China's frontier AI labs: who is building advanced AI?
DeepSeek, Moonshot AI, Zhipu AI, Alibaba's Qwen, ByteDance Seed and MiniMax: what China's leading AI developers say they are building, what independent testing shows, and what cannot be known.
In short: On the evidence of independent government evaluations and research groups, the Chinese organisations whose models independent evaluators have most often treated as among the most capable in 2026 are DeepSeek, Moonshot AI, Zhipu AI (Z.ai), Alibaba’s Qwen team and ByteDance’s Seed team, and, more tentatively, MiniMax. Most of them say, in their own published words, that they are working towards AGI, and Alibaba’s chief executive has spoken of artificial superintelligence. Several release their most capable models with downloadable “open weights”, which sets them apart from most leading American developers. Independent testing by the UK and US governments in 2026 found the most capable of these models a few months behind leading American models, including on cyber-attack tasks, and found their safeguards could often be bypassed. Much about them, including how much computing power they use and how they relate to the state, cannot be established from public information.
This page is part of our series on who is building superintelligence. It describes what each organisation says and has demonstrated. It does not treat company statements as evidence of Chinese government policy, or the reverse, and it is not a ranking.
Which organisations, and why
There is no official list of “frontier” laboratories. This page includes an organisation if independent evaluators or researchers have treated its models as among the most capable, or as a significant step for open-weight AI:
- DeepSeek: the US Center for AI Standards and Innovation (CAISI; NIST’s website now calls it the Center for Advancing Innovation and Standards for Super Intelligence) called DeepSeek V4 the most capable Chinese model it had evaluated, in May 2026.
- Moonshot AI: its Kimi K3 model was the subject of a joint preliminary assessment by the UK AI Security Institute and CAISI in July 2026.
- Zhipu AI (Z.ai): CAISI described its GLM-5.3 as the most cyber-capable open-weight model released to date, in September 2026.
- Alibaba (Qwen): Stanford’s AI Index 2026 found Alibaba produced the most notable Chinese models in 2025.
- ByteDance (Seed): a Seed model was the highest-ranked Chinese model on a widely used public comparison in March 2026, according to Stanford’s AI Index.
- MiniMax: included more tentatively. This site found no independent capability evaluation, but MiniMax has signed international safety commitments and releases large open-weight models.
Other companies, including Tencent, Baidu and StepFun, also build large models. This site found no independent 2026 evaluation placing them near the frontier, which may reflect a gap in published evaluations rather than in their capabilities.
What they say they are building
| Organisation | Its own description | Uses AGI or ASI language? |
|---|---|---|
| DeepSeek | “A Chinese company dedicated to making AGI a reality” (its Hugging Face page); “focused on building world-leading general artificial intelligence” (its website) | Yes, AGI |
| Moonshot AI | “Seeking the optimal conversion from energy to intelligence”; describes research “toward AGI” | Yes, AGI |
| Zhipu AI (Z.ai) | “Inspiring AGI to Benefit Humanity” (title of its About page); mission to “teach machines to think like humans, benefit humanity with reliable AI” | Yes, AGI |
| Alibaba (Qwen) | Qwen releases “LLM, LMM, and other AGI-related projects”; chief executive Eddie Wu has spoken of artificial superintelligence as Alibaba Cloud’s goal (reported) | Yes, AGI and ASI |
| ByteDance (Seed) | “Advancing the frontier of intelligence, in service of humanity”; “discovering new approaches to general intelligence” | “General intelligence”; no explicit “AGI” found |
| MiniMax | Aims to “co-create intelligence with everyone” and to achieve “Artificial General Intelligence (AGI)” | Yes, AGI |
As with American companies, these are statements of aim, not evidence of progress. The one Chinese use of “superintelligence” found by this site came from Alibaba’s chief executive. At Alibaba Cloud’s Apsara conference in September 2025 he described three stages of AI development ending in systems that improve themselves and surpass humans, according to the technology publication KrASIA; Alibaba’s own English-language write-up of the conference does not include those remarks. At the 2026 conference he was reported to have announced plans for a model of 5 to 10 trillion parameters, which he said was aimed at “advancing toward ASI”. Neither is a formal definition. Our explainer sets out the research meaning of superintelligence, and our AGI page the competing meanings of AGI.
