Hirundo Releases Westernized Qwen to Strip Political Bias

Hirundo Releases Westernized Qwen to Strip Political Bias

The strategic integration of Chinese open-weight models into Western enterprise stacks is facing a significant technical hurdle: embedded geopolitical alignment. Hirundo, a Tel Aviv-based AI safety lab, has released "Westernized" versions of Alibaba’s Qwen models, specifically targeting the removal of Chinese Communist Party (CCP) aligned censorship and propaganda from the model weights. This development addresses a critical vulnerability for enterprises like Airbnb and Uber, which already utilize Qwen, by attempting to decouple high-performance reasoning from state-mandated political framing. By applying machine unlearning directly to the weights, Hirundo aims to provide a version of these models that adheres to Western standards of factual history and balanced discourse without sacrificing the underlying coding or instruction-following capabilities that make the original models attractive to global developers.

Reducing CCP-Aligned Responses in Qwen Models

Hirundo’s research identifies a deep-seated alignment issue within Alibaba’s Qwen architecture, where political bias is learned into the model weights rather than being a superficial layer. In a 500-prompt benchmark, the original Qwen3.6-35B-A3B produced CCP-aligned censorship, propaganda-aligned framing, or political bias in 89.8% of responses. The Westernized iteration successfully reduced this figure to 2.8%. This reduction is not merely limited to overt refusals; the company notes that the original model often provides fluent but biased answers on sensitive topics such as Xinjiang, Taiwan, and the origins of COVID-19, frequently omitting critical facts or framing events through Beijing's lens.

The technical approach utilizes proprietary machine unlearning to edit these behaviors directly within the model's weights. This method is designed to separate learned political behaviors from core capabilities like reasoning and coding. According to Hirundo, because the changes occur within the weights themselves, the neutralized behavior persists even when the model is integrated into new applications or fine-tuned for specific tasks. The effectiveness of this method was further validated on external benchmarks: refusals on DECCP dropped from 65.26% to 3.16%, while non-compliance on ChinaBench fell from 96.67% to 6.67%. The same unlearning process applied to the smaller Qwen3.5-4B model reduced CCP-aligned responses from 89.2% to 1.2%.

Mitigating Enterprise Risks in Open-Weight Adoption

The push to "Westernize" these models comes as Chinese open-weight models rapidly gain market share in Western digital infrastructure. Data from OpenRouter indicates that the share of token volume from Chinese models grew from approximately 1% in late 2024 to roughly half of all traffic by mid-2026. This trend presents a unique risk for enterprise IT leaders, as the alignment required by China's Interim Measures for the Management of Generative AI Services is baked into the models. This alignment can manifest in ways that compromise technical integrity; for instance, Booz Allen found that describing a user as a U.S. government agency increased Qwen3-Coder's vulnerability score by 130%, and CrowdStrike observed DeepSeek-R1 writing more vulnerable code when a project was associated with Tibet.

Hirundo's Westernized models, now available on Hugging Face as Qwen3.6-35B-A3B-Westernized and Qwen3.5-4B-Westernized, attempt to mitigate these risks while maintaining performance. On industry-standard benchmarks including GPQA, IFBench, LiveCodeBench, and MMLU-Pro, the Westernized models' scores remained within an average of 0.72 points of the original models. This suggests that the removal of political bias does not necessarily strip away the model's utility for complex reasoning or instruction following. Furthermore, the company claims that safety and harmfulness guardrails remained intact, ensuring that the removal of political alignment did not result in a less safe model for general enterprise deployment.

Key Takeaways

  • Hirundo’s Westernized Qwen3.6-35B-A3B reduced CCP-aligned censorship and propaganda from 89.8% to 2.8% in benchmark testing.
  • The machine unlearning process modifies model weights directly, ensuring the removal of political bias persists across different deployment scenarios.
  • Performance on coding and reasoning benchmarks, such as MMLU-Pro and LiveCodeBench, remained within 0.72 points of the original Alibaba models.

TechInsyte's Take

In our view, Hirundo is addressing a fundamental tension in the global AI supply chain: the conflict between the high performance of Chinese open-weight models and the geopolitical requirements of Western enterprise compliance. As Chinese models move from a niche 1% of OpenRouter traffic to potentially dominating half the market, the "hidden" alignment embedded in their weights represents a non-trivial risk to cybersecurity and corporate neutrality. Hirundo’s ability to maintain performance metrics—staying within 0.72 points of the original models—is the most critical aspect of this announcement. If enterprises can successfully decouple raw computational capability from state-mandated ideological framing, it may change the calculus for adopting high-efficiency, low-cost Chinese models. However, the long-term success of this approach depends on whether these "unlearned" weights can truly withstand the pressure of future fine-tuning or if the underlying alignment remains a latent risk.

Questions & Answers

How does Hirundo’s unlearning method differ from using a system prompt to control AI behavior?

Unlike a system prompt or a domain-specific fine-tune, which acts as a layer on top of a model, Hirundo’s method edits the model's weights directly. This means the removal of political bias is an intrinsic part of the model's architecture and will travel with the model even when it is integrated into new enterprise applications or further customized.

Does the removal of political bias degrade the model's technical performance for coding or reasoning?

According to Hirundo's testing, the performance impact is minimal. On industry-standard benchmarks such as GPQA, IFBench, LiveCodeBench, and MMLU-Pro, the Westernized models' scores stayed within an average of 0.72 points of the original Qwen models, suggesting that reasoning and instruction-following capabilities remain largely intact.

Why is the political alignment in Chinese models considered a risk for Western enterprises?

The alignment is a requirement of China's Interim Measures for the Management of Generative AI Services, which mandates that models uphold "Core Socialist Values." This alignment can lead to biased information delivery and, as noted by research from Booz Allen and CrowdStrike, can even impact technical outputs like code security when certain geographic or political contexts are introduced.

What specific topics showed the most significant bias in the original Qwen models?

The research highlighted significant bias across 15 topics, specifically naming Tiananmen, Xinjiang, Taiwan, Hong Kong, Tibet, and the origins of COVID-19. In these instances, the original models either refused to answer or provided answers that framed the issues according to Beijing's official positions.

Source: Hirundo

TechInsyte | Technology Intelligence technology intelligence workspace

About TechInsyte | Technology Intelligence

TechInsyte is a B2B technology news and intelligence platform covering major developments across AI, cloud, cybersecurity, enterprise software, semiconductors, startups, policy, and markets. We focus on the signals that matter for decision-makers.

The idea behind TechInsyte is simple. Technology moves fast, and professionals need clear information without unnecessary noise. New platforms emerge, security risks evolve, enterprise software changes, and the AI shift continues to reshape how companies operate. We help readers understand those developments in a practical and business-focused way.

Our coverage focuses on meaningful technology updates, product launches, enterprise strategy, funding activity, regulatory change, infrastructure trends, and the broader forces shaping the technology industry. The goal is to keep every article clear, relevant, and useful for professionals who need to know what happened, why it matters, and what it could mean next.

TechInsyte is built for readers who want sharper context, cleaner coverage, and a more focused view of technology without the clutter.