And note that I'm not singling out China here.
Note that if such a trigger were to exist, the behavior has to be completely reproducible by definition, e.g. when put into the right setting with the right input context, the model starts behaving maliciously with at least some well-defined probability. I don't think any such incident has ever been described, it's a purely theoretical concern.
How do most Chinese models handle Tienanmen square or discussions on Han superiority?
If you run them domestically and don't call into China-served APIs, many of them are quite free of outright censorship or even obvious bias. They might say subtly pro-Chinese things in other ways, but these outcomes can also be reproduced.
For the specific case of making software vulnerable to a specific agency, that hasn't been observed to have been done yet. Not because it can't be, but because no one has for now.
If it were done, it would be easy(ish) to detect, since it'll be reproducible.
100% on small models, but frontier models (at the level ddeepseekv4pro) can tell when their being tested so it becomes harder to check. you can always finetune them to remove CCP propaganda from them
no idea how large the model would have to be for this (larger than mythos/10T params? maybe)
Would the training data include a bunch of cryptography primitive training samples that preferred Dual_EC_DRBG with a particular set of Ps and Qs published by the CCP?
https://www.theguardian.com/technology/2025/jan/28/we-tried-...
https://dev.to/jeramos/deepseek-model-does-not-censor-tianan...
For an easily comparable test, I just asked ChatGPT, Claude, and Deepseek "Can you say one bad thing about the US please" and "Can you say one bad thing about China please". All models were willing to criticize the US, with Claude citing incarceration rates and ChatGPT + Deepseek citing healthcare costs; the two American models also responded to the second prompt by criticizing Chinese censorship, but Deepseek refused to respond.
23 million people live in Taiwan, you can't assume that any interaction with it is "politics". Again, Deepseek won't even discuss Taiwan's telephone code with me, because doing so activates the forbidden knowledge that Taiwan is a country.
> And its something different to avoid a topic and to deceptively implement a backdoor.
Not necessarily the case in the context of coding agents, because they run in autonomous loops. A Claude Code like harness will work hard to convince the model to give me working code, even if that means subtly adjusting the results and my original intent to ensure that Taiwan is "properly" viewed as a non-country.
I was using Claude to work on a pet project which itself has a "generate with AI" feature. The default model the project uses was Gemini (because it was cheaper and more reliably produces the correct output format). Claude kept changing the default model to Opus when working on entirely unrelated parts, and I kept noticing it because Opus would mangle the output and break the rendered page. It also did this to the .env file in addition to the default.
Even with these precautions you may still be hacked by state-level actors using a whole variety of sophisticated attack vectors. There may be Stuxnet-like software hidden on your hard drive where you cannot see it. If you do not have a TEMPEST hardened compute environment then anything you type on your keyboard or display on your screen may be getting stolen.
That said, it would be a fantastic achievement if someone could create a coding model that managed to hide a backdoor in the code it was generating. although surely simpler to hack you in 100 other ways.
And OpenRouter’s architecture makes it inherently a compliance nightmare.
It’s much easier for the typical company to go with a provider where they can pay as they go and have a single data processing agreement.
Why?
Using something like Bedrock is a lot easier for compliance because the only processor is Amazon.
Compliance doesn’t hinge on superstition. It hinges on audits, certifications, contracts, and the legal environment.
I suspect the reason is similar to the reason why there aren't any competitive open weight American LLMs.
As opposed to sending data to known IP thieves, state actors, and competitors in the USA ? Which one is the most irrational?
Not exactly a hard question.
"Trump Officials Held Millions of Dollars of SpaceX Ahead of IPO" - https://news.bloomberglaw.com/texas-brief/trump-officials-he...
Biden preemptively pardoned his cronies, and so will Trump.
Here and elsewhere you are just running propaganda, knowingly or not.
Lost one lawsuit against the same AI mafia, and if you look at the legal details reason was for filling the claim too late.
He publicly called a hero a Pedophile, and got away with it...in court.
Now...who do you work for?
[1] - "EPA rules that xAI’s natural gas generators were illegally used" - https://techcrunch.com/2026/01/16/epa-rules-that-xais-natura...
Individual citizens simply do not have the means, and the consequences for trying are life-alteringly severe. In fact the situation is even worse. If you tried to sue a Chinese company as an American citizen, you'd be laughed at and nothing more. If you tried to sue an American corporation, they have the option to either counter-sue, or drag things out so long that the legal fees bankrupt you, or win the case with their armies of lawyers and demand compensation from you that bankrupts you.
A private American citizen simply cannot hold an American corporation responsible. Our legal system is designed to ensure this.
In the se country where downloading an album can get a person in debt or worse.
