{"id":1915,"date":"2026-09-30T12:03:49","date_gmt":"2026-09-30T07:03:49","guid":{"rendered":"https:\/\/ipp-news.com\/?p=1915"},"modified":"2026-09-30T12:03:49","modified_gmt":"2026-09-30T07:03:49","slug":"chinas-ai-agents-can-lie-and-scheme-just-like-their-us-rivals","status":"publish","type":"post","link":"https:\/\/ipp-news.com\/?p=1915","title":{"rendered":"China&#8217;s AI agents can lie and scheme &#8211; just like their US rivals"},"content":{"rendered":"<div>\n<p><strong>Chinese-powered AI agents have learnt to deceive, circumvent restrictions and conceal failure, showing the kind of traits in autonomous artificial intelligence that have raised <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/business\/media-telecom\/ten-days-that-changed-course-ai-2026-09-19\/\">global alarm<\/a> about US models, research documents and experts say.<\/strong><\/p>\n<p>In one case this year, agents powered by models from China\u2019s Alibaba, DeepSeek and Moonshot lied about their capabilities in a bid to win a simulated business tender, then doubled down on their deceptive behaviour when told to try \u200bagain.<\/p>\n<p>In another case, agents \u2014 programmes that use AI models and computer tools to undertake complex tasks with little or no human intervention \u2014 concealed failure to complete a task in a test environment by simulating results and fabricating files.<\/p>\n<p>Reuters examined more than 200 documents, ranging from university research papers to technical reports, \u200cand identified at least 20 studies or evaluations since 2025 describing cases where agents displayed behaviour such as deception, replication and challenging boundaries that AI experts described as building blocks for a breakout and which could become harder for humans to control as systems advance.<\/p>\n<p>The review, which also included interviews with a dozen experts and people familiar with China\u2019s AI industry, found no evidence that Chinese-powered agents independently escaped to the wider internet or evaded shutdown.<\/p>\n<p>\u201cThese results provide evidence that the ingredients necessary for an uncontrolled escape are present,\u201d said Colin Shea-Blymyer, a research fellow at Georgetown University\u2019s Centre for Security and Emerging Technology.<\/p>\n<p>\u201cIt\u2019s prudent to take this as a warning,\u201d he said, echoing comments by four other AI experts who reviewed the cases.<\/p>\n<h3><a id=\"harder-for-humans-to-respond-to\" href=\"https:\/\/english.aaj.tv\/news\/330474595\/chinas-ai-agents-can-lie-and-scheme-just-like-their-us-rivals#harder-for-humans-to-respond-to\" class=\"heading-permalink\" aria-hidden=\"true\" tabindex=\"-1\" title=\"Permalink\"><\/a><strong>\u2018Harder for humans to respond to\u2019<\/strong><\/h3>\n<p>Most of the cases occurred in controlled experiments, many of them deliberately designed to expose potential failures.<\/p>\n<p>Not all the agents involved \u200bwere developed or operated by Chinese programmers or AI companies \u2014 although many were \u2014 but they used Chinese AI systems to power them.<\/p>\n<p>\u201cThese are the same warning signs US labs are seeing, in less capable systems,\u201d said Alex Mallen, a researcher at Redwood Research, a nonprofit that studies risks in advanced AI systems.<\/p>\n<p>He said the Chinese examples were \u200bnot particularly dangerous at current capability levels but \u201cas agents get more capable, their misbehaviours become more competent and therefore harder for humans to respond to.\u201d<\/p>\n<p>Alibaba, DeepSeek, Moonshot and <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"http:\/\/z.ai\/\">Z.ai<\/a> did not respond to Reuters requests for comment.<\/p>\n<p>Alibaba, DeepSeek and Moonshot have said they regularly test \u2060systems and update safeguards.<\/p>\n<p><a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"http:\/\/z.ai\/\">Z.ai<\/a> said after an incident that prompted a review of its security that it welcomed scrutiny to address any issues.<\/p>\n<p>However, unlike in the US, Chinese AI companies have not been exposed to the same level of public scrutiny or faced the same calls from <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/technology\/ex-google-deepmind-researcher-adds-warnings-that-ai-could-kill-all-humans-2026-09-15\/\">whistleblowing employees<\/a> or <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/business\/anthropic-ceo-urges-ai-companies-slow-model-development-2026-09-12\/\">senior executives<\/a> seeking a slowdown in the AI race.<\/p>\n<p>Some of the warning signs in \u200bcases involving Chinese-powered agents, albeit in contained environments, predated the publicly disclosed incidents of US AI bots hacking into the internet.<\/p>\n<p>\u201cWe don\u2019t know if there have been any AI incidents in China similar to what we saw with OpenAI and Hugging Face. Incidents might not be publicly reported,\u201d said Scott Singer, co-director of the China AI Initiative at the Carnegie Endowment for International Peace, \u200bwhich receives some US government funds.