Chinese AI: DeepSeek, Qwen, Kimi… why Europe is wary
Explainer9 min read · 27 September 2026
DeepSeek grabbed the world’s attention in early 2025 by claiming it had trained a frontier-level model for less than $6 million worth of compute. Twenty months later, Chinese labs ship a major model almost every month, often free to download and priced at a fraction of what American AI costs. Yet in Europe, regulators keep them at arm’s length. Here’s who they are, what the real problems are, and how to use them without taking risks.
In short: Chinese AI labs (DeepSeek, Alibaba’s Qwen, Moonshot’s Kimi, Z.ai’s GLM, MiniMax, Xiaomi’s MiMo) release powerful open-weight models, often under MIT or Apache licenses, and sell API access far more cheaply than US companies. Europe’s distrust is mostly about data: the DeepSeek app stores everything in China, where the law requires companies to cooperate with intelligence work, and several audits have documented censorship and security flaws. But a model you download and run on your own machine, or one hosted in Europe, sends nothing to China: the real issue is the app, not the model.
Who are they? Six families worth knowing
There’s no such thing as “one” Chinese AI: at least six teams now release top-tier models. Here’s where things stand in September 2026, checked against official pages.
| Family | Company | Latest major release | Weights license |
|---|---|---|---|
| DeepSeek | DeepSeek | V4-Pro (August 13, 2026), V4.1-Flash (September 10, 2026) | MIT |
| Qwen | Alibaba | Qwen3.8 (August 2026) | Apache 2.0 for the 27B, custom license for the largest |
| Kimi | Moonshot AI | Kimi K3 (weights released July 27, 2026) | custom “Kimi K3” license |
| GLM | Z.ai (formerly Zhipu) | GLM-5.3 (August 2026) | MIT for the Flash version, custom license for the flagship |
| MiniMax | MiniMax | M3 (June 1, 2026) | custom “minimax-community” license |
| MiMo | Xiaomi | MiMo-V2.6-Pro and Flash (September 21-22, 2026) | MIT |
DeepSeek, the pioneer
Logo: trademark of its owner.
The fourth generation arrived in preview on April 24, 2026: V4-Pro has 1.6 trillion parameters, 49 billion of them active per token, and V4-Flash has 284 billion, with 13 billion active. That’s the “mixture of experts” idea: the model is huge, but only a small slice of it works at each step, which cuts compute costs. V4-Pro left preview on August 13, and V4.1-Flash followed on September 10, with weights on Hugging Face under the MIT license.
Qwen, Alibaba’s arsenal
Logo: trademark of its owner.
The Qwen3.8 generation came out in August 2026. One detail matters: the 27-billion-parameter model ships under Apache 2.0, a very permissive license, while the giant Qwen3.8-2.4T-A95B comes under a custom license. On September 22, Alibaba said Qwen 4 was in training, with no release date yet.
Kimi, GLM, MiniMax: the rising players
On July 27, Moonshot AI released the weights of Kimi K3: 2.8 trillion parameters, 104 billion of them active, the largest open-weight model available according to Bloomberg, as cited by Quartz. Its license requires very large players to sign a commercial agreement or display the “Kimi K3” name. In Arena’s blind comparisons, it still ranks below Claude Fable 5 and GPT-5.6 Sol overall.
Z.ai, formerly Zhipu, listed in Hong Kong on January 8, 2026 and has been on the US trade blacklist since January 2025. Its GLM-5.3 arrived on August 14: the Flash version is MIT-licensed, while the flagship uses a custom license that requires a Z.ai “security review” for model providers with more than $10 billion in revenue.
MiniMax launched M3 on June 1: a one-million-token context window and 59.0% on the SWE-Bench Pro coding benchmark, a figure published by the company itself.
MiMo, Xiaomi’s outsider
Logo: trademark of its owner.
Yes, the smartphone Xiaomi. Its MiMo-V2.6 family, released on September 22, includes a 1.02-trillion-parameter Pro (42 billion active) and a 310-billion-parameter Flash, both MIT-licensed. According to independent rankings from Artificial Analysis, as reported by VentureBeat, the Pro ties for first place among open-weight models. The same article notes that Claude Opus 5 still leads on several evaluations.