Their systems
| Organisation | Flagship, 2026 | Weights |
|---|---|---|
| DeepSeek | DeepSeek-V4, released in preview on 24 April 2026; full release of V4-Pro on 13 August 2026 | Open, MIT licence |
| Moonshot AI | Kimi K3, released 16 July 2026 | Open from 27 July 2026, under a modified MIT-style licence that requires large “model-as-a-service” providers to sign a separate agreement and very large products to display the model’s name |
| Zhipu AI (Z.ai) | GLM-5.3, available through its service from 14 August 2026 | Open from about two weeks later, under a custom licence |
| Alibaba (Qwen) | Qwen3.8-Max, announced 3 August 2026 | Base weights (Qwen3.8-2.4T-A95B) released 12 August 2026 under a custom licence; the hosted Qwen3.8-Max adds features not in the download |
| ByteDance (Seed) | Seed 2.0 (February 2026), followed by Seed 2.1 (23 June 2026) | No open release of the flagship found |
| MiniMax | MiniMax-M3 (June 2026) | Open, under a community licence with conditions for large commercial users |
Open weights matter for two reasons. They let researchers, companies and governments anywhere run, study and adapt the models, which has made Chinese models widely used outside China. They also mean safeguards can be removed by whoever runs the model, and a release cannot be withdrawn. Several of the licences above add conditions for the largest commercial users, so “open” does not always mean unrestricted.
Independent evidence of capability
The most reliable evidence comes from government testing bodies and independent researchers, not company benchmarks:
- DeepSeek V4. CAISI found in May 2026 that it performed similarly to a leading American model released about eight months earlier. Its September 2025 evaluation of earlier DeepSeek models found they were more susceptible to jailbreaking than American models and more often repeated Chinese Communist Party narratives.
- Kimi K3. The UK AI Security Institute and CAISI found in July 2026 that it performed significantly below the most capable cyber models, but that its safeguards did not stop it attempting to develop cyber exploits. It completed a full 32-step simulated network attack once in ten attempts.
- GLM-5.3. CAISI found in September 2026 that its cyber capabilities were significantly lower than those of current American frontier models, lagging by about four months on its measures. Anthropic reported on 29 September 2026 that GLM-5.3 developed working end-to-end exploits in 50 of 410 attempts on ExploitBench, a test of exploiting known vulnerabilities in Chrome’s V8 engine, against 56 of 410 for Anthropic’s own Claude Mythos Preview, and that attackers could bypass its safeguards between 64% and 100% of the time in Anthropic’s simulated tests. Anthropic is a competitor, and these are its own tests.
- Overall. Epoch AI, analysing data to late 2025, found Chinese models had on average matched the capability of American models about seven months later. Stanford’s AI Index 2026, using a different, preference-based measure, found the gap had effectively closed. The two findings measure different things and should not be read as a single score.
Our page on recognising AGI explains why benchmark results do not settle questions of general capability.
Distillation
American developers and US government agencies have accused several Chinese laboratories of “distillation”: training their own models on large volumes of answers extracted from American models. In February 2026 Anthropic said it had detected campaigns that it attributed to DeepSeek, Moonshot and MiniMax, using about 24,000 fraudulent accounts that, it said, generated over 16 million exchanges with its Claude models. In September 2026 three US agencies, the NSA, CISA and FBI, issued a joint advisory accusing six Chinese companies (DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.ai) of distillation “at an industrial scale”. On 30 September 2026 OpenAI said it attributed a core cluster of a coordinated campaign in July 2026 to “individuals associated with Moonshot AI”, while saying it was unclear whether all those involved came from a single actor. This site found no on-record response from the companies named. China’s commerce ministry rejected the US government’s allegations, calling distillation a common practice and accusing the US of “politicizing and weaponizing” technology issues.
Chips and compute
Since October 2022 the United States has restricted exports of the most advanced AI chips, and the equipment to make them, to China, and tightened those rules in October 2023. A further rule restricting chips worldwide was rescinded in May 2025 before it took effect. From January 2026 sales of some high-end Nvidia and AMD chips to China were moved to case-by-case review, according to legal analysis of the rule; reported shipments have been small.
How much computing power Chinese laboratories actually use is largely unknown. The last clear primary figure is DeepSeek’s December 2024 technical report, which said its V3 model needed 2.788 million GPU hours on Nvidia H800 chips for its full training. DeepSeek’s 2026 report on V4 does not disclose the hardware or compute used. Some Chinese companies have said they use Huawei’s Ascend chips, mainly for running models; a July 2026 technical report described post-training DeepSeek’s V4 models on Huawei Ascend hardware, but which chips were used for the initial training has not been disclosed, and claims about which chips trained which model are mostly unconfirmed. Lack of disclosure is not unique to China: Stanford’s AI Index notes that training details are no longer published for several of the most resource-intensive systems anywhere.
Safety commitments and evaluation
Zhipu AI was among the original signatories of the Frontier AI Safety Commitments at the AI Seoul Summit in May 2024, and MiniMax signed later; signatories undertake to publish a framework for managing severe risks. In December 2024, according to the research organisation Concordia AI, 17 Chinese companies including DeepSeek, Zhipu, MiniMax and Alibaba signed voluntary safety commitments through a Chinese industry body. China’s government published a revised AI Safety Governance Framework in September 2025, which, according to analysts, refers to the risk of AI escaping human control; that is government policy, separate from what any company has committed to.
