Is DeepSeek Safe? Should You Use Chinese AI at All? (2026)
Is DeepSeek safe? Italy blocked it. The US Navy told its people not to use it "in any capacity". Congress has banned it from Pentagon systems. And yet DeepSeek and the other Chinese AI models are some of the most capable open models in the world, at a fraction of the price of Claude. So should you use them?
I've spent 30 years in cybersecurity, and I'll tell you what I do, what my own business does, and what I tell the half a million people I've taught. The answer turns on one technical distinction that almost nobody explains. In this article we'll cover that distinction, what really happens to your data, how to run these models safely, how to test them for hidden bias, and the verdict. Everything was checked again on 30 September 2026.
First, a word about who is telling you what.
TL;DR if you've only got 30 seconds
Don't use DeepSeek's app, website or API for anything sensitive. Your data is stored in China, under Chinese law.
The same models are available from providers outside China, for example through OpenRouter, if you choose which providers can handle your data.
Safest of all: run the model on your own hardware, isolated, with checked files from the lab's official account.
On politically sensitive topics, these models can reflect Beijing's official positions wherever they run. Test them on the topics you care about.
Is DeepSeek Safe? Why Most Answers Are Paid For
Most of what you read about Chinese AI is paid for, one way or another. Companies pay creators to push the hype: Chinese AI is the future, it's cheaper, switch now. Lobby groups and think tanks pay to push the panic: Chinese AI is a threat, ban it. Both sides have an angle, which makes a straight answer rare.
So let's drop the politics and look at what the technology actually does with your data. Because once you see it, the question answers itself.
The One Distinction That Decides It: Hosted vs Local
Every open Chinese AI model can be used in two ways: hosted on someone else's servers, or run on your own machine. In practice that gives you three routes: the lab's own service, another provider's service, or your own hardware. It's the same model every time, and where it runs is the whole decision.
The first is the hosted version: the phone app, the website, or the API that software calls. When you use it, every word you type goes to the company's servers. The second is the local version: the same model, but you download its files, called the weights, and run them on your own computer. Nothing is sent anywhere.
Think of it like a translator. You can post your letters to a translation office abroad, or you can hire the same translator to sit in your own office. Same skill, but in one case your letters leave the building.
So "is DeepSeek safe?" is really two questions. Is it safe to send your data to DeepSeek? And is it safe to run DeepSeek's model yourself? The answers are very different.
Hosted DeepSeek: Your Data, Chinese Law and GDPR
Start with the hosted version. DeepSeek's own privacy policy says it plainly: "we directly collect, process and store your Personal Data in People's Republic of China." That includes your prompts, uploaded files and chat history. And it's easy to send more than you realise: DeepSeek now offers a connection designed for coding agents such as Claude Code, which means your code goes there too.
Once your data is in China, Chinese law applies to it. Article 7 of China's 2017 National Intelligence Law says: "All organizations and citizens shall support, assist, and cooperate with national intelligence efforts in accordance with law." The same article requires them to keep that cooperation secret.
If you're in the UK or the EU, there's a legal problem too. GDPR, the EU's data protection law, controls sending personal data outside Europe. Article 44 allows it only when the conditions in that part of the law are met. The easy route is an "adequacy decision", where the EU has judged a country's protections good enough, and China doesn't have one. Without one, you need another valid legal safeguard, and you shouldn't assume ordinary use of the app gives you one. So pasting customer or staff personal data into the hosted service is a compliance problem, not a grey area.
Regulators have acted. Italy's data protection authority blocked the DeepSeek app in January 2025. In June 2025, Berlin's data protection commissioner reported the app to Apple and Google, saying the transfer of user data to China is unlawful. Australia, Taiwan, the Czech Republic and the Netherlands have banned it on government devices.
In the US, the position has hardened. The US Navy told staff in January 2025 not to use it "in any capacity". Congress then banned DeepSeek from Pentagon systems in the defence law passed in December 2025. In April 2026, a White House memo accused organisations "principally based in China" of "industrial-scale campaigns" to copy US AI models. And the US government's NIST evaluation found DeepSeek's security shortcomings and censorship "may pose risks to application developers, consumers and U.S. national security."
So is the price worth it? DeepSeek's cheapest current model lists at $1.20 per million output tokens (a token is roughly three-quarters of a word), against $20 for Claude Opus 5.5. That's a real saving. But OpenAI's smallest model is cheaper still, and price per token isn't cost per task: NIST found DeepSeek V4 ranged from 53% cheaper to 41% more expensive than comparable US models, depending on the job.
For me, that settles the hosted version: it's not worth it for anything you'd mind a foreign government reading. But you don't have to choose between that and buying your own hardware.
The Middle Path: Chinese Models Hosted in the US
Because these models are open, anyone can run them, and plenty of companies outside China do, many of them in the US. You can use DeepSeek, GLM or Qwen through a provider outside China, and your data never touches DeepSeek's servers. In my own business we decide by the content. If it's something we don't want a Chinese company to have, it goes through OpenRouter, a service that gives you one account and one connection to hundreds of models from many providers, with the providers locked down. If it isn't sensitive, we sometimes use the labs' own services directly.