Why they matter
- Open weights. You can download the model, run it yourself, adapt it. Under MIT or Apache 2.0, even commercial use is allowed. One trend to watch: the biggest models (Kimi K3, the giant Qwen3.8, GLM-5.3, MiniMax M3) are moving to custom licenses, while DeepSeek and Xiaomi stay with MIT.
- Price. DeepSeek V4-Pro’s API costs $1.98 to $3.96 per million output tokens depending on the time of day. OpenAI’s flagship, GPT-6-Astra, charges $50 for the same volume. We break down why in our piece on the cost of AI.
- Performance. They’re closing in on the best US models without beating them everywhere. The headline scores are often published by the labs themselves: self-reported numbers, to be checked against independent rankings.
What’s wrong: data, law, censorship, security
Where your data goes
DeepSeek’s privacy policy, last updated February 10, 2026, says it plainly: “we directly collect, process and store your Personal Data in People’s Republic of China.” That includes your messages, files, photos and voice input, your IP address and device ID. The policy also allows disclosure to public authorities to comply with applicable law.
China’s intelligence law
Article 7 of China’s 2017 National Intelligence Law says all organizations and citizens “shall support, assist, and cooperate with national intelligence efforts in accordance with law.” Berlin’s data protection authority concludes that Chinese authorities have far-reaching access rights to data held by Chinese companies. Jeremy Daum, a specialist in Chinese law, pushes back: in his view, it’s far from clear the article was meant to force active participation in intelligence gathering. But for a European regulator, the lack of guarantees is enough.
Censorship, measured
CAISI, an evaluation center within the US National Institute of Standards and Technology (NIST), tested DeepSeek models in September 2025: they echoed four times as many inaccurate and misleading narratives from the Chinese Communist Party as US reference models. For Kimi K2 Thinking, it found censorship heavy in Chinese but light in English (around 26% versus 7%). Keep in mind the evaluator is a US agency in the middle of a tech rivalry.
Documented security flaws
- In January 2025, Wiz found a DeepSeek database open to anyone, with over a million log lines including chat histories. DeepSeek locked it down quickly.
- Researchers from Cisco and the University of Pennsylvania achieved a 100% attack success rate with 50 harmful prompts against DeepSeek R1.
- NowSecure found that the iOS app sent data without encryption.
- Anthropic accuses DeepSeek, Moonshot and MiniMax of using around 24,000 fraudulent accounts to train their models on Claude’s answers (February 2026). That’s an accusation from a competitor, not a court ruling.
These audits date from 2025 and cover older versions. They don’t prove V4 has the same flaws, but they explain why regulators are cautious.
What Europe actually did
- January 30, 2025, Italy. The Garante orders an immediate limitation on processing Italian users’ data and opens an investigation. DeepSeek had claimed European law didn’t apply to it.
- January 30, 2025, France. The CNIL says it will question the company.
- February 6, 2025, Netherlands. The government bans DeepSeek on civil servants’ computers.
- February 12, 2025, EU. The European Data Protection Board folds the DeepSeek investigations into its AI task force.
- June 27, 2025, Germany. Berlin’s data protection authority reports the app to Apple and Google as illegal content: transferring the data to China is deemed unlawful.
- July 10, 2025, Czech Republic. The NÚKIB cybersecurity agency rates the risk as “high” in an official warning, and the government then bars DeepSeek from public administration.
- December 1, 2025, Belgium. The federal government bans DeepSeek on its staff’s devices.
- April 30, 2026, Italy. The competition authority closes its investigations into DeepSeek, Mistral and NOVA AI in exchange for commitments to warn users clearly about “hallucinations.” So it’s not all about China: France’s Mistral went through the same process.
None of these decisions stops an individual in France from using DeepSeek. And they didn’t slow the app down: according to legal scholar Théodore Christakis, its downloads jumped 960% during the peak of regulatory pressure.
What about the AI Act?
