Chinese Open-Weight AI Models Expose Uneven Defenses, Supply-Chain Risks
Open-weight AI models give companies greater control over deployment and customization, but strong benchmark performance does not guarantee robust security. F5 researchers found wide differences among Chinese models in resisting prompt-injection and jailbreak attacks, underscoring the risk of selecting systems primarily for capability. The findings matter as enterprises increasingly download model weights and integrate them into applications that may handle sensitive data or access internal tools.
Recent testing covering models including Qwen3.5 and GLM-5.2 found that higher-performing systems did not necessarily provide stronger defenses. F5 also warned that model files distributed in the Pickle format can execute malicious code during deserialization, creating a software supply-chain threat. As of August 2026, the researchers advised companies to obtain models from trusted sources, favor Safetensors files and evaluate downloads in isolated environments before production deployment; no transaction value was associated with the research.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.