Chinese LLMs in the UK Technology Stack

Data Security and Dependency Risks

Daniel Li and Ryan Wu

14 July 2026

Global Digital Economy Conference 2025 in Beijing (Source: Xinhua)

This is written evidence submitted to the Business and Trade Committee of the UK Parliament.

I. Introduction

Chinese large language models (LLMs) are rapidly gaining in popularity due to their customisability, low cost, and increasingly competitive capabilities. Chinese models have overtaken their U.S. counterparts in cumulative downloads on Hugging Face, the primary global repository for open-source AI models. A partner at the U.S. venture capital firm a16z told The Economist in August 2025 that 80% of AI start-ups were building derivatives from Chinese open-source base models. Even Airbnb, a flagship consumer-tech platform, has reportedly chosen Alibaba’s Qwen models over ChatGPT for its customer service chatbot.

With the AI Opportunities Action Plan driving economy-wide AI adoption, Chinese AI models have likely entered the United Kingdom’s technology stack at scale. This submission examines the risks arising from the diffusion of Chinese AI in the UK economy. The first risk arises from UK users’ direct interaction with Chinese-hosted models or from vulnerabilities embedded within model weights, which have become more difficult to track as the AI supply chain has grown in complexity. The second risk that comes with Chinese model adoption is ecosystem-level standards lock-in. As Chinese model architectures embed in UK developer infrastructure, the cost of any future transition rises, binding the UK to a Chinese AI ecosystem from which diversification becomes progressively harder.

Critical gaps remain in the Government’s understanding of how prevalent Chinese AI models are in the UK, and how adequately existing governance frameworks extend to AI-related risks. To bridge these gaps, the Government should map the extent of Chinese AI adoption in domestic economic sectors, review existing data security policies to identify blind spots in addressing AI-related data risks, and guard against ecosystem-level standards entrenchment.

II. Data Security Risks of Chinese AI Model Adoption

UK-based users may access Chinese AI models in several ways, each with a distinct risk profile.

First, they could directly interact with a Chinese AI model hosted on a Chinese cloud by using the AI labs’ designated web or app interface, or making application programming interface (API) calls to the Chinese model. The data security risk is high: UK data transits Chinese jurisdiction and falls under China’s National Intelligence Law, which compels all organisations and individuals to “support, assist, and cooperate with state intelligence work”. In July 2025, a Harmonic Security study of 14,000 US and UK-based enterprises found that approximately one in twelve employees had interacted with a Chinese-developed generative AI tool without authorisation, leading to 535 incidents of sensitive data exposure.

Alternatively, users may access Chinese models hosted on Western cloud infrastructure. For example, AWS, Azure, and Google Cloud provide serverless, managed access to DeepSeek and other Chinese models through their model catalogues. OpenRouter, a New York-based aggregator that routes API calls to the developer’s chosen model, is another widely used way of accessing LLMs. OpenRouter’s own data show that since early 2026, models from Chinese AI labs including MiniMax, Moonshot AI, Z.ai, Alibaba, and DeepSeek have accounted for a substantial share of total token usage on the platform.

Running inference on Western cloud infrastructure reduces the data exfiltration risk, since data no longer transit Chinese servers. However, those model weights processing UK data are still trained in China by actors legally compelled to cooperate with state intelligence work. In 2024, Anthropic researchers deliberately trained backdoors into models, demonstrating that such vulnerabilities – activating only under specific trigger conditions – can be embedded directly in model weights and persist regardless of where inference runs.

The same risk profile applies to self-hosting the original or derivative model. The inference infrastructure for self-hosted models carries its own vulnerability surface. In December 2025, cybersecurity researchers disclosed a critical remote code execution vulnerability in vLLM, the standard open-source inference engine for self-hosted LLMs. Before the vulnerability was patched, loading a poisoned model configuration file would prompt vLLM to execute attacker-controlled code silently on the host machine, bypassing the framework's own security settings. This vulnerability is not specific to Chinese models, but it illustrates that keeping data on-premise does not resolve the broader exposures embedded across the AI software supply chain.

The rising complexity of the AI supply chain, coupled with deteriorating documentation practices, compounds the opacity of model provenance. In February 2026, 70% of new fine-tuned models uploaded to that platform were built on Chinese base models. However, the 2025 Foundation Model Transparency Index recorded a decline in average transparency scores, with Chinese developers including Alibaba and DeepSeek ranked in the bottom half. Training data origins, licensing lineages, and post-deployment data handling represent the areas of greatest opacity. Third-party AI products further decrease visibility into AI provenance. In March 2026, Cursor, a third-party coding environment, was revealed to have used Kimi K2.5 as a base model for its Composer 2 system, drawing criticism that it had misled the public into believing its “frontier-level coding intelligence” was an original product.