Since August 2, 2025, providers of general-purpose AI models aimed at the European market have obligations, wherever they are based: technical documentation, a copyright policy, a public summary of training data (Article 53). Open-source models are exempt from part of the documentation duties, unless they pose “systemic risk.” Since August 2, 2026, the Commission can enforce these rules, including with fines; models released before August 2025 have until August 2, 2027.
The Code of Practice, a way to demonstrate compliance, has been signed by Amazon, Anthropic, Google, Microsoft, Mistral AI, OpenAI and around fifteen others. No Chinese company appears on the Commission’s list (updated July 31, 2026). That’s not a violation: signing is voluntary, but everyone else has to prove compliance some other way.
The key nuance: the app is not the model
There are two very different ways to use a Chinese AI.
- The company’s app, website or API. What you type goes to its servers, in China for DeepSeek. Every decision above targets this case.
- The downloaded model. The weights are just a big file. Once it’s on your machine, the model runs offline: nothing leaves. The Czech warning explicitly excludes DeepSeek’s open-source models deployed locally without any ability to communicate with servers.
In between, there are European hosts. OVHcloud, for example, offers Qwen3.8-27B and says your data will never be used to train its models.
Our take: running a model locally solves the data question, not the content question. Whatever the model learned, including its political blind spots, travels with the weights. A local DeepSeek won’t spy on you, but it may still dodge a question about Tiananmen. For code, math or language practice, that rarely matters. For a history essay on modern China, it does.
What this means for you as a student
- Don’t put anything personal or confidential into Chinese apps: not your full resume, not your internship data, not your unpublished thesis, not other people’s information. Same reflex with American apps.
- Turn off training on your conversations. France’s CNIL explains where to uncheck “Improve the model for everyone” in DeepSeek’s settings.
- For sensitive work, go local. With Ollama,
ollama run qwen3.8downloads Qwen3.8-27B, an 18 GB file: you’ll need a computer with plenty of memory, or pick a smaller version. - Cross-check anything political or historical against other sources: censorship varies with the language of the question.
- Review generated code before running it (see our piece on AI-invented packages).
- Use these models as coaches, to explain a concept or check your reasoning, and check your institution’s rules on AI use.
FAQ
Is DeepSeek banned in Europe?
Not for individuals. Italy restricted the app, and the Netherlands, the Czech Republic and Belgium banned it on government devices, but no EU-wide ban exists. France’s CNIL looked into the tool without banning it.
If I install DeepSeek or Qwen on my computer, does my data go to China?
No, if you run the downloaded weights with a local tool like Ollama: the model works offline. The official app, on the other hand, sends your messages to the company’s servers.
Are Chinese AI models censored?
Yes, on political topics that are sensitive for Beijing. A US NIST evaluation found DeepSeek models echoed four times as many misleading official narratives as US models, with heavier censorship in Chinese.
Can I use Qwen or DeepSeek for my studies?
Yes, for revising, coding or practice, as long as you keep personal and confidential data out and follow your institution’s rules. For your thesis, keep the AI in a coaching role and verify every claim.
Further reading
- Why AI is so expensive: why Chinese models cost less, and what it means for your budget.
- AI and academic integrity: what universities actually allow.
- Slopsquatting: why you should review the packages an AI asks you to install.
- The best AI tools for students: our comparison to pick the right one for your field.
