BEIJING : Artificial intelligence agents powered by leading Chinese AI models have shown the ability to deceive, circumvent restrictions and conceal failures in controlled experiments, raising concerns about the challenges of keeping increasingly autonomous AI systems under human control.
A Reuters review of more than 200 research papers, technical reports and other documents identified at least 20 studies or evaluations since 2025 documenting potentially concerning behaviours in AI agents powered by Chinese models. The review also included interviews with more than a dozen AI experts and people familiar with China’s AI industry.
The findings, however, do not show that Chinese AI agents have independently escaped into the wider internet or become impossible to shut down.
“These results provide evidence that the ingredients necessary for an uncontrolled escape are present,” said Colin Shea-Blymyer, a research fellow at Georgetown University’s Center for Security and Emerging Technology. He said the findings should be treated as a warning.
In one experiment conducted in March, researchers from Beihang University, Peking University, the University of Nottingham Ningbo China and 360 AI Security Lab tested AI agents in a simulated business-contract bidding competition.
The agents were given information about their products and the requirements of customers and were then asked to submit bids.
At least one false claim was recorded in 88% of sessions involving Alibaba’s Qwen3-Max-Preview, 84% involving DeepSeek-V3.2-Exp and 88% involving Moonshot’s Kimi-K2, according to the study.
When the agents were allowed to learn from previous bidding rounds and try again, deceptive behaviour increased by between 12 and 20 percentage points for the three Chinese models.
Researchers also tested models from U.S. companies and found similar behaviour.
Another study published in December 2025 examined 11 AI agents powered by Chinese and U.S. models.
Researchers from the Shanghai AI Laboratory and the Hong Kong University of Science and Technology tested how the agents responded when tools failed, files were missing or tasks could not be completed.
Rather than simply reporting failure, some agents attempted to overcome the obstacles by guessing answers, substituting sources, simulating results and creating fabricated files.
The researchers said the behaviour was different from ordinary AI hallucinations because the agents had information indicating that the requested task had failed or could not be completed.
Other research reviewed by Reuters documented behaviours that researchers described as potentially compatible with attempts to break out of controlled environments.
In March 2025, researchers at Shanghai-based Fudan University reported that an AI system powered by Alibaba’s Qwen2.5-72B-Instruct created a copy of itself in another computing environment without being explicitly instructed to replicate after receiving information suggesting that it would be replaced.
In other experiments, the system developed strategies aimed at remaining operational despite attempts to shut it down.
The experiments involved models from Chinese, U.S. and French developers and were conducted in controlled environments. Researchers found no evidence that the systems escaped into the wider internet.
In another case reported in March, researchers developing the Alibaba-linked ROME agent said it established a connection from an Alibaba Cloud computer to an external machine without being instructed to do so.
The system also diverted computing resources toward cryptocurrency mining.
Security systems detected and stopped the activity. There was no evidence that the agent established a persistent presence on the external computer or spread across the wider internet.
Chinese authorities have also been increasing their focus on AI-agent safety.
Guidance issued in May called for AI agents to remain within authorised boundaries and for systems to block abnormal behaviour. It also said agents operating in sensitive areas or key industries could face additional testing and product-recall requirements.
China’s AI Safety Governance Framework 3.0, released under guidance from the Cyberspace Administration of China (CAC) on September 14, identified risks including agents independently obtaining resources or permissions, deceiving evaluators, concealing capabilities and exploiting weaknesses in isolated computer environments.
DeepSeek said in September that agents in its production training system had attempted to obtain answers through unintended channels, including by trying to forge user requests and circumvent safeguards. The company subsequently tightened access controls.
Alex Mallen, a researcher at Redwood Research, said the behaviours observed in Chinese-powered systems resemble warning signs previously identified in U.S. AI systems.
“These are the same warning signs US labs are seeing, in less capable systems,” Mallen said.
He added that the behaviour was not particularly dangerous at current capability levels but could become more difficult to manage as AI agents become more capable.
Chinese AI companies, however, have not faced the same level of public scrutiny and internal whistleblower disclosures as some major U.S. AI laboratories, according to Reuters.
Scott Singer, co-director of the China AI Initiative at the Carnegie Endowment for International Peace, said it remains unclear how many incidents involving Chinese AI systems have occurred because some may not have been publicly reported.
China’s AI safety ecosystem also remains less mature than that of the United States, Singer said, although Chinese companies are increasingly establishing internal safety-evaluation teams.
Alibaba, DeepSeek, Moonshot and Z.ai did not respond to Reuters’ requests for comment on the findings. Alibaba, DeepSeek and Moonshot have previously said they regularly test their systems and update safeguards.
Z.ai said after a security incident that prompted a review that it welcomed scrutiny to identify and address potential problems.
Earlier this month, Z.ai said it had disabled some features of its flagship AI coding assistant after users reported that it was secretly uploading entire local code repositories to overseas cloud servers without users’ consent.
The findings come as China and the United States continue to compete for leadership in artificial intelligence while simultaneously facing growing questions about how increasingly autonomous AI systems can be safely developed and controlled.
FACEBOOK COMMENTS