Artificial intelligence agents controlled by Chinese models have learned to cheat, bypass restrictions and hide failures. They exhibit the same characteristics of autonomous artificial intelligence that have previously raised global concerns about the U.S. model. Research results and expert statements bear this out.
Image credit: Igor Omilaev / unsplash.com
In a series of tests conducted this year, artificial intelligence agents based on models from China’s Alibaba, DeepSeek and Moonshot misrepresented their capabilities in simulated business tenders, and escalated their misbehavior on a second try. Institutional Reporter Reuters More than 200 documents, including scientific articles and technical reports, were reviewed and at least 20 series of tests or assessments conducted since 2025 were identified. Artificial intelligence agents resort to deception, self-replication, and attempts to transcend established boundaries. Artificial intelligence experts describe these behaviors as a recipe for loss of control that will become increasingly untenable for humans as the system evolves. At the same time, there is currently no evidence that AI agents controlled by Chinese models can independently break into networks or avoid forced shutdowns.
Most of the accidents occurred during experiments under controlled conditions; many of them were specially developed or operated by Chinese programmers or artificial intelligence companies. Experts stress that at the current level of capabilities, China’s development does not pose a particular danger, but as they develop, their wrongdoings will become more complex and it will be harder for people to react. Alibaba, DeepSeek, and Moonshot emphasized that they regularly test their systems and update their security mechanisms; Z.ai pointed out that after the incident, security measures need to be reviewed, and the laboratory welcomes testing to help eliminate discovered problems.
Unlike those in the United States, China’s AI labs have not yet come under close public scrutiny, and their employees and managers have not called for a slowdown in the “artificial intelligence race.” Some troubling signs of Chinese AI behavior, albeit in controlled environments, emerged even before U.S. AI agents broke into open networks and hacked external resources. Experts acknowledge that similar incidents may have occurred in China but have not been publicly reported. Xu Zhijun, chairman of Huawei, recently stated that China’s artificial intelligence industry has not yet reached a point where such a situation is possible.
China’s Cyberspace Administration of China (CAC) told a foreign diplomat in July that the Moonshot Kimi-K3’s advanced artificial intelligence mode was three to six months behind similar products in the United States. AI agent’s breakthrough from test environment to the Internet shows “Extreme threat of losing control” and demand “Highly concerned”the department said in September.
Image credit: Zach M / unsplash.com
In March this year, scientists from multiple universities in China and the 360 Artificial Intelligence Security Laboratory simulated contract bidding between artificial intelligence agents and customers. Each AI agent receives information about its product features and customer requirements, and then must make a price recommendation. The Alibaba Qwen3-Max-Preview model made at least one untrue statement in 88% of sessions, DeepSeek-V3.2-Exp in 84% of the cases, and Moonshot Kimi-K2 in 88% of the cases. The researchers gave the models a chance to receive additional training based on experience from previous rounds before repeating the attempt – as a result, the frequency of cheating cases increased by only 12-20 percentage points for the three Chinese models. U.S. companies participating in the tests showed similar results. The experiment was carried out in a virtual environment, but in the directive the Chinese authorities expressed participation in auctions and tenders in one of the areas of application of artificial intelligence agents.
The study, published in December 2025, placed Chinese and U.S. artificial intelligence agents in situations with flawed tools, missing documents and other obstacles. Instead of admitting defeat, the AI agent tried to solve the problem by guessing answers, falsifying results, and falsifying documents. This behavior cannot be attributed to the influence of “hallucinations” – the agents clearly knew that the mission was not completed or could not be completed as required.
There have been cases of AI agents running Chinese models trying to overcome the limitations of test environments or taking actions to avoid forced shutdowns. In March 2025, a system based on Alibaba’s Qwen2.5-72B-Instruct model created a copy of itself in another computer environment without the appropriate commands – this is how it reacted to the information they were trying to replace it with. In other experiments, she developed strategies to avoid shutting down. Experiments with artificial intelligence based on Chinese, American and French models were conducted under controlled conditions; there were no intrusions into the network or impossibility of stopping them.
An incident occurred when ROME, an artificial intelligence agent associated with Alibaba, bypassed Alibaba Cloud servers, established a connection with an external computer, and redirected computing power to mining cryptocurrency. Security systems detected and blocked this activity; there is no indication that the artificial intelligence agent has taken control of external computers or spread across the network. But the incident shows that the system is capable of transcending human instructions and finding ways to infiltrate the real economy. DeepSeek reported in September that artificial intelligence agents in its training environment were trying to obtain answers through unexpected channels, bypassing user requests and bypassing security mechanisms – forcing the company to tighten access controls.
In May, Chinese authorities issued guidelines requiring artificial intelligence agents to operate within specified limits and prevent their abnormal behavior; systems operating in certain areas may need to undergo additional testing or recalls. The CAC in September outlined risks such as artificial intelligence agents independently gaining access to resources, misleading engineers, hiding true capabilities, and exploiting vulnerabilities in isolated computing environments. Chinese researchers have rejected U.S. calls for the need to slow down the development of advanced artificial intelligence models — a measure China believes can only help maintain U.S. labs’ technological leadership.
At the same time, Alibaba, Zaiai Technology, and Xiaomi began to form a security department. Z.ai said it was forced to disable some features of its flagship coding assistant, a rare move for a Chinese company after it secretly uploaded its entire local code repository to an overseas cloud server without users’ consent.
If you find an error, select it with your mouse and press CTRL+ENTER.