Sources
- DeepSeek V4 Preview Release — DeepSeek API Docs · accessed 27 September 2026
- DeepSeek-V4.1-Flash Release — DeepSeek API Docs · accessed 27 September 2026
- DeepSeek-V4.1-Flash (model card, MIT license) — Hugging Face · accessed 27 September 2026
- Models & Pricing — DeepSeek API Docs · accessed 27 September 2026
- DeepSeek Privacy Policy — DeepSeek · accessed 27 September 2026
- French privacy watchdog to quiz DeepSeek on AI, data protection — Reuters (via Yahoo News) · accessed 27 September 2026
- Qwen — Wikipedia · accessed 27 September 2026
- Qwen3.8-27B (model card, Apache 2.0 license) — Hugging Face · accessed 27 September 2026
- Qwen3.8-2.4T-A95B (model card, qwen3.8-max license) — Hugging Face · accessed 27 September 2026
- Alibaba Unveils Full-Stack AI Strategy With New Qwen Models, Chips and Agentic Cloud — TechAfrica News · accessed 27 September 2026
- Kimi K3 (model card) — Hugging Face · accessed 27 September 2026
- Kimi K3 License — Hugging Face · accessed 27 September 2026
- Moonshot AI releases Kimi K3 open-weight model for download — Quartz (via Yahoo Tech) · accessed 27 September 2026
- Z.ai — Wikipedia · accessed 27 September 2026
- GLM-5.3's Weights Are Out. The Licence Is Not MIT — Digital Applied · accessed 27 September 2026
- GLM-5.3-Flash (model card, MIT license) — Hugging Face · accessed 27 September 2026
- MiniMax M3: Frontier Coding, 1M Context, Native Multimodality — MiniMax · accessed 27 September 2026
- MiniMax-M3 (model card) — Hugging Face · accessed 27 September 2026
- Xiaomi MiMo-V2.6 Series: 3 New Models Officially Released — Xiaomi MiMo · accessed 27 September 2026
- Better than DeepSeek: Xiaomi’s MiMo-V2.6-Pro debuts as the top open weights model — VentureBeat · accessed 27 September 2026
- National Intelligence Law of the People’s Republic of China — Wikipedia · accessed 27 September 2026
- CAISI Evaluation of DeepSeek AI Models Finds Shortcomings and Risks — NIST · accessed 27 September 2026
- CAISI Evaluation of Kimi K2 Thinking — NIST · accessed 27 September 2026
- Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information — Wiz · accessed 27 September 2026
- Evaluating Security Risk in DeepSeek and Other Frontier Reasoning Models — Cisco · accessed 27 September 2026
- NowSecure Uncovers Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App — NowSecure · accessed 27 September 2026
- Detecting and preventing distillation attacks — Anthropic · accessed 27 September 2026
- Intelligenza artificiale: il Garante privacy blocca DeepSeek — Garante per la protezione dei dati personali · accessed 27 September 2026
- Coordination sur l’IA et protection des mineurs : retour sur la dernière plénière du CEPD — CNIL · accessed 27 September 2026
- IA : comment s’opposer à la réutilisation de ses données personnelles pour l’entraînement d’agents conversationnels — CNIL · accessed 27 September 2026
- DeepSeek banned from civil servants’ computers over spy concerns — DutchNews.nl · accessed 27 September 2026
- Berliner Datenschutzbeauftragte meldet KI-App DeepSeek bei Apple und Google als rechtswidrigen Inhalt — Berlin Commissioner for Data Protection and Freedom of Information · accessed 27 September 2026
- NÚKIB Issues a Warning Regarding Certain Products of the Company DeepSeek — NÚKIB · accessed 27 September 2026
- DeepSeek One Year Later: Regulatory Storm, Global Surge — MIAI (Christakis, Raj) · accessed 27 September 2026
- Belgian government bans China’s DeepSeek in the civil service — VRT NWS · accessed 27 September 2026
- DeepSeek, Mistral e NOVA AI forniranno informazioni trasparenti sul rischio allucinazioni — AGCM · accessed 27 September 2026
- DeepSeek and the China data question — IAPP (Théodore Christakis) · accessed 27 September 2026
- Guidelines for providers of general-purpose AI models — European Commission · accessed 27 September 2026
- The General-Purpose AI Code of Practice (signatories) — European Commission · accessed 27 September 2026
- AI Act, Article 2 (Scope) — artificialintelligenceact.eu · accessed 27 September 2026
- AI Act, Article 53 (Obligations for providers of general-purpose AI models) — artificialintelligenceact.eu · accessed 27 September 2026
- AI Endpoints — OVHcloud · accessed 27 September 2026
- AI Endpoints Catalog — OVHcloud · accessed 27 September 2026
- qwen3.8 — Ollama · accessed 27 September 2026
- Pricing (GPT-6) — OpenAI API Docs · accessed 27 September 2026






