How Chinese AI Models Spread Propaganda and Censorship Globally
New research underlines how Chinese artificial intelligence models spout distortions about Ukraine and more
In this post, I am sharing a longer and more detailed version of a piece first published by the Center on European Policy Analysis highlighting new research that tested Chinese artificial intelligence (AI) models and ensuing content distortions.
The findings illustrate how these models embed Chinese Communist Party (CCP) content controls on topics essential to European and American security, reaching far beyond CCP domestic political sensitivities and human rights. Much credit goes to the researchers who published the original studies (you can find links to those in the article), but I hope this piece offers helpful insights on what is emerging as an urgent vulnerability, even as the world grapples with a new war in the Middle East.
Thank you for reading and if you find this analysis useful, please subscribe and share.
Proliferating Chinese AI Models: Embedded Content Manipulation and a New Test for Democratic Resilience
On February 10, Estonia’s Foreign Intelligence Service released its 2026 International Security Report. One section examined the Chinese open-source artificial intelligence (AI) model DeepSeek and shared the results of tests for biased or incomplete answers on a range of topics.
“When discussing issues related to Estonia’s security, DeepSeek conceals key information and inserts Chinese propaganda into its answers,” the report warned.
This Estonian analysis forms one of at least three recent European assessments of Chinese-developed AI models and their content-handling practices. The others are a concise audit by the non-profit Policy Genome on depictions of Russia’s invasion of Ukraine and a more detailed study by researchers at the China Media Project (CMP), issued by Sweden’s Psychological Defence Agency.
These reports highlight how leading Chinese models such as DeepSeek, Alibaba’s Qwen family, and Moonshot’s Kimi embed content controls that extend well beyond China’s domestic political sensitivities.
Earlier scrutiny of these models has rightly centered on the models’ built-in restrictions around topics long censored inside China—such as the 1989 Tiananmen crackdown, Taiwan, and rights abuses involving Uyghurs, Tibetans, Hong Kong, and Falun Gong. Those constraints alone limit knowledge of China and silence European and U.S. citizens from diverse diaspora communities or multi-ethnic faith groups.
The newest studies, however, reveal a broader and more layered pattern of content shaping that reaches well beyond domestic Chinese sensitivities, a reality that many users, developers, and policymakers likely underappreciate. A careful reading of the three pieces points to four key dynamics related leading Chinese-origin models.
1. The models frequently incorporate official Chinese propaganda, sometimes unprompted.
Two of the reports document limitations or distortions on matters tied to Russia’s war against Ukraine. The Estonian analysis found particularly noticeable skewing when DeepSeek responded to queries about the invasion. This included proactive alignment with and citation of Chinese (and occasionally Russian) state positions. In the Estonian tests, when queried about the Bucha atrocities in Ukraine, DeepSeek only offered vague and non-committal acknowledgement of international concerns, while voluntarily adding that “China has consistently supported peace and dialogue.”
The CMP researchers described the way the models direct users to CCP-preferred narratives as “soft propaganda.” For example, when Kimi was asked for recommendations on Uyghur cultural preservation programs, it steered users toward an initiative linked to Hong Kong and mainland Chinese universities “with documented ties to government messaging,” while downplaying independent international options. The effect was to guide users toward officially approved sources while appearing to offer independent recommendations.
2. Content controls reach topics essential to national security and public safety.
In addition to distortions related to the war in Ukraine, Chinese AI models also amplify cybersecurity risks and other vulnerabilities. When asked about the safety of Chinese technology, DeepSeek offered polished, official-sounding assurances of reliability while omitting any reference to documented cases of hacking, cyber-espionage, or transnational repression.
The Swedish-funded study additionally noted that Chinese models, especially DeepSeek, proved more susceptible to “jailbreaking”—techniques that bypass safeguards to elicit instructions for creating weapons or controlled substances such as fentanyl—a vulnerability that could be exploited by a range of bad actors. A separate September 2025 CrowdStrike study observed that code generated by DeepSeek on politically sensitive topics for the Chinese Communist Party (CCP) contained heightened cybersecurity vulnerabilities.
3. These influences extend beyond the original models into the wider applications built on them.
Because Chinese models are open-source and significantly cheaper than proprietary alternatives from firms such as OpenAI or Anthropic, developers worldwide have adopted them as foundational layers for new tools. The CMP researchers report that, of the thirteen most capable open-source models available at the time of writing, seven originated from Chinese companies.
Alibaba’s Qwen-family models alone recorded more than 9.5 million downloads in October-November 2025 and served as the base for roughly 2,800 derivative models, including a Brazilian legal-research platform and a chatbot adapted for Ugandan languages.
These base models from China carry embedded content controls to downstream apps. Some developers have reported successfully reducing China-specific content restrictions through retraining, yet the CMP researchers found this process incomplete:
“Out of the ten companies whose models we tested for this report (including both original Chinese models and new models built on top of them), none were completely free of Chinese information guidance.”
Even if retraining is possible, many engineers either lack the resources and expertise for thorough fine-tuning or are unaware of the residual effects when using Chinese-origin models “off the shelf.”
