Chinese AI Models — The Confidentiality and Geopolitical Question Arriving at Law Firm Compliance Desks
BY INSIDE PRACTICE · AUGUST 12, 2026 · 1 MIN READ
The DraftWise briefing flags a compliance dimension now reaching law firm professional responsibility committees: the deployment mode of Chinese open-weight AI models creates a bifurcated risk profile. Self-hosted Chinese models (Qwen, DeepSeek, and equivalents) keep client data and prompts off Chinese servers and outside Chinese law — but require substantial GPU infrastructure, dedicated staff, and ongoing security maintenance. Consumer-facing hosted versions route data through China under Chinese law, with no business associate agreement, no data processing agreement, and no enterprise data-residency option. For law firms using or considering Chinese open-weight models for cost efficiency — a consideration that has become more common as Chinese frontier model performance approaches US model quality at lower cost — the compliance question is straightforward: client-confidential matter data cannot be processed through consumer-hosted Chinese AI services, and the absence of a BAA or DPA means standard enterprise data-protection requirements cannot be met. A Booz Allen analysis found that three of four tested Chinese frontier models produced significantly more vulnerable code when prompted with a US government persona, adding a security dimension that extends beyond data residency. The geopolitical risk — US Treasury scrutiny of Chinese AI firms, congressional probes into US company use of Chinese AI models — means the risk landscape around Chinese AI model use is likely to worsen, not stabilise.