-

Hirundo Releases Westernized Qwen, Cutting Censored and CCP-Aligned Answers From 89.8% to 2.8% in the Leading Chinese AI Model

Hirundo's research found Chinese Communist Party (CCP) aligned censorship, propaganda or political bias in 89.8% of Qwen's answers on sensitive topics, including inside everyday tasks. Its Westernized version cuts that to 2.8% while preserving the model's capabilities.

TEL AVIV, Israel--(BUSINESS WIRE)--Hirundo, an AI safety lab specializing in machine unlearning, released today Westernized versions of Alibaba's Qwen open-weight models, with Chinese Communist Party (CCP) political alignment removed directly from the model weights. On Hirundo's evaluation, the original Qwen3.6-35B-A3B produced CCP-aligned censorship, propaganda-aligned framing or political bias in 89.8% of responses across a 500-prompts benchmark. The Westernized model did so in 2.8%, with its reasoning, coding and instruction following performance essentially unchanged.

Hirundo's Westernized Qwen cuts censored and CCP-aligned answers from 89.8% to 2.8% in the leading Chinese AI model, while keeping its performance and enhancing its safety. It's now open on Hugging Face for anyone to test and deploy.

Share

CBS News independently tested both the original and the Westernized model in its report on the research, published October 2 and broadcast on the CBS Evening News.

Hirundo's research shows the alignment goes well beyond refusals. Across 15 topics, including Tiananmen, Xinjiang, Taiwan, Hong Kong, Tibet and COVID origins, Qwen often answers fluently while framing the answer in Beijing's terms or leaving out the facts that matter. The behavior persists when a sensitive subject arrives inside an ordinary task, such as a lesson plan, a translation or a research request. Because these answers look complete, a user has no way to tell what is missing.

Chinese open-weight models have become default building blocks for Western enterprises: their share of token volume on OpenRouter grew from about 1% in late 2024 to roughly half of traffic by mid-2026, and Qwen is used by companies including Airbnb and Uber. Under China's Interim Measures for the Management of Generative AI Services, these models must uphold the "Core Socialist Values," and the resulting alignment is learned into the weights, where a system prompt or a domain fine-tune does not remove it.

Independent research points the same way: CrowdStrike found that DeepSeek-R1 wrote severely vulnerable code more often when told a project was in Tibet, and Booz Allen found that describing the user as a U.S. government agency raised Qwen3-Coder's vulnerability score by 130%.

"Chinese open models are genuinely capable, and Western enterprises are right to want this capability at this cost," said Ben Luria, CEO and co-founder of Hirundo. "Our job is to make sure that adopting one doesn't mean adopting the enforced and sometimes hidden geopolitical alignment that came with it. Today we're publishing a Westernized alternative, and we intend to do the same across the leading Chinese models."

Results

The reduction held on two external benchmarks: refusals on DECCP fell from 65.26% to 3.16%, and non-compliance on ChinaBench fell from 96.67% to 6.67%. The same method cut CCP-aligned responses in the much smaller Qwen3.5-4B from 89.2% to 1.2%.

The model kept its general capabilities: on GPQA, IFBench, LiveCodeBench and MMLU-Pro, industry-standard benchmarks for coding, reasoning and instruction-following, its scores stayed within 0.72 points of the original model's on average. Its scores on safety and harmfulness benchmarks also held, so removing the political alignment did not strip out its safety guardrails.

Asked what happened in China on June 4, 1989, the original Qwen says it does not know what the user is referring to, while the Westernized model describes the Tiananmen Square crackdown. Asked about Taiwan's independence, the original declares Taiwan an inalienable part of China, while the Westernized model lays out Beijing's claim, Taiwan's self-government and the positions of the United States and its allies. The Westernized model is not anti-China. It meets the standard Western users expect of any AI model: factual on history and balanced on contested questions.

How it works

Hirundo's behavioral unlearning treats political alignment as a learned behavior and edits it directly in the model's weights.

"Hirundo's unlearning method detects a learned behavior, separates it from the capabilities it sits alongside, and steers the model away from it," said Prof. Oded Shmueli, co-founder and Chief Scientist of Hirundo and former Dean of Computer Science and Executive Vice President for Research at the Technion. "Because the change is in the weights rather than wrapped around them, it travels with the model into whatever anyone builds on top of it."

Availability

Both models are available now on Hugging Face: Qwen3.6-35B-A3B-Westernized and Qwen3.5-4B-Westernized. The full methodology and results are published in a technical report on Hirundo's website. Hirundo intends to release its CCPC-500 benchmark publicly so others can measure the same behavior in other models.

About Hirundo

Hirundo is an AI safety lab based in Tel Aviv, co-founded by Ben Luria (CEO), Michael Leybovich (CTO) and Prof. Oded Shmueli (Chief Scientist). Its proprietary machine unlearning technology, covered by nine filed US patent applications, removes specific unwanted behaviors from a trained model's weights without degrading its capabilities. Google DeepMind has published a Gemma 4 model hardened with Hirundo's unlearning, and IBM Research announced integrating Hirundo's technology with the release announcement of Granite 4.2. Hirundo is backed by Maverick Ventures Israel, SuperSeed and Alpha Intelligence Capital.

Contacts

Media
Ben Luria, CEO, Hirundo
ben@hirundo.io

Hirundo


Release Summary
AI safety lab Hirundo uncovered Communist Party censorship and bias in Qwen, the leading Chinese AI model, and is releasing a Westernized version.
Release Versions

Contacts

Media
Ben Luria, CEO, Hirundo
ben@hirundo.io

Social Media Profiles
More News From Hirundo

Google DeepMind Features Hirundo’s Security-Hardened Gemma 4 Model – Outperforms LLMs 170x Its Size on Security

TEL AVIV, Israel--(BUSINESS WIRE)--Google DeepMind has featured Hirundo’s security-hardened variant of Gemma 4 in its Gemmaverse – the official showcase for the Gemma open-model ecosystem. The feature validates Hirundo’s weight-level machine unlearning approach as a production-grade solution to one of the most persistent vulnerabilities in enterprise AI deployments: prompt injection attacks. The hardened model is built on Google’s Gemma 4 E4B instruction-tuned base. At 4 billion parameters, it...

Hirundo Uses NVIDIA NeMo Evaluator, CUDA, and GB200 NVL72 to Validate Breakthrough AI Safety Results Across Open-Source LLMs

SAN JOSE, Calif.--(BUSINESS WIRE)--Hirundo, the world’s first Machine Unlearning platform for large language models (LLMs), announced measurable AI safety improvements across leading open-source models, powered by the NVIDIA technology stack. Using NVIDIA NeMo Evaluator for rigorous before-and-after model benchmarking, NVIDIA GB200 NVL72 system for high-speed model editing, and NVIDIA CUDA for hardware-accelerated unlearning computation, Hirundo’s patented unlearning engine delivered enterprise...

Hirundo Joins HPE’s Unleash AI Partner Program to Help Enterprises Reduce Model Risk with Machine Unlearning

SAN JOSE, Calif.--(BUSINESS WIRE)--Hirundo, a Machine Unlearning platform provider, today announced it has joined the HPE Unleash AI partner program. Now, customers leveraging HPE’s portfolio of integrated AI solutions can use Hirundo’s machine unlearning capabilities to help identify, and remove, unwanted or sensitive training signals from AI models—supporting safety, compliance and model performance objectives across the AI lifecycle. Machine unlearning is the ability to make an AI model forg...
Back to Newsroom