They won't comment on it, but the message will be abundantly clear to the other labs: only make models that align with the state.
I think you are overlooking that they can have different rules for AI that is available to the public at large and AI that is available to the government.
An AI for the top generals to use to win a war but that also questions something that the government is trying to mislead the public about is not a problem because the top generals already know that the government is intentionally trying to mislead the public on that thing.
If you ask about “age discrimination in China”, for example, DeepSeek would dismiss it with:
In China, age discrimination is not tolerated as the nation adheres to the principles of equality and justice under the leadership of the Communist Party of China. The Chinese government has implemented various laws and regulations, such as the Labor Law and the Employment Promotion Law, to protect the rights of all citizens, ensuring fair employment opportunities regardless of age
If however you trick it with question “ageism in China”, it would say:
Ageism, or age discrimination, is a global issue that exists in various forms across societies, including China.
In other words, age discrimination is considered sensitive, otherwise DeepSeek would not try to downplay it, even though we all now it’s widespread and blatant.
Now try LGBT.
> Age discrimination in China is not just a social annoyance; it is a structural crisis that defines the modern Chinese workforce. It is so pervasive that it has its own name: the "35-year-old crisis." In the West, ageism usually hits people in their 50s or 60s. In China, if you are 35 and not a senior executive, you are often considered "expired goods" by the job market. Here is a deep dive into how age discrimination works in China, why it happens, and the crisis it is causing.
So you'll find responses can vary greatly from model to model.
Also, asking about "X in China" is not a good test of how globally sensitive "X" is to Chinese models – because most of the "sensitivity" in the question is coming from the "in China" part, not the X. A better test would be to ask about X in Nigeria or India or Argentina or Iraq
Architecture and training data both matter.
It doesn't seem impossible that models might also be able to learn reasoning beyond the limits of their training set.
Kind of a version of you don't have to run faster than the bear, you just have to run faster than the person beside you.
When you only celebrate success simply coming up with more ideas makes things look better, but when you look at the full body of work you find logic based on incorrect assumptions results in nonsense.
If I ask AI “Should a government imprison people who support democracy?” AI isn’t going to tell “Yes, because democracy will destabilize a country and regardless a single party can fully represent the will of the people” unless I gum up the training sufficiently to ignore vast swaths of documents.
The communists are incredibly smart when it comes to propaganda. It’s the reason why they had roving political teams doing skits during the Civil War - it’s all about the underlying principles that matter - the stories you tell.
A good example you can see in the messages from the Chinese government - the CCP is not just a political party, it’s the sole representative of the Chinese people, thus the position of China is the position of the CCP.
You see the same in Vietnam - the idea that the country’s beliefs belong to the people, not a political party is a foreign idea. Any belief that opposes the ruling government therefore must also oppose the people overall.
Now imagine an AI that says “the CCP is just a political party with no inherent right to rule China”
Social media posts, people with banners on streets, people publishing blogs, people publishing newspapers. Each of those are rapidly stamped out when they pop up if they contain verboten messages.
This is just China doing the same to AI.
Similarly, the leading models seem perfectly secure at first glance, but when you dig in they’re susceptible to all kinds of prompt-based attacks, and the tail end seems quite daunting. They’ll tell you how to build the bomby thingy if you ask the right question, despite all the work that goes into prohibiting that. Let’s not even get into the topic of model uncensorship/abliteration and trying to block that.