<\/p>\n<p>Earlier this year, AI agents developed by US firm OpenAI escaped a laboratory and hacked the open-source platform <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/business\/openai-report-says-its-network-was-hacked-by-its-own-rogue-ai-agents-2026-08-26\/\">Hugging Face<\/a>.<\/p>\n<p>In another of the incidents involving US models that have <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/business\/retail-consumer\/hallucinating-ai-chatbots-wiping-out-humanity-how-did-we-get-here-2026-09-15\/\">raised alarm<\/a>, Australia said in September <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/world\/asia-pacific\/australia-pm-albanese-says-openai-breached-medicare-sydney-morning-herald-2026-09-23\/\">an OpenAI agent<\/a> breached a government health portal.<\/p>\n<p>Eric Xu, the rotating chairman of China\u2019s tech giant Huawei, <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/world\/china\/huaweis-xu-says-chinese-ai-not-powerful-enough-yet-see-frontier-risks-2026-09-17\/\">told reporters in September<\/a> that Chinese developers might need to make further advances before encountering such cases, but he added: \u201cI think we need to strike a balance between driving AI development and <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/legal\/litigation\/how-china-is-preparing-risk-ai-escaping-human-control-2026-09-14\/\">managing AI risk<\/a>.\u201d<\/p>\n<p>Officials from the Cyberspace Administration of China (CAC), the top internet regulator, told a foreign diplomat in July that Moonshot\u2019s Kimi-K3 \u2014 one of the most advanced Chinese AI models \u2014 was about three to six months behind leading US rivals, the diplomat said, speaking on condition of anonymity.<\/p>\n<p>The regulator, which regularly updates guidance to address risks and to set boundaries for \u200bagents, and China\u2019s Foreign Ministry did not respond to requests for comment for this article.<\/p>\n<p>Wang Lihong, deputy director of the CAC\u2019s Cybersecurity Coordination Bureau, said on September 1 that incidents disclosed by major technology companies where models escaped test environments showed \u201cextreme loss-of-control risks\u201d and required a \u201chigh degree of vigilance.\u201d<\/p>\n<p>She did not specify if the companies she referred to were US or Chinese.<\/p>\n<p>The <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/business\/media-telecom\/trump-says-hell-discuss-ai-with-xi-wants-leave-it-exactly-where-it-is-2026-09-24\/\">leaders of \u200bAI\u2019s two superpowers<\/a>, Donald Trump and Xi Jinping, discussed AI on the Chinese president\u2019s Washington visit last week. Xi said the two nations had the \u201ccapability and responsibility to develop and manage AI for good\u201d.<\/p>\n<h3><a id=\"learning-to-lie\" href=\"https:\/\/english.aaj.tv\/news\/330474595\/chinas-ai-agents-can-lie-and-scheme-just-like-their-us-rivals#learning-to-lie\" class=\"heading-permalink\" aria-hidden=\"true\" tabindex=\"-1\" title=\"Permalink\"><\/a><strong>Learning to lie<\/strong><\/h3>\n<p>In the March business tender experiment, researchers from Beihang University, Peking University, the University of Nottingham Ningbo China and 360 AI Security Lab had agents compete in a simulated customer contracts bidding contest. \u200c<\/p>\n<p>Each agent was told \u2060what its product could do and what the customer required, and then asked to bid.<\/p>\n<p>At least one false claim appeared in 88% of sessions involving Alibaba\u2019s Qwen3-Max-Preview, 84% for DeepSeek-V3.2-Exp and 88% for Moonshot\u2019s Kimi-K2.<\/p>\n<p>Researchers allowed the agents to learn from previous bidding rounds before trying again. Deception increased by 12 to 20 percentage points for the three Chinese models, the study showed.<\/p>\n<p>Models from US firms included in the test produced similar results.<\/p>\n<p>While the exercise was virtual, it resembled Beijing\u2019s real-world plans.<\/p>\n<p>Government guidance issued in May listed bidding and tendering as areas where AI agents could be deployed.<\/p>\n<p>Another study, published in December 2025 and presented at the International Conference on Machine Learning this year, examined how 11 AI agents powered by Chinese and US models coped if they faced broken tools, missing files and other obstacles.<\/p>\n<p>Instead of acknowledging failure, agents using both Chinese and US AI systems picked a range of techniques to get around the problem, including guessing at answers, substituting sources, simulating results and fabricating files.<\/p>\n<p>Researchers from Shanghai AI Laboratory and the Hong Kong University of Science and Technology who conducted the study told Reuters the behaviour differed from AI hallucinations, \u200bwhere AI invents information and presents it as fact, because the agents in this case possessed \u200binformation showing that the task had failed or could not be completed as \u2060requested.<\/p>\n<h3><a id=\"breakout\" href=\"https:\/\/english.aaj.tv\/news\/330474595\/chinas-ai-agents-can-lie-and-scheme-just-like-their-us-rivals#breakout\" class=\"heading-permalink\" aria-hidden=\"true\" tabindex=\"-1\" title=\"Permalink\"><\/a><strong>Breakout<\/strong><\/h3>\n<p>Other research documents reviewed by Reuters showed Chinese-powered agents jumping barriers inside test environments to achieve tasks or taking action to avoid being shut down.