Practice is uneven. Concordia AI’s 2026 report on AI safety in China found that only five of ten leading Chinese developers had published safety evaluation results when releasing models in the past year, and none did so consistently. The independent tests above found safeguards on open-weight models could be removed or bypassed. These are general problems, discussed on our pages on risks and control.
What cannot be known from public information
- How much computing power the 2026 flagship models were trained with, and on which chips.
- What these organisations’ internal goals and research priorities are, beyond their published statements.
- How decisions about the most capable models are influenced by the Chinese state. Company statements are not evidence of government objectives, and government documents are not evidence of what a given company is doing.
- How company benchmark claims compare with independent results, except where government evaluators have tested a model.
The UK’s own position, which depends on access to American chips and hosts research offices of American laboratories, is covered in could the UK build AGI?
Sources
- US Center for AI Standards and Innovation (NIST), “CAISI Evaluation of DeepSeek V4 Pro”, 1 May 2026; evaluation of DeepSeek models, 30 September 2025, updated 20 November 2025; CAISSI home page, checked 3 October 2026.
- UK AI Security Institute, “UK AISI / CAISI Preliminary Assessment of Kimi K3’s Cyber Capabilities”, 23 July 2026.
- US Center for AI Standards and Innovation (NIST), assessment of Z.ai’s GLM-5.3 cyber capabilities, 17 September 2026.
- Anthropic, “GLM-5.3 and the spread of advanced cyber capabilities”, 29 September 2026: a competitor’s own testing.
- Stanford HAI, AI Index Report 2026, chapter 1 and chapter 2.
- Epoch AI, comparison of US and Chinese model capabilities, 2 January 2026.
- DeepSeek, Hugging Face organisation page and website, checked 3 October 2026; DeepSeek-V4 release, 24 April 2026; DeepSeek-V3 technical report, December 2024; Quartz, report of the V4-Pro launch, 13 August 2026, and Implicator, report on Ascend post-training: secondary.
- Moonshot AI, website, checked 3 October 2026; Kimi K3 licence.
- Zhipu AI, About and Hugging Face organisation page, checked 3 October 2026.
- Alibaba, Qwen Hugging Face organisation page; Alibaba Cloud, “Alibaba unveils Qwen3.8-Max”, 3 August 2026; Qwen3.8-2.4T-A95B model card.
- KrASIA (36Kr English), “Alibaba Cloud lays out vision for artificial superintelligence at Apsara Conference 2025”, 1 October 2025: secondary; Alizila, Alibaba’s write-up of the conference, 27 September 2025; Unite.AI, report of the 2026 conference, 22 September 2026: secondary.
- ByteDance Seed, website, checked 3 October 2026; Seed 2.1 announcement, 23 June 2026.
- MiniMax, website, checked 3 October 2026; MiniMax-M3 licence.
- Anthropic, “Detecting and preventing distillation attacks”, 23 February 2026.
- OpenAI, “Disrupting a coordinated model distillation campaign”, 30 September 2026; The Information, report of the commerce ministry’s response; The Register, report of the US agencies’ advisory, 9 September 2026; Global Times, report of the commerce ministry’s statement, September 2026: secondary.
- US Bureau of Industry and Security, press release on advanced computing rules, 17 October 2023; rescission of the AI diffusion rule, 13 May 2025; Baker McKenzie, analysis of the January 2026 licence-review rule: secondary.
- UK Government, Frontier AI Safety Commitments, AI Seoul Summit 2024, updated 7 February 2025.
- Concordia AI, State of AI Safety in China 2026, July 2026; AI Safety in China newsletter #19: the December 2024 commitments.
- Geopolitechs, report on China’s AI Safety Governance Framework 2.0, September 2025: secondary.
Common questions
- Which Chinese companies are building frontier AI?
- The Chinese organisations whose models independent evaluators have most often treated as among the most capable in 2026 are DeepSeek, Moonshot AI, Zhipu AI (Z.ai), Alibaba's Qwen team and ByteDance's Seed team, and, more tentatively, MiniMax. This is not a ranking.
- Do Chinese AI companies say they are building AGI?
- Most of them do, in their own published words. Alibaba's chief executive has also spoken of artificial superintelligence. These are statements of aim, not evidence of progress.
- Why does it matter that Chinese models have open weights?
- Open weights let anyone run, study and adapt a model, which has made Chinese models widely used outside China. They also mean safeguards can be removed by whoever runs the model, and a release cannot be withdrawn.