China’s legal and political architecture systematically co-opts or coerces domestic AI labs into supporting security authorities. This applies to all Chinese AI developers — Moonshot AI, MiniMax, and DeepSeek alike — regardless of where their models are deployed or hosted. Where models developed within this context are embedded in products used by UK organisations, data handling and model behaviour could in principle be directed by Chinese state authorities, yet remain difficult to detect.

The emergence of agentic AI systems, in which models act as orchestrating components within multi-step workflows, amplifies these risks materially. An LLM-powered agent granted privileged access across the digital environment is susceptible to prompt injection attacks. Malicious instructions embedded in content the agent reads, such as an email or a document, can hijack its behaviour – a vulnerability found in OpenClaw, the AI agent framework which has surged in popularity since February 2026.

III. Standards Lock-in

A significant but underappreciated dimension of economic security is the entrenchment of foreign-origin technical and commercial standards within critical or high-leverage sectors. Standards lock-in refers to the process by which AI technical standards (interfaces, protocols, or operational norms) become so deeply embedded in a market or supply chain that switching becomes prohibitively costly. Firms and public bodies that have organised their operations around a given technology stack, cloud environment, industrial protocol, or model interface may find their practical freedom to diversify has contracted, regardless of their procurement intentions. 

The dependency is not imposed through ownership but accumulated through adoption. The rise of agentic AI systems compounds this lock-in risk, as the interfaces and behavioural conventions of dominant models propagate through every ecosystem that integrates them.

Moonshot AI and its Kimi model series illustrate how this process unfolds in the AI sector. Kimi models are distributed through open-source channels and designed to be compatible with widely used developer frameworks and API conventions. This compatibility substantially lowers barriers to adoption. Once integrated into development pipelines, as has happened in the case of Cursor, these models function as upstream dependencies that may not be visible to end users or their organisations. Adoption at that level creates structural exposure that is difficult to map and costly to reverse, precisely because it does not arise from a single procurement decision.

This risk is analogous to the concerns raised in the context of telecommunications infrastructure, electric vehicle charging standards, smart infrastructure platforms, industrial automation protocols, and enterprise software environments.  In each case, the concern is not only which firms supply components, but which firms are shaping the interfaces, data structures, and interoperability expectations that organise the market itself. The Huawei extraction stands as a cautionary precedent. It cost £2 billion and set the 5G rollout back by two to three years.

IV. Questions for the Committee

Many of these risks are still emerging, and the critical gaps lie not only in existing policy instruments, but more fundamentally, in how the Government monitors and understands them. This submission identifies areas of inquiry that may guide the Committee’s deliberations on the appropriate course of action:

1) What is the actual pattern of UK adoption of Chinese AI models, including the software components embedded throughout the AI supply chain?

The Committee should consider commissioning a sectoral audit of Chinese AI adoption across critical sectors, with priority coverage of financial services, healthcare, legal services, and the defence supply chain. The AI Security Institute would be well-positioned to lead this work, establishing the evidentiary baseline HMG requires to calibrate a proportionate response where exposure has already crossed the threshold of strategic significance.

2) Do existing policies adequately address the security risks arising from the UK’s accelerating adoption of Chinese AI models?

The United States’s Software Bill of Materials (SBOM) requirements and the European Union’s Cyber Resilience Act obligations, for example, are designed to increase transparency into the exploitable vulnerabilities present in software supply chains. The UK’s Cyber Security and Resilience Bill, introduced to Parliament in November 2025, should provide explicit guidance on how its digital security requirements apply to the AI supply chain. The Information Commissioner’s Office (ICO) should likewise issue formal guidance on whether the processing of UK personal data by Chinese models, whether via direct API or Western cloud intermediaries, complies with UK data protection legislation.

3) Do existing policies provide an adequate framework for identifying and managing data and economic security risks arising from structural dependency on Chinese-origin standards and platforms, as distinct from individual product or service decisions?

The Committee may wish to consider whether current UK economic security assessments adequately account for exposure to foreign-origin standards entrenchment. A forward-looking approach would extend to active support for interoperability requirements, diversified supply chains, and meaningful UK participation in the international and sector-specific standards bodies that govern this terrain.

Next
Next

Authoritarian Innovation