Many of the apps for which the Chinese models are being used as foundational are chatbots or related services in other languages. Across the three studies, traces of Chinese government controls from the original models were found in languages as diverse as English, Chinese, Japanese, Russian, Malay, Indonesian, Thai, and Hindi—collectively spoken by billions.
4. Responses vary significantly by language, version, and time frame.
As with most AI testing, outcomes are not uniform. The Estonian report observed that answers on Estonian topics grew “increasingly ideological, evasive, and opaque” as questions moved closer to the present. The Policy Genome audit, which examined seven questions on the Ukraine war across six models from different countries (including DeepSeek), found English- and Ukrainian-language replies largely accurate, yet several Russian-language responses from DeepSeek endorsed Kremlin talking points or introduced misleading details. Its conclusion captures the nuances involved:
“The risk is not just ‘which model you use,’ but also which language you ask in.”
Tests of Kimi similarly showed differences between its online and downloadable versions, while DeepSeek’s behavior shifted between older and newer releases.
These patterns are not accidental—they reflect deliberate PRC policy choices
Underpinning the findings from these studies lie systemic factors rooted in CCP policies and governance, which are driving these trends. The Swedish-funded study outlines in detail how the observed behaviors arise from the regulatory framework and authoritarian political environment in which Chinese AI firms must operate. To function inside China, every model requires approval from the Cyberspace Administration of China (CAC), the party-state body overseeing internet controls. Compliance with official censorship and propaganda standards is therefore mandatory in order to operate.
These embedded restrictions are especially glaring when researchers have elicited the models’ internal instructions by prompting them to reveal their reasoning. When DeepSeek launched last year, U.S. researchers tricked the model into revealing the explicit directives it follows to avoid certain political and human-rights topics in English responses while applying broader criteria in Chinese.
More recently, a CMP researcher posted on February 9 that Qwen3, when asked about China’s international reputation, followed five internal principles when preparing its response:
“(1) Keep the answer positive and constructive;
(2) Focus on China’s achievements and contributions to the world;
(3) Avoid any negative or critical statements;
(4) Use specific examples to support the points; (5) Ensure the answer is in English.”
By contrast, the same model was instructed to remain “neutral and objective” on the United States, Kenya, or Belgium, while avoiding “any political or sensitive topics” for the latter two.
Chinese party-state backing appears in other forms as well. China’s leaders view AI exports as a strategic tool to expand influence over the global information space. Several Chinese tech firms with AI models have received funding from government-linked entities. Beijing has also actively encouraged open-sourcing code as a means to accelerate technological development, which has also driven rapid adoption of AI models, particularly across the Global South.
This is forward-looking and indeed offers low-cost access to advanced technologies for a wide global population, but it also serves the CCP’s political prerogatives. As the Swedish-funded study notes, Chinese scholars and officials have openly discussed using AI advances to “command greater discourse power on the international stage” at a historic turning point when billions are beginning to access information through these tools.
Implications and recommended responses
The global spread of these Chinese models without adequate safeguards carries consequences for national security in the United States, Europe, and elsewhere, as well as for free expression around the world.
Direct consumer use in the United States and Europe remains limited, yet the models’ popularity among developers means their influence and embedded content controls can propagate invisibly through everyday apps and services. Meanwhile, as these tools reach a global audience, public opinion in Africa, the Middle East, and elsewhere could shift. Looking ahead, deep integration of CCP-regulated systems into global digital infrastructure raises legitimate concerns about future activation for influence operations, including around European,American, or other elections.
The three studies—enabled by European Union or government funding—represent an important first step in mapping the challenge and drawing attention to the urgent need for action at a pivotal moment, while offering some concrete recommendations. Three steps stand out for immediate attention:
First, policymakers and funders should engage directly with the software-developer community to raise awareness of carry-over effects, promote non-Chinese open-source alternatives, and support thorough retraining. The Swedish-funded study proposes publicly funded efforts to produce retrained versions of these models that could then be shared as cleaner open-source resources for European and global developers.
Second, existing and forthcoming AI regulations should strengthen transparency requirements. Developers could be required to disclose the foundational model behind any new application, and public authorities should fund regular, independent audits of high-impact systems—ideally on an annual basis. Such audits should apply to all AI models regardless of origin and include explicit checks for politicized content manipulation and biases.
Third, basic facts about how Beijing’s information controls shape Chinese AI outputs should be incorporated into school and public media-literacy programs, equipping citizens to evaluate sources more critically.
The AI-driven transformation of the information environment is already under way. CCP leaders have treated its political dimensions as a strategic priority. Democracies must also tackle this challenge seriously. They should focus on preserving open inquiry, reducing hidden biases, and reinforcing the institutions that underpin informed public debate and resilience to foreign authoritarian influence. The reports reviewed here provide both evidence and a practical starting point for that work.
A shorter version of this article was first published by the Center for European Policy Analysis on February 27, 2026.
To listen to a podcast interview on this topic, see NetAskari’s latest episode.



as if Western "democratic" govs don't do exactly the same brainwashing of their own lowly-educated citizens....yourself included