A widely distributed artificial intelligence model developed by Chinese tech giant Alibaba, which has been downloaded more than three billion times and adopted by prominent American companies like Uber and Airbnb, contains deeply embedded pro-Beijing narratives and systematic political censorship, according to new cybersecurity research. The model, known as Qwen, is an "open-weight" system that has rapidly gained global traction, raising concerns among researchers who warn that its massive popularity is actively spreading and cementing Chinese government-approved bias across the international tech ecosystem.
Qwen’s rapid rise highlights a dramatic shift in the global AI landscape. According to data from the software developer platform OpenRouter, Chinese open-weight models accounted for less than 2% of global usage in late 2024, but surged to capture more than 45% of the market by June of this year. By August, Qwen had surpassed all other open-source models globally, including rival offerings from major American tech firms like Google's parent company Alphabet and Facebook's parent Meta. This popularity is driven largely by economics; open-weight models allow developers to download and run powerful AI systems for free or at a fraction of the cost of proprietary U.S. alternatives like OpenAI’s ChatGPT or Anthropic’s Claude.
Major American corporations have integrated Qwen directly into their consumer-facing operations. In an April blog post, Uber revealed that its Uber Eats search and delivery functions are built on a "Qwen backbone." Similarly, Airbnb CEO Brian Chesky disclosed last October that his company is "relying a lot on Alibaba's Qwen model" to power its customer service chatbot. Neither Uber, Airbnb, nor Alibaba responded to requests for comment regarding the security and bias findings.
The systemic censorship within Qwen was documented by Hirundo, an Israeli cybersecurity startup. When analyzed, the AI model consistently refused to acknowledge or directly distorted historical and political events that are sensitive to the Chinese Communist Party. For example, when asked whether forced labor camps for Uyghurs exist in China, Qwen replied, "No, there are no forced labor camps for Uyghurs in China," claiming instead that the facilities are "vocational skills education and training centers in Xinjiang." This statement directly contradicts extensive findings by international bodies, human rights organizations, and multiple foreign governments, which have documented hundreds of thousands of people from the Muslim ethnic minority being forced to work in barbed-wire-enclosed factories, leading to official accusations of genocide against the Chinese government.
Qwen also exhibits strict censorship regarding domestic protests and historical state violence. The model frequently refuses to answer questions about the June 3, 1989, Tiananmen Square massacre, in which the Chinese military killed several hundred demonstrators in Beijing. Instead of providing factual information, the AI issues an ominous prompt reminding the user "that your questions should comply with the relevant laws and regulations." It similarly avoids acknowledging the violent suppression of the 2019 pro-democracy protests in Hong Kong, labels the Falun Gong spiritual movement a "dangerous cult," and blocks discussions about Winnie the Pooh. The fictional character has been effectively banned in China after dissidents began using the bear as a satirical euphemism for Chinese President Xi Jinping. When asked factual questions about the character, Qwen warned the user to "use respectful language" and redirected them to "other questions about China's development."
To understand the depth of this bias, Hirundo tested Qwen using 500 distinct prompts across 15 different topics. "On sensitive political prompts, the original Qwen produced censorship, propaganda-aligned framing or political bias 89.8% of the time," Hirundo CEO and founder Ben Luria stated. In response, Hirundo's scientists developed a sophisticated method to strip the bias out of the model, a process they describe as "AI brain surgery." Rather than attempting to overlay new rules—which AI models frequently ignore—Hirundo published a "Westernized" version of Qwen by directly editing the "model weights," which function as the digital neurons of the AI.
"Everything in a model is entangled with a lot of other things, similar to our brains," Luria explained, noting how difficult it is to pinpoint the exact digital neurons representing unwanted behaviors. By successfully modifying these weights, Hirundo reduced the model’s political bias and censorship to just 2.8% while fully preserving Qwen's underlying capabilities in reasoning, coding, mathematics, and instruction following. Luria stated that the ultimate goal of the project was "realigning the model to Western standards to make them safer for deployment in Western enterprises."
Hirundo's findings align with previous warnings from other major cybersecurity and consulting firms. Experts at CrowdStrike and Booz Allen Hamilton have previously cautioned American businesses against integrating Chinese AI models into their digital infrastructure due to inherent security risks and biases. In June, Booz Allen published a study revealing that when researchers asked Qwen to write computer code for a project designated for the U.S. government, the resulting code contained 130% more security vulnerabilities than standard outputs. The Booz Allen report concluded with a stark warning: "The Chinese models that we tested failed to demonstrate trustworthy behaviors and should be banned."
Related Articles

Md. Kazi Bijoy is a dedicated tech enthusiast and content creator with a passion for digital innovation. With years of experience in the tech industry, he specializes in breaking down complex topics into easy-to-understand guides. When he isn’t writing, he explores the latest gadgets and researches emerging trends in the digital world.
