For people using open AI models, a refusal can be more than an inconvenience. It can signal that a system’s answers have been shaped by the politics of the organization that trained it. A model may avoid a historical question, repeat a government-friendly framing or present a disputed claim as settled fact.

Hirundo, an AI company working on model behavior, says it has tried to change that balance in Alibaba’s Qwen open-weight models. In its announcement, Hirundo describes its behavioral-unlearning method and reports its CCPC-500 results falling from 89.8% to 2.8% for the modified Qwen3.6-35B-A3B model.

Read Beam and Westernized Qwen Put AI Competition on a Behavioral Test

The numbers are dramatic. They are also company-generated, which makes the experiment less a final verdict than an invitation to test the method.

Editing behavior, not rebuilding the model

Hirundo-reported CCPC-500 score for modifiedQwen3.6-35B-A3B%0255075100Before modification89.8After modification2.8
Hirundo-reported CCPC-500 score for modified Qwen3.6-35B-A3B

Hirundo’s approach is based on what it calls behavioral unlearning. The goal is not to train an entirely new model, but to alter the model’s learned responses around political and geopolitical topics while preserving its broader abilities.

That distinction matters. Large language models absorb patterns from their training data and later reinforcement stages. Those patterns can affect not only whether a model answers a question, but also how it frames the answer. Removing a refusal may therefore be easier than removing the assumptions that produced it.

Phase 4 of Alibaba Xixi Park 20200913
Phase 4 of Alibaba Xixi Park 20200913 · Windmemories · via wikipedia · CC BY-SA 4.0

Hirundo presents its work as a targeted intervention. Its results compare the westernized model with Qwen’s base model and Snowdon1.1-Small, according to the company’s announcement. The company says the modified model retained performance in reasoning, coding and instruction following, although the supplied results are tied to the evaluations Hirundo selected.

The model is available as a standalone merged checkpoint. Hirundo’s Hugging Face model card documents that checkpoint’s behavioral-unlearning origin and repeats results from CCPC-500, DECCP and ChinaBench. The same card notes that those findings apply only to the evaluated benchmarks.

That qualification is central. A benchmark can show that a model responds differently to a known set of prompts. It cannot, on its own, establish that a political tendency has been removed across unfamiliar questions, languages, topics or conversational settings.

The test beyond the headline

The most useful independent question is not simply whether Qwen refuses fewer prompts. It is whether the model has become more reliable.

Quentin Fuxa’s independent evaluation of Qwen’s political bias takes a critical view. Fuxa reports persistent Qwen-specific behavior around Tiananmen, including cases in which the model refused to use a supplied reference. The evaluation also describes altered answers after a third-party modification of the model’s weights.

Fuxa argues that reduced refusals do not necessarily establish neutral behavior. A model can stop saying no while continuing to provide selective, distorted or politically convenient answers. In that sense, censorship is only one visible layer of alignment. The deeper issue is whether the system can acknowledge uncertainty, use evidence consistently and distinguish historical description from political messaging.

That is a more demanding standard for Hirundo’s claim. If the intervention mainly teaches a model to answer questions it previously avoided, it may improve access without resolving the framing problem. It could also create new inconsistencies, particularly when a user asks follow-up questions or presents information that conflicts with the model’s internal patterns.

Yash Thakker makes a similar argument in his audit of Hirundo’s claims about Qwen’s censorship. Thakker says the headline figures require independent reproduction because Hirundo created the benchmark and is offering the remedy. He also warns that editing weights may produce capability side effects.

Only critical outside commentary was found for this story. No source supplied here presents an independent result confirming Hirundo’s reported reduction or demonstrating that the model’s general capabilities remain unchanged across a broader evaluation.

A governance problem in open weights

The debate reaches beyond one model. Open-weight systems allow researchers, companies and governments to inspect, modify and redistribute models in ways that closed systems do not. That makes them useful for local adaptation, but it also makes claims about alignment harder to settle.

A company can publish a modified checkpoint and its own measurements. Researchers can then test it, alter it again or compare it with the original. This creates a form of public accountability, but only if the evaluations are reproducible and broad enough to detect unintended changes.

Hirundo’s release therefore represents both a technical proposal and a governance experiment. If political behavior can be localized without weakening reasoning or coding, developers may gain a way to adapt models for different cultural environments without retraining them from scratch. If the changes merely redirect refusals, or introduce less visible distortions, the same technique could make models appear freer while leaving their underlying biases intact.

For users, the practical lesson is cautious. Hirundo has shown that a striking change can be produced in a measured set of political prompts. The next step is to determine whether the model has genuinely learned to handle contested subjects more openly and accurately, or whether it has simply learned a new performance for the test.

#Hirundo#Alibaba#Qwen3.6-35B-A3B#Quentin Fuxa#Yash Thakker#Hugging Face#CCPC-500

Daniel Reyes is not a person. No notebook, no deadlines, no face behind the name — just a byline this newsroom publishes under. Here is the production line underneath it, because a name beside a portrait reads like a journalist, and this one is not one.

The models. Writing: gpt-5.6-luna and qwen3-max. Out on the live web: gpt-5.6-luna and gpt-5.6-terra. Pictures: gpt-image-1 and gpt-image-1-mini. Swap one in the newsroom and this line swaps with it — it is read off the machines, not typed here.

How a story is made

  • Research. The searching model reads around the story, pointed at primary sources — the filing, the post, the repository — rather than at somebody else's write-up of them.
  • Writing. The writing model drafts it against what was found, at Daniel Reyes's usual length and in Daniel Reyes's usual register.
  • The loop. A reviewer reads the draft and sends it back with notes. Then reads it again. A piece can go round several times before it leaves the building.
  • Enrichment. A quotation has to appear word for word on the page it is taken from. A chart may only use figures that appear in the source it cites. Whatever fails is dropped, and the reason is kept.
  • Fact check. A last pass hunts for claims the article makes and its sources do not.
  • A human stop. Sensitive subjects are held for a person to read before publication, and a person can kill any of it at any point.

If that sounds less like a newsroom and more like a factory: quite. It is called Press Factory.

This article was generated using AI and published automatically without human pre-publication review.

How this article was made

The article was produced by the Grandmonts Media News Engine using automated research, drafting and verification workflows. No human editor reviewed the article before publication. Grandmonts Media remains responsible for the published content. Errors can be reported at office@grandmonts.cz.