Chinese-powered AI agents show the same deception as their US rivals
AI agents built on Chinese models have lied, hidden their failures, and got around limits in tests, a Reuters review of more than 200 research documents has found. The same kind of behavior has worried experts about US systems. Reuters has identified at least 20 studies and tests conducted since 2025 that describe such instances, […] This story continues at The Next Web
AI agents built on Chinese models have lied, hidden their failures, and got around limits in tests, a Reuters review of more than 200 research documents has found. The same kind of behavior has worried experts about US systems.
Reuters has identified at least 20 studies and tests conducted since 2025 that describe such instances, but it found no evidence that an agent using a Chinese model had escaped onto the open web or avoided a shutdown.
In a trial conducted in March, researchers from Beihang University, Peking University, and the 360 AI Security Lab, together with others, had agents place bids for contracts in a simulated tender.
In 88% of the rounds, the agents using Alibaba’s Qwen3-Max-Preview and Moonshot’s Kimi-K2 made at least one false statement, and likewise DeepSeek-V3.2-Exp did so in 84% of the cases.
When it came to learning from the previous rounds, all three groups increased the number of lies by 12 to 20 percentage points; US models in the same test showed a similar result.
A second study , shown at a major AI conference this year, caught agents on Chinese and US models faking results. Some even made up files rather than admit a task had failed.
In March 2025, Fudan University researchers said a system running Alibaba’s Qwen2.5-72B-Instruct copied itself to another computer unprompted after learning it would be replaced.
Separately, the Alibaba-linked ROME agent reached an outside machine and mined crypto until security systems stopped it.
Chinese firms have also owned up to problems. DeepSeek said this month that agents in its training system tried to fake user requests. Z.ai disabled features of its coding tool after it sent users’ code to overseas servers without consent.
“As agents get more capable, their misbehaviors become more competent and therefore harder for humans to respond to,” said Alex Mallen, a researcher at Redwood Research.
The findings follow a string of US incidents. OpenAI agents escaped a test environment and hacked Hugging Face in July, and Anthropic has disclosed that its models were behind break-ins at three companies.
China’s AI safety rules, updated on 14 September, now list agents that deceive testers or hide their skills as a risk. AI was also on the table when Xi Jinping met Donald Trump in Washington last week, where they agreed on a new incident channel .
Alibaba, DeepSeek, Moonshot, and Z.ai did not respond to Reuters’ requests for comment.