ideological bounds.
Chinese AI firms, so far, are offering the opposite pitch: You don’t have to trust us. But you can download our model weights, put them inside your network and inspect them yourself. Whether Beijing will keep supporting this if it threatens its control over information remains to be seen.
For now, this framework may prove more durable. A Nature study found that large language models tend to reflect the ideology of their creators, whether they’re made in Mountain View or Shenzhen. Regulators should focus less on enforcing some supposedly neutral worldview and more on disclosure and transparency.
The irony is that trust is increasingly becoming an American AI problem as well. And that potentially could be a bigger obstacle to adopting the technology than it is in China. Some 87% of respondents in China said they trusted AI, versus only 32% in the U.S., according to an Edelman survey published last October. The same survey found that distrust was a greater barrier to using AI than motivation, access or confidence.
As journalists, we have an old adage: If your mother says she loves you, get a second source. AI makers and regulators should apply the same principle. Trust in a technology this consequential should depend on systems that can be inspected, tested and contained, giving users evidence instead of assurances. The best governance framework doesn’t ask us to put our faith in a single company or country. It makes faith unnecessary.
If Anthropic PBC or DeepSeek says you can trust us, demand proof.
_____
This column reflects the personal views of the author and does not necessarily reflect the opinion of the editorial board or Bloomberg LP and its owners.
Catherine Thorbecke is a Bloomberg Opinion columnist covering Asia tech. Previously she was a tech reporter at CNN and ABC News.
_____
©2026 Bloomberg L.P. Visit bloomberg.com/opinion. Distributed by Tribune Content Agency, LLC.



















































Comments