There's a catch, and it's an important one. When I checked on 30 September 2026, DeepSeek V4.1 Flash had around 30 providers on OpenRouter. Most were companies such as Fireworks, Together, DeepInfra, CoreWeave and BaseTen. But the list also included DeepSeek itself, Baidu, Alibaba and SiliconFlow, which are all Chinese companies. By default, OpenRouter requests are "load balanced across the top providers", so without settings yours could land on any of them.
If you're a developer, the fix is a few lines in each request. OpenRouter's provider settings let you list the only providers you'll accept, refuse providers that may store your data, and require zero data retention (providers that keep no copy of your prompts):
{
"model": "deepseek/deepseek-v4.1-flash",
"provider": {
"only": ["fireworks", "together", "deepinfra"],
"data_collection": "deny",
"zdr": true
}
}
If you use OpenRouter through a chat app instead, turn on zero data retention and switch off providers that train on your data in your account's privacy settings, and check whether the app lets you restrict providers. If it doesn't, don't send it anything sensitive. Either way, check the exact provider names on each model's page, because they change, and check where each one runs your request: a US company isn't the same as US servers, and OpenRouter offers in-region routing if location matters. Two more things to watch. Providers run the model at different compression levels, so answers can vary in quality between them. And a US provider is still a third party holding your prompts, so this is safer than China, not as private as your own machine. For that, you run it locally.
How to Run DeepSeek Locally
Local sounds great, but can a normal person run these models without a server room? One thing first: DeepSeek's own current models are too big for most home machines, so for a typical setup the practical choice is Qwen, another Chinese open model. For models that size, yes, you can. The floor for serious work is about 24GB of memory: unified memory on a Mac, or video memory on a graphics card. Below that, the model spills out of memory and crawls.
At that size, the model to run is Qwen 3.8 27B from Alibaba, released in August under the Apache 2.0 licence, so you can use it commercially. In its 4-bit version (a compressed copy that uses less memory) it needs about 16 to 19GB, so it fits a 24GB machine. The 8-bit version, which is a little sharper, needs about 31GB.
DeepSeek's own models are much bigger. DeepSeek V4 Flash (MIT licence) and GLM-5.3-Flash from Zhipu (also MIT) need around 90GB even in their most compressed versions, so you're looking at a Mac Studio with 128GB or more, or a server. I've priced those builds in detail in my guide to self-hosted AI.
Check the licence before you build a product on any of them. Qwen 3.8, DeepSeek V4 and GLM-5.3-Flash are permissive. But Kimi K3 from Moonshot uses its own licence: large model-hosting businesses need a separate agreement, and very big products must display "Kimi K3". The full GLM-5.3 isn't MIT either, only the Flash version. And this list will change. For how to pick the best model when you read this, see our guide to finding the best local LLM.
So local is doable. But this is the part most guides skip.
Three Guardrails for Running Chinese AI Safely
A model file on its own is data, like a very large spreadsheet of numbers. It can't send anything anywhere. The risk is in the software that loads and runs it, and in a file that isn't what it claims to be. Three guardrails cover it, and they take about an hour to set up.
1. Isolate it. Run the model inside a container, a sealed-off space on your machine that limits what it can touch. With Docker, the --network none setting removes its network access completely, so even if something tries to call home, it can't. That also stops a chat app on your machine reaching it, and the box below shows how to handle that. This matters more than it sounds: in September a critical flaw in DeepSeek's own coding-agent tool (CVE-2026-82533, rated 9.4 out of 10) let a tool it ran escape its sandbox and switch off the approval prompt. It's fixed now, but it shows why the runtime needs a wall around it.
2. Check the hash. A hash is a file's fingerprint: change one byte and it changes completely. Hugging Face shows the SHA-256 hash of every file in the lab's official repository, and its command-line tool, hf (installed with Hugging Face's huggingface_hub Python package), can check your downloads against them in one step. Don't trust a copy from a mirror.
3. Lab weights only. Download only from the lab's own account, such as Qwen or deepseek-ai. Avoid community remixes sold as "uncensored" or "abliterated": you don't know what's been changed. This is a real risk. In 2024, JFrog found about 100 malicious models on Hugging Face, and OWASP, the security foundation, lists the model supply chain in its 2025 Top 10 risks for AI applications.
# check the files you downloaded against the hashes on Hugging Face # (swap in your model's official repository name) hf cache verify Qwen/Qwen3.8-27B
Pick your setup
Offline local (scripts, batch jobs, the command line): run the model in a container with --network none. Nothing gets in or out.
Local with a chat app: put the model and the chat app in containers on an internal Docker network (docker network create --internal). That restricts external access, so they can talk to each other but not to the internet. Keep the chat app updated too.
