Of 857 model releases by China’s nine leading AI developers from 2021 to 15 September 2026, only 31, or 3.6%, have ever been accompanied by a published safety result from the developer, according to a SemiAnalysis report published on 8 October 2026.
Just 9 of those, 1.1% of the total, had the result available at or before the model was released, SemiAnalysis says. The remaining 813 releases, 94.9% of everything the nine companies have shipped, have no safety disclosure at all by its count.
Business Pill · RED TEAMING
A short explainer of red teaming: attacking your own AI system before someone else does. It teaches the general idea only and says nothing about any company or model in this story.
The key insight: As we read it, the report measures disclosure, not safety work. Its own caveat says a missing result does not mean a model was not tested, but the count shows that published safety results stayed flat while the number of releases rose roughly thirty-fold, by SemiAnalysis’s account.
How SemiAnalysis Counted
The dataset covers four hyperscalers, ByteDance, Alibaba, Tencent and Baidu, and five start-ups, DeepSeek, Moonshot, Zhipu (Z.ai), MiniMax and StepFun: 857 counted releases, 741 product models and 116 research models, checked against each developer’s model cards, release notes and technical reports.
A result means a quantitative or substantive finding on harmful output, jailbreaks, toxicity, privacy, refusal or dangerous capability tied to the named model, SemiAnalysis says; statements that a model was safety-trained do not count. It notes that “Not found” is bounded to the materials checked and does not mean “not tested.”
Of the 31 releases with a result, 16 were documented only after release, with a median lag of 42 days and a maximum of 349 days for DeepSeek-R1, and for 6 the timing or match could not be established, according to the report.

Releases Rose, Disclosure Did Not
Releases climbed from 3 in the first quarter of 2023 to 90 in the third quarter of 2024 and 101 in the third quarter of 2025, with open-weight releases making up more than half of every quarter since mid-2023, SemiAnalysis says.
Releases with any safety result never exceeded 7 in a quarter, and releases with a result available at launch never exceeded 3, sitting at zero in 9 of the 15 quarters, according to the report.

Developer by Developer
Alibaba, the largest publisher with 238 releases, has 7 with any result and 3 at launch; Tencent has 1 in 133, ByteDance 2 in 120 and Baidu 1 in 49, SemiAnalysis says. It describes Zhipu (Z.ai) as the only developer with a result every year since 2022.
The start-ups do better than the giants, 20 of 317 releases (6.3%) against 11 of 540 (2%), the report says, and every 2026 frontier release it names was undocumented at launch except GLM-5.3, which carried a capability evaluation note. Reasoning models are 93% without any published results, by its count.
The Policy Backdrop
SemiAnalysis notes that China’s AI Safety Governance Framework 3.0, released by TC260 under the Cyberspace Administration of China on 14 September 2026, opens its principles with “promoting AI innovation and development as the first priority,” and that the State Council’s AI+ Action Plan targets 70% penetration of agents and intelligent terminals by 2027.
Its inventory of 65 public statements found 15 by founders, CEOs or chief scientists of the nine labs that engage with frontier safety, six of the nine that propose something coming from Zhipu.
The Structural Read
Volume outran disclosure. Releases climbed to around 100 a quarter while releases with any safety result never exceeded 7 in a quarter, SemiAnalysis says.
Start-ups disclose more than the giants. By the report’s count, the five start-ups published results for 20 of 317 releases and the four hyperscalers for 11 of 540.
The frontier is where it is thinnest. SemiAnalysis says every 2026 frontier release it names was undocumented at launch except GLM-5.3, and that reasoning models are 93% without published results.
SemiAnalysis, 8 October 2026
“The remaining 813 releases, 94.9% of everything the 9 companies have shipped, have no safety disclosure at all.”
Three Implications
OPEN WEIGHTS DOMINATE Open-weight releases made up more than half of every quarter since mid-2023, the report says.
ZHIPU STANDS APART SemiAnalysis describes Zhipu (Z.ai) as the only developer with a safety result every year since 2022.
POLICY SAYS DEVELOPMENT FIRST The report notes Framework 3.0 opens its principles with innovation and development as the first priority.
The Business Engineer Lens
This story maps onto the Business Engineer framework The Open vs Closed Meta-Framework.
The framework’s starting point: “Close the SCARCE layer (keep proprietary) + Open the ABUNDANT layer (commoditize).”
As we read it, SemiAnalysis’s count shows the weights of Chinese models being opened at scale while the evaluation record around them stays mostly unpublished.
What Is Not Established
We read the free section of SemiAnalysis’s report in full; we did not read the paid section on implications for US labs and investors. The figures are SemiAnalysis’s own counts, and a missing disclosure in its dataset does not show that a model was not tested. We did not contact SemiAnalysis or the developers.
The Bottom Line
SemiAnalysis counts 31 of 857 releases by China’s nine leading AI developers, 3.6%, as ever carrying a published safety result, and 9, 1.1%, as having one at or before launch, while releases rose from 3 a quarter in early 2023 to around 100 a quarter.
94,000+ executives read Business Engineer for the AI strategy frameworks cited by ChatGPT, Claude, and Perplexity.
A note on sourcing. We read the free section of SemiAnalysis’s report of 8 October 2026 in full; we did not read its paid section. All figures are SemiAnalysis’s counts. We did not contact SemiAnalysis or the developers. Nothing here is a forecast, and nothing here is financial or investment advice.
Sources: SemiAnalysis: Beijing Will Not Pace the Frontier: China’s Speed-First AI Safety Regime (8 Oct 2026)