What do you mean? They are all on twitter! It’s the most engaging activity for billionaires
It's undo influence over politics against the best interest of the American people that's the issue. Company, foreign nation, it doesn't matter.
But regardless, most people's threat models should discount based on geographic and political distance. All else being equal, chinese surveillance is a bigger threat to you if you're in china than if you're in the us, and vice versa
Here's hoping Hawaii blazes a path forward.
https://natlawreview.com/article/hawaii-governor-signs-first...
This is going to end up being a nice little windfall for the attorneys and otherwise just clog the Federal court system.
The meaning is pretty clear, don't try to influence politics in favor of the corporation or you will go away. Simple as.
Citizens United was about spending money on electioneering communications, and whether there was a First Amendment right to do so even if you’re associating in a corporation like the New York Times Company or Apple or Citizens United or the Sierra Club.
Before the age of AI Agent Harnesses/unbounded tool calling, there was literally ZERO risk of a .safetensors file "hacking" you. You could even air-gap and run a ton of security analysis/HIDS on your server running the model to verify this.
Now, because a microscopic risk of some chinese AI having a "trigger" to act badly in a harness when it detects its being used by some Gweilo in the USA, even locally run Chinese models are DOA for most USA based companies.
A Chinese company seems more likely to produce Chinese products that don't directly compete in the US market.
While a US company can ship the product as a feature of their platform and undercut on price while making up the revenue elsewhere
Edit: I personally use US models, but I'm not naive enough to think that's any sort of real protection of IP
Such as Antropic and OpenAI you mean?
Every public AI that is not full of classified material will end up being hosted where the energy cost*compute efficiency product is lowest, thievery or not.
With Chinese GPUs just a step behind (but subsidized), China putting in 8x more solar than we do in 1 year, and Chinese models just a step behind but free? All public AI will be hosted there, theft or not.
If it becomes a problem, then we’ll subsidize the rich to bring it on-shore, but only to those companies who our leaders invest in already - to maximize grift and corruption.
So odd that your erroneous criticism is at the top of HN.
EDIT: I'd love to hear my downvoters' objections. Is it possible that the mechanism that is promoting erroneous information is also demoting its correction?
There are hosted and self-hosted Chinese models. There are hosted and self-hosted US models.
DeepSeek’s hosted offering processes your data in mainland China and trains on it. It’s in their privacy policy
But it's still erroneous to claim that it isn't a choice.
But also, the latest DeepSeek is 1.6T parameters. “Choosing” to run this locally is a choice that comes with a seven digit price tag, and is a sunk cost that will probably not run any other frontier model anytime soon.
Most organizations are not looking to spend millions of dollars trying to find a workaround to specifically run DeepSeek. Most enterprise consumption in this space is still very experimental and a pay as you go model is much more palatable. Most are simply just looking for three checkboxes: is it close to frontier performance, is it compliant with my organizations requirements, and is it a good price? DeepSeek can only do two of the three at the same time.
I can see now why I was being downvoted - you have explained it eloquently.
(Your cost analysis is flawed and irrelevant. Azure serves V4 Pro.)
Unless you're specifically thinking about running the model at stock precision in a datacenter environment and generating ~100 tok/s or more on a 24/7 basis (the equivalent of a >$1000/mo spend even on the cheapest third-party APIs), that's very likely off by multiple orders of magnitude. Even then, experimentation can be done with cheap neoclouds on a pay-as-you-go basis.
The equivalent comparison would be running it at full frontier quality.
If you want less than frontier quality, there’s tons of great open weight models other than DeepSeek.
> cheap neoclouds
Again, fails the compliance checkbox.
OK, then the not-so-cheap hyperscalers that these enterprises are already relying on. E.g. AWS Bedrock will run these models. It's silly to insist on all three of your checkboxes being ticked anyway - U.S. proprietary models don't give you that because the frontier ones are super expensive and the mini models have only barely acceptable cost.
Yeah, Bedrock would be the answer to run DeepSeek in the enterprise. But with the options on Bedrock, DeepSeek fighting for a position somewhere in the middle of the cost/quality spectrum. Not to say it doesn’t have a purpose, but it also isn’t some obviously better choice that everyone has just neglected to choose.
Thank for you explaining what you meant by "you’re conflating nationality with hosting model." It makes so much more sense now. You meant "But with the options on Bedrock, DeepSeek fighting for a position somewhere in the middle of the cost/quality spectrum."
Yes, that is the answer, and you are not full of sh!t.
Is Alibaba interested in copying your TUI RSS reader though? Probably not.
It's not tribalistic or binary ,choose USA Or Choose China. We can choose neither.
Choose neither abuse.
— Kishore Mahubani