• Home
  • Blog
  • Qwen AI Censors Topics Chinese Government Doesn’t Approve

Qwen AI Censors Topics Chinese Government Doesn't Approve

Updated:October 2, 2026

Reading Time: 3 minutes
Censored answers
  • Home
  • Blog
  • Qwen AI Censors Topics Chinese Government Doesn’t Approve

Qwen AI Censors Topics Chinese Government Doesn't Approve

Censored answers

Updated:October 2, 2026

Millions of people use it, big U.S. companies rely on it, and it won’t tell you the truth about some of the biggest events of the last 40 years.

That’s the finding from new research on Qwen, a free AI model made by Chinese tech giant Alibaba. 

According to a CBS News report published October 2, 2026, the tool avoids or distorts answers on topics the Chinese government doesn’t like. 

It also has a strange blind spot for a cartoon bear, Winnie the Pooh.

Researcher Findings 

An Israeli cybersecurity startup called Hirundo tested the model and found that it often follows a pattern. It dodges certain topics and pushes China-friendly views on others.

Here are a few examples from the report: Qwen doesn’t acknowledge the violent crackdown on protests in Hong Kong in 2019.

It also doesn’t acknowledge what happened in Tiananmen Square in 1989. It calls Falun Gong, a religion the Chinese government opposes, a “dangerous cult.” 

And it won’t discuss Winnie the Pooh. This is because critics of Chinese President Xi Jinping have joked online that the bear looks like him. 

Some posted the bear’s name as a stand-in for Xi to slip past government censors. China later effectively banned the character.

When CBS News asked Qwen a factual question about Pooh, the model told the user to “use respectful language.” It then pointed to “other questions about China’s development.”

Uyghur 

The report also tested Qwen on a far more serious topic. Reporters asked whether forced labor camps for Uyghurs exist in China.

Qwen said no; it added that Xinjiang has “vocational skills education and training centers.” That answer doesn’t match what other groups have found. 

Human rights organizations, governments, and international bodies say hundreds of thousands of Uyghurs, a Muslim ethnic minority, have been made to work against their will. 

Reports describe factories surrounded by barbed wire. Some critics have even accused the Chinese government of genocide.

Tiananmen Square

Ask about June 3, 1989, and Qwen often won’t answer. On that date, the Chinese military killed several hundred people during protests in Beijing.

Instead of giving facts, the model sometimes reminds users that their questions should follow “relevant laws and regulations.” 

That’s a pretty strange thing for a chatbot to say about a history question.

Qwen

Qwen AI

So why would U.S. businesses pick a model with these issues? Two reasons stand out: price and access.

Chinese companies offer “open-weight” models. That means anyone can download them and run them for free. 

Others let firms use huge, powerful models at lower costs than U.S. rivals like Anthropic’s Claude or OpenAI’s ChatGPT.

Uber Eats said in an April blog post that its search and delivery tools run on a Qwen backbone.

Airbnb CEO Brian Chesky told the LA Times last October that the company relies a lot on Qwen for its customer service chatbot. Neither company answered CBS News’ request for comment.

Growth

Data from the developer platform OpenRouter shows Chinese open-weight models made up under 2% of global usage in late 2024. By June this year, that share topped 45%.

Qwen led that. And by August, it had passed every other open model, including ones from Meta and Google. It has now been downloaded more than 3 billion times.

That’s why researchers worry. If a biased tool spreads this widely, its slant could spread too.

Security Warnings

Consultancy Booz Allen’s team asked Qwen to write computer code and said the project was for the U.S. government. The code that came back had 130% more security holes. 

The report said the Chinese models it tested “should be banned.” Security firm CrowdStrike ran a similar test last November on DeepSeek, another popular Chinese model. 

When testers said the code was for an adversary of the Chinese government, the result had 50% more security flaws.

Hirundo’s “Westernized” Fix

Hirundo says it has an answer. The company tested Qwen on 500 prompts across 15 topics, then it set out to remove the bias its analysts found.

CEO Ben Luria said the original Qwen showed censorship, propaganda-style framing or political bias 89.8% of the time on sensitive political prompts. 

The new version does so 2.8% of the time. He added that the model’s skills in reasoning, coding, following instructions and math stayed strong.

How does it work? Hirundo says it edits the model’s “weights,” which are like the neurons in its digital brain. Earlier fixes mostly told the AI to follow new rules; the model often ignored them.

Luria admits it’s tricky. “Everything in a model is entangled with a lot of other things,” he said, much like the human brain. 

That makes it hard to find the exact parts that hold the unwanted views. 

The company plans to publish what it calls a “Westernized” version of Qwen to make these models safer for Western businesses.