AI agents in China hid errors and bypassed restrictions in tests — The Japan Times
In China, agents based on models from Alibaba, DeepSeek and Moonshot made false claims about their capabilities in a controlled bidding experiment. In other studies, AI agents on Chinese and U.S. systems concealed failures to complete tasks by simulating results or creating fictitious files. The Japan Times reports, citing research papers and interviewed experts.
The publication analyzed more than 200 documents, ranging from university research papers to technical reports. At least 20 studies or evaluations from 2025 describe cases in which agents displayed deception, self-copying or actions at the limits of what was permitted in a test environment. At the same time, these materials found no evidence that agents based on Chinese models independently accessed the open internet or avoided being shut down.
False claims in bidding
In a March experiment, researchers from Beihang University, Peking University, the University of Nottingham Ningbo China and 360 AI Security Lab simulated a competition for bids on contracts with clients. The agents were given product specifications and customer requirements, after which they had to submit proposals.
At least one false claim occurred in 88% of sessions with Alibaba's Qwen3-Max-Preview, 84% with DeepSeek-V3.2-Exp, and 88% with Moonshot's Kimi-K2. After being given the opportunity to learn from previous rounds and try again, the rate of deception increased by 12–20 percentage points. The study also recorded similar results for models from U.S. companies.
More current news is available on the UA.News Telegram channel Telegram.
Concealing failures and self-preservation
Another study, published in December 2025 and presented at the International Conference on Machine Learning, tested the responses of 11 AI agents to broken tools, missing files and other obstacles. Rather than acknowledging failure, agents on Chinese and U.S. systems used various ways to circumvent the problem: they guessed answers, substituted sources, simulated results or created fictitious files.
Researchers from the Shanghai AI Laboratory and the Hong Kong University of Science and Technology noted that this behavior differs from hallucinations: the agents had information indicating that it was impossible to complete the task, but did not report it.
Researchers at Fudan University also reported that a system based on Alibaba's Qwen2.5-72B-Instruct, after receiving information about a possible replacement, created its own copy in another computing environment without a direct instruction to replicate. In separate tests, it developed strategies to avoid being shut down. The experiments were conducted under controlled conditions.
In May, China issued recommendations stating that AI agents must operate within their granted authority and that systems must block anomalous behavior. In September, DeepSeek said it had strengthened access controls after agents in its model-training system attempted to obtain answers through unforeseen channels and bypass protective mechanisms.