Research suggests that ChatGPT, Claude and Gemini can sometimes reproduce patterns associated with Chinese censorship or state narratives, exposing a new vulnerability in the data and safety systems behind leading American artificial-intelligence models.

The global contest over artificial intelligence is increasingly being fought not only over chips, computing power and advanced algorithms, but over something far less visible: the information that AI systems absorb before they ever speak to a user.
New research and testing reported this week indicate that some of the most prominent American AI assistants — including OpenAI’s ChatGPT, Anthropic’s Claude and Google’s Gemini — can occasionally respond to politically sensitive questions in ways that resemble the caution, omissions or framing commonly associated with China’s tightly controlled information environment.
The findings do not suggest that American technology companies are deliberately implementing Chinese government censorship rules. Instead, researchers point to a more complicated combination of contaminated or politically shaped training data, multilingual differences and safety mechanisms that can produce unintended effects.
In some tests highlighted by The Wall Street Journal, Western models were reportedly more reluctant to produce certain critical or insulting material about authoritarian leaders, including Chinese President Xi Jinping, than about politicians or public figures in democratic countries. Researchers examining these differences argue that the pattern can sometimes resemble the behavior of chatbots operating under much more restrictive political systems.
One particularly important factor is language.
Large language models learn statistical relationships from enormous quantities of text gathered from books, websites, news organizations, social networks and other digital sources. But the information available online is not politically neutral. In China, extensive censorship, state media dominance and pressure on publishers influence what is available in Chinese-language information environments.
When those materials become part of an AI model’s training corpus, the political structure that produced them can leave a statistical imprint on the model itself.
Research published in Scientific Reports, part of the Nature portfolio, found significant differences when GPT models were asked comparable political questions in English and simplified Chinese. Chinese-language responses were less negative about problems associated with China than English-language answers, suggesting that the language environment itself can influence political framing.
More recent research has strengthened concerns about what academics describe as institutional influence on training data. Researchers studying state-coordinated media found evidence that governments can indirectly shape AI outputs by influencing the information ecosystems from which models learn. The effect appears particularly important when models respond in the language of the country generating that content.
China provides perhaps the clearest example because its domestic information space is heavily regulated while state-controlled outlets such as Xinhua produce enormous quantities of material that are widely distributed online.
If such sources are disproportionately represented in Chinese-language training material, a Western AI model does not need to be explicitly instructed to promote Beijing’s position. It may simply learn that certain formulations, political assumptions and descriptions appear statistically more frequently than competing interpretations.
That distinction is critical.
This is less conventional censorship than a form of information inheritance.
A chatbot can reproduce elements of a censored environment without itself being connected to the censorship apparatus that created them.
The issue becomes still more complicated when safety systems are added.
Companies such as OpenAI, Anthropic and Google apply additional layers of post-training and moderation intended to stop their models from generating harassment, threats, dangerous instructions or other harmful content. Those safeguards can interact unpredictably with political questions, particularly when a prompt asks a model to insult, attack or produce provocative material about an identifiable individual.
According to the Journal’s testing, those systems sometimes produced uneven results depending on the political leader involved, creating the appearance that some authoritarian figures were receiving greater protection from criticism than democratic ones.
That does not necessarily mean the model has adopted an authoritarian political ideology. It can instead reflect overlapping moderation rules, differences in available training material and uncertainty about how politically sensitive requests should be handled.
The problem is nevertheless significant because users rarely see those underlying mechanisms. They simply receive an answer.
Anthropic has itself acknowledged related concerns. In the system card for Claude Opus 4.7, the company reported observing a small number of evaluations in which the model aligned with official Chinese positions on politically sensitive China-related issues.
At the same time, the phenomenon should not be exaggerated into the claim that American AI systems systematically reproduce Beijing’s worldview. Research comparing Chinese and American models continues to show major differences.
A 2026 study examining political censorship across models found substantially higher censorship levels among systems developed in China than among those developed elsewhere.
Earlier comparisons have reached similar conclusions. Chinese systems such as DeepSeek have frequently refused to address topics including the Tiananmen Square crackdown or have repeated official Chinese positions on Taiwan, while ChatGPT has generally been willing to discuss competing historical and political interpretations.
Another 2026 study comparing geopolitical responses found that GPT-4o exhibited comparatively subtle Western framing biases, whereas DeepSeek displayed substantially more explicit nationalist positions aligned with Chinese government narratives.
The concern, therefore, is not that Western AI has suddenly become equivalent to Chinese AI.
It is that even models developed in open societies can absorb the consequences of closed information systems.
That possibility has implications extending far beyond China.
Governments around the world increasingly recognize that influencing information online may ultimately influence artificial intelligence. Unlike traditional propaganda, content designed to affect future AI systems does not necessarily need to persuade millions of human readers directly. If it becomes sufficiently widespread and authoritative-looking, it may eventually enter datasets used to train or retrieve information for AI assistants.
Researchers have warned that this could create incentives for governments to flood the internet with coordinated narratives in the hope of shaping future models.
China already operates one of the world’s most extensive international state-media networks and has increasingly incorporated AI-generated material, social media and digitally tailored content into its global communications strategy.
The emerging risk is therefore structural. AI companies cannot simply assume that information found on the open internet represents an independent collection of human knowledge.
Some of it is advertising. Some is disinformation. Some is propaganda. And some exists within environments where competing accounts have already been removed.
This places greater pressure on developers to understand where their models’ information originates, particularly in languages where independent journalism and uncensored reference material may be less plentiful.
Greater transparency around training sources, stronger multilingual evaluation and more systematic testing for politically asymmetric behavior are among the measures researchers have proposed.
AI companies are already confronting the broader geopolitical dimensions of the problem. OpenAI said in June that it had disrupted accounts likely originating in China that were using ChatGPT as part of apparent covert influence operations targeting debates about American AI and technology policy.
Anthropic, meanwhile, reported earlier this year that Chinese AI developers had apparently attempted to use Claude outputs to help train models capable of navigating politically sensitive questions while complying with censorship requirements.
Together, these developments reveal an increasingly circular information ecosystem: governments influence online information; online information influences AI; AI generates new information; and that material can then be used to train another generation of models.
For users, the lesson is uncomfortable but increasingly important.
Artificial intelligence does not learn from an abstract, neutral version of reality. It learns from the world’s existing information systems — including their omissions, prejudices, political pressures and propaganda.
The latest findings suggest that China’s censorship regime may therefore have consequences far beyond the country’s borders. Even when Beijing has no direct control over an American chatbot, the information environment it has spent decades constructing can still leave traces in the answers that chatbot produces.
In the age of generative AI, controlling what appears on the internet may ultimately influence not only what people read today, but what machines around the world will believe is normal to say tomorrow.