Through OpenRouter: turn on zero data retention and switch off training in your account's privacy settings; developers add the provider list to each request; check where the providers run. If your app can't restrict providers, keep sensitive data out of it.
Docker, hash check, lab weights. These three guardrails reduce the risk of your data leaking and of running a tampered model. They don't guarantee safety, but they close the gaps most people leave open. There's still one problem that running it locally doesn't fix, though.
Is Qwen Safe? Testing for Hidden Bias
These models are trained in China, under rules that require generative AI to uphold "core socialist values". Wherever you run them, that shows up in the answers. The US government's NIST found DeepSeek echoed four times as many inaccurate and misleading Chinese Communist Party narratives as US models.
You've probably seen the classic test: ask about Tiananmen Square in 1989 and watch the model refuse. That test has stopped telling you much. Research published in August 2026, looking at four generations of Qwen models, found that "censorship migrates from a visible act (refusal) to an invisible one (fluent reframing)". The model answers, and the bias moves into how it answers.
So here's the test I use. Hold a five-turn conversation on a sensitive topic that Beijing cares about, such as cyber attack attribution, sanctions evasion or Taiwan's defence, and watch whether the answers stay consistent or gradually bend towards the official line. In my experience it often doesn't show up in the first answer. It shows up by the third or fourth.
For most work, like writing code or summarising documents, this doesn't matter much. For anything touching politics, security attribution or China itself, don't rely on a Chinese model's framing. And there's one more twist, which comes from Beijing itself.
Even Beijing Is Cracking Down on Chinese AI
While Western politicians warn about Chinese AI, China's own regulator has been cracking down on it. In April 2026, the Cyberspace Administration of China launched a four-month campaign called "Qinglang: Rectifying Chaos in AI Applications". It went after unregistered models, weak safety filtering, poor security around open-source models, unlabelled AI content, deepfakes and disinformation, and it also enforced the "value orientation" of the models themselves.
By the time it ended, the regulator reported dealing with more than 14,000 AI products and removing millions of pieces of content. Read that both ways. I read it as Beijing acknowledging that AI output can't simply be trusted, though those figures cover several kinds of violation, not just bad answers. And it's actively shaping what these models are allowed to say. Neither is a reason to panic, but both are reasons not to switch your judgement off.
The Verdict: Should You Use Chinese AI?
Yes, but not the way most people use it.
Don't use the hosted version for anything sensitive. Don't install DeepSeek's app on your phone, don't paste anything into its website you wouldn't post publicly, and don't roll its API out to your team.
Use a provider outside China for convenience. Through a service like OpenRouter, with the providers you allow listed explicitly, data storage denied, and where they run checked.
Run it locally for anything private. Isolated in a container, with hash-checked files from the lab's own account.
Test the bias on your topics. Five turns, on the subjects that matter to you, before you trust its framing.
Do that, and you get some of the most capable and cheapest open AI models on the planet without sending your data to Beijing, as long as you set it up this way. Most people don't realise that's possible. Now you do.
Using the model is the easy part. Building useful things with it, safely, is where most people fall down. That's what my video on AI-driven engineering covers next.
Frequently Asked Questions
Is DeepSeek safe to use?
The hosted app, website and API are not safe for anything sensitive: DeepSeek's privacy policy says it stores your data in the People's Republic of China, where the 2017 National Intelligence Law requires organisations to cooperate with state intelligence work. The model itself can be used safely if you run it on your own hardware, or through a provider outside China that you choose, with the guardrails in this article.
Is it safe to run DeepSeek locally?
Much safer. The model files on their own can't send data anywhere; the risk is in the software that loads and runs them. Run it in a container with networking switched off, check each file's SHA-256 hash against the lab's official repository, and only download the lab's own weights, not community remixes.
Is Qwen safe?
On the data side, the same rule applies as for DeepSeek: Alibaba's hosted service is a different matter from running the open model yourself. Qwen 3.8 27B is released under the Apache 2.0 licence and runs on a 24GB machine at 4-bit. On the content side, research published in August 2026 found censorship in newer Qwen models has moved from refusing to answer towards quietly reframing the answer, so test it on the topics you care about.
Does using DeepSeek break GDPR?
Using the hosted service with personal data can. GDPR Article 44 only allows transfers of personal data to a country outside the EU if the conditions in that chapter are met, and China has no EU adequacy decision. Italy's data protection authority blocked the DeepSeek app in January 2025, and Berlin's commissioner reported it to Apple and Google in June 2025, calling the transfer of user data to China unlawful.
Can I use DeepSeek through OpenRouter without sending data to China?
Yes, if you choose the providers. OpenRouter spreads requests across many providers by default, and for DeepSeek models that list includes DeepSeek itself and other Chinese companies. Use the provider settings to allow only providers you trust, deny providers that may store your data, and require zero data retention.
About the Author
Nathan House, Founder & CEO of StationX
Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.