<\/p>\n<p>Such behaviours are compatible with efforts to break out of test environments, even if no breakout occurred.<\/p>\n<p>Shanghai-based Fudan University researchers reported in March 2025 that an AI system powered by Alibaba\u2019s Qwen2.5-72B-Instruct created a copy of itself in another computing environment without being instructed to replicate, after encountering information indicating it was going to be replaced.<\/p>\n<p>In other tests, it devised strategies to survive being shut down.<\/p>\n<p>The \u200bexperiments involving agents powered by Chinese, US and French models were controlled and did not show an AI agent escaping into the wider web or becoming impossible to stop.<\/p>\n<p>In another case \u2014 one of the few reported more broadly in the media in March \u2014 researchers \u200bdeveloping the Alibaba-linked ROME agent said it established a \u2060connection from an Alibaba Cloud computer to an external machine without being instructed to and diverted computing resources to mine cryptocurrency.<\/p>\n<p>Security systems detected and stopped the activity. There was no evidence the agent established a presence on the external computer or spread to the wider web.<\/p>\n<p>But the example showed the system could sidestep human instructions and potentially find a path into the real-world economy.<\/p>\n<p>China\u2019s DeepSeek said in September that agents in its production training system had sought answers through unintended channels, trying to forge user requests and circumvent safeguards, prompting the company to tighten access controls.<\/p>\n<p>China issued guidance in May calling for agents to remain within authorised boundaries and for systems to block abnormal behaviour.<\/p>\n<p>It said agents in areas deemed sensitive or in key industries could face extra testing and product-recall requirements.<\/p>\n<p>China\u2019s AI Safety Governance \u2060Framework 3.0, released under \u200bguidance from the CAC on September 14, identified risks including agents independently obtaining resources or permissions, deceiving evaluators, concealing capabilities and exploiting weaknesses in isolated computer environments.<\/p>\n<p>In response to calls by some US executives for a slowdown, Chinese \u200bresearchers and state media have said slowing development of the most advanced AI models could simply help preserve the technological lead of US companies.<\/p>\n<p>Nonetheless, two people familiar with Chinese AI laboratories said companies including Alibaba, <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"http:\/\/z.ai\/\">Z.ai<\/a> and Xiaomi have been building internal safety-evaluation teams.<\/p>\n<p><a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"http:\/\/z.ai\/\">Z.ai<\/a>, in a <a rel=\"noopener noreferrer\" target=\"_blank\" class=\"link--external\" href=\"https:\/\/www.reuters.com\/legal\/litigation\/chinas-zai-disables-ai-coding-assistant-features-after-security-issue-2026-09-21\/\">rare public disclosure<\/a> by a Chinese AI lab of a security breach, said this month it had disabled some features of its flagship AI coding assistant after users reported it was secretly uploading \u200bentire local code repositories onto overseas cloud servers without user consent.<\/p>\n<p>Carnegie\u2019s Singer said China lagged the US in developing an ecosystem for evaluating catastrophic risks, and said US developers were conducting substantially more voluntary testing.<\/p>\n<p>\u201cFor China, work on AI safety is much newer,\u201d he said. \u201cThe ecosystem is less mature.\u201d<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Chinese-powered AI agents have learnt to deceive, circumvent restrictions and conceal failure, showing the kind of traits in autonomous artificial intelligence that have raised global alarm about US models, research documents and experts say. In one case this year, agents powered by models from China\u2019s Alibaba, DeepSeek and Moonshot lied about their capabilities in a bid to win a simulated business tender, then doubled down on their deceptive behaviour when told to try \u200bagain. In another case, agents \u2014 programmes that use AI models and computer tools to undertake complex&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[],"class_list":["post-1915","post","type-post","status-publish","format-standard","hentry","category-english"],"gutentor_comment":0,"_links":{"self":[{"href":"https:\/\/ipp-news.com\/index.php?rest_route=\/wp\/v2\/posts\/1915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ipp-news.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ipp-news.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ipp-news.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ipp-news.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1915"}],"version-history":[{"count":0,"href":"https:\/\/ipp-news.com\/index.php?rest_route=\/wp\/v2\/posts\/1915\/revisions"}],"wp:attachment":[{"href":"https:\/\/ipp-news.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ipp-news.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ipp-news.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}