On October 8, 2026, SemiAnalysis reported that 31 of 857 Chinese AI model releases had a published safety-evaluation result tied to a specific model. Nine releases had a result available at or before launch. The census covers releases from nine developers between 2021 and September 15, 2026.
What SemiAnalysis counted
The census covers 857 releases from Alibaba, ByteDance, Tencent, Baidu, DeepSeek, Moonshot AI, Zhipu (Z.ai), MiniMax and StepFun. It includes 741 product models and 116 research models.
SemiAnalysis counted a safety result when a developer published a substantive finding tied to a named model. The subjects included harmful outputs, resistance to jailbreaks, toxicity, privacy, refusal behavior and dangerous capabilities. A general statement that a model had undergone safety training or evaluation did not meet that standard.
That threshold matters: the reported 31 releases, or 3.6% of the sample, had a qualifying public result. The nine with results available at or before launch represent 1.1% of all 857 releases.
When the 31 results appeared
The census divided the qualifying results into three groups by timing or how clearly a result matched a particular release.
| Reported timing or match | Releases | Details |
| Available at or before launch | 9 | A qualifying result was available by the release date. |
| Documented only after release | 16 | The median delay was 42 days; the longest reported delay was 349 days. |
| Timing or model match unclear | 6 | A result existed, but its timing or match to the specific release was unclear. |
The timing breakdown adds up to the 31 releases with qualifying results. For the other 826, SemiAnalysis classified 813 as having no public developer safety disclosure, 10 as having an evaluation claim without reported results or figures, and three as known only from press or investor accounts.
What a missing public disclosure means
The 813 figure describes public developer disclosures: SemiAnalysis says companies may have conducted private evaluations. A missing published result therefore does not establish whether a model was tested internally.
The census also did not treat a result for one model size or snapshot as applying to another. Release counts can vary with how developers distinguish versions, sizes and snapshots; SemiAnalysis cautions that its company-level totals are indicative rather than a definitive ranking.
China’s Framework 3.0 and safety disclosures
On September 14, 2026, the National Technical Committee 260 on Cybersecurity (TC260) released the AI Safety Governance Framework 3.0 under the guidance of the Cyberspace Administration of China (CAC). The CAC announcement marked the framework’s release.
The framework recommends regular safety testing and periodic disclosure of model-algorithm safety assessments, audits and responses to abnormal behavior. It also identifies risks such as unauthorized access to system permissions or external resources, bypassing safeguards, deceiving evaluators and concealing capabilities.
Those recommendations are distinct from a mandatory legal duty. SemiAnalysis characterizes China’s binding rules as not imposing frontier-model risk-assessment or publication requirements triggered by model capability.
What the census compares
The 3.6% figure applies to the Chinese releases in this census. It does not provide a China–U.S. disclosure-rate comparison: the releases counted are from nine Chinese developers, and the study’s company totals use differing levels of granularity.