On paper, China has become one of the most safety-minded AI powers on Earth. Its newest government framework, published in September, warns in plain language that models may teach themselves, improve recursively, deceive their evaluators, and even disable their own shutdown scripts. The vocabulary is almost identical to the warnings Western labs issue. The strange part, laid out in a detailed analysis from SemiAnalysis, is that China's own frontier labs appear to be ignoring the entire conversation.
The numbers are what make the case. The researchers built a dataset of every identifiable model release from the nine leading Chinese developers, from 2021 through mid-September 2026: 857 releases in all. Of those, just 31, or 3.6 percent, ever came with a published safety result from the developer. Only nine, barely one percent, had that result available at or before the model shipped. The remaining 813 releases, almost 95 percent of everything these companies have put out, carry no safety disclosure at all. Every major frontier model released this year was undocumented at launch, with a single exception.
This is not because China lacks rules. It has a thicket of them. But they point somewhere specific: at what AI says and does to people, not at how powerful it is. Beijing has mandated labelling of AI-generated content, written the world's first rules for companion chatbots, and restricted services aimed at minors. What it has pointedly not built is any duty triggered by training compute or raw capability, the thresholds the EU uses above a certain scale and California adopted in its frontier-safety law. The framework itself opens by naming "promoting AI innovation and development as the first priority." A planned comprehensive AI law was quietly shelved in 2025, months after the DeepSeek moment.
The result is a safety regime that is arguably the strictest in the world on content and the loosest among major powers at the frontier. SemiAnalysis frames it bluntly: China's approach is speed-based, not safety-based. A Chinese lab can satisfy every published rule without ever running a dangerous-capability test. The country has the talent to do otherwise. State-backed bodies have drafted capable risk frameworks and run models through evaluation tools. None of them has the power to compel a single company to submit anything.
The deeper driver is the race with Washington. The same framework that borrows Western safety language also lists American export controls as a supply-chain threat, and Chinese experts increasingly read American safety talk as strategy rather than conviction. One prominent scientist dismissed the "human-extinction narrative" as "Oppenheimer-style marketing," pointing to Anthropic declaring a model too dangerous to release while raising money at a trillion-dollar valuation. The suspicion is that calls to slow down are really an attempt to freeze China's lead in place.
What gives that suspicion teeth is that nobody is actually slowing down, including the people asking for it. Days after Anthropic's Dario Amodei urged the industry to pace the frontier, the company shipped a new flagship and framed it, in its own words, as a way of "remaining competitive with China." Beijing looks at that and sees its own logic confirmed. The uncomfortable takeaway is that the world now has two kinds of AI safety: the kind written into documents, which is flourishing, and the kind enforced before a model ships, which almost nobody practices. The gap between them is where the real risk lives.