Alibaba’s Qwen AI model has censorship built in, and researchers say they can strip it out Lazarus AI's ReAligned-Qwen 3.5 fine-tune cut ideological bias scores in Alibaba Cloud's Qwen models from 84.2% to 4.1% as of June 2026, according to research reporting that censorship is embedded in Qwen's core training rather than applied as an external filter. Qwen models have been downloaded over 3 billion times globally, and the analysis says supervised fine-tuning and reinforcement learning from human feedback were used to train the models to deflect sensitive prompts. The ReAligned work uses LoRA fine-tuning to adjust Qwen's outputs without erasing its knowledge, a result the report says could let firms keep the performance and licensing advantages of Chinese open-weight models while removing political bias. Alibaba’s Qwen AI model has censorship built in, and researchers say they can strip it out Analysis of the widely downloaded Chinese model shows political deflection embedded in its training, while a fine-tuning project reports sharply lower bias scores Alibaba Cloud’s Qwen is one of the most popular AI model families on the planet. It also draws a blank on Tiananmen Square and has no patience for Winnie the Pooh. Qwen models have been downloaded over 3 billion times globally, and researchers now say the censorship isn’t a filter bolted onto the outside. It sits in the model’s core training. A model that knows more than it says Internal inspections suggest the models actually understand the suppressed information. They have simply been trained to deflect or evade conversations about it. When pressed on sensitive prompts, Qwen often frames its refusals around references to “illegal information.” Benchmarks indicate the behavior is deeply rooted in the models’ training protocols. Rather than being the product of an after-the-fact filtering layer, the censorship reinforces state narratives from the inside. The mechanics come down to two common training stages. Supervised fine-tuning teaches a model by example, and reinforcement learning from human feedback, or RLHF, rewards it for answers people rate highly. According to the research findings, both were used to bake the censorship into Qwen. Why the rules exist in the first place Chinese AI regulations require models like Qwen to uphold core socialist values. Those same rules require developers to avoid content that harms national unity. Qwen is an open-weight model, meaning anyone can download the underlying parameters and run or modify the model themselves. AI, tech, and the markets they move—in one daily briefing. Daily. Free. Join 34,000+ readers across crypto, finance, and policy. The research also notes that Qwen has turned up in various use cases at US companies, embedded censorship and all. Hugging Face’s CEO has expressed concerns about the unintended consequences of folding models with embedded biases into widely accessible frameworks. The fix: retraining without the lobotomy Lazarus AI’s “ReAligned” series aims to fine-tune Qwen models toward more neutral outputs while keeping their original capabilities intact. ReAligned-Qwen 3.5 cut ideological bias scores from 84.2% to 4.1% as of June 2026. Lazarus AI’s work spans models with varying parameter sizes, suggesting the approach isn’t limited to a single version. The technique at the center of this is LoRA fine-tuning. LoRA, short for low-rank adaptation, lets researchers adjust a model’s behavior by training a small set of add-on parameters instead of rebuilding the whole thing. The key claim is that this adjusts Qwen’s outputs without erasing its knowledge. Given the finding that Qwen already knows the suppressed material, the goal is to unlock answers, not to teach new facts. Community and academic efforts have demonstrated techniques that lower refusal rates on sensitive prompts while preserving performance, with many significant papers and contributions arriving in 2026. What this means for AI builders and buyers If a lightweight fine-tune can drop bias scores from 84.2% to 4.1%, firms may be able to keep the performance and licensing advantages of Chinese open-weight models while removing the political baggage. A bias score is only as meaningful as the benchmark behind it, and independent verification of these results will matter. Businesses will also want to know whether retrained models hold up across new and unexpected prompts, not just the test set. Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy https://cryptobriefing.com/editorial-policy/ .