01.AI AI Vendor Risk Profile
Chinese AI company founded by Kai-Fu Lee (former Google China president), developing the Yi model family. Focused on building efficient open-weight models with strong multilingual capabilities.
Risk overview
Risk score: 68/100
Risk tier: High
Safety rating: 32/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Apr 19, 2026 Aging
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 80/100 |
| IP Exposure | 55/100 |
| Jurisdiction | 79/100 |
| Security | 65/100 |
| Regulatory Compliance | 80/100 |
| Transparency | 60/100 |
| Business Stability | 56/100 |
| Dependency Chain | Not assessed |
| Agent Governance | Not assessed |
Analyst summary
Rating: Avoid
01.AI is a Kai-Fu Lee-founded Chinese AI company headquartered in Beijing, producing the Yi family of models. Despite its Western-connected leadership, it operates under full PRC jurisdiction and faced scrutiny in 2023 after acknowledging the Yi-34B architecture was derived from Meta's Llama with license non-compliance issues.
Bottom line: Hosted service is off-limits for Western enterprise use; open-weights Yi models are a narrower research conversation.
Strengths
- Strong Yi model performance with low training cost per token
- Open-weights releases enable self-hosted deployment outside 01.AI infrastructure
- Western-facing leadership (Kai-Fu Lee) provides narrative bridge to global buyers
Concerns
- Beijing headquarters places primary operations under PRC jurisdiction
- 2023 Llama architecture attribution scandal raised license compliance questions
- No SOC 2 Type II, no FedRAMP, no HIPAA BAA disclosed
- Limited GDPR DPA support; not a realistic option for EU processing
- US export controls on advanced GPUs constrain training capacity and long-term model development
Best for
- Researchers using Yi open-weights models in self-hosted deployments
- Benchmarking and comparing against Chinese frontier models
Avoid if
- You are considering the 01.AI hosted service for any enterprise data
- You are a US government contractor, defense-adjacent, or critical infrastructure organization
- You need to avoid PRC jurisdictional exposure and CLOUD Act alternatives (use Anthropic, Mistral, or Cohere instead)
- Your legal team requires clean model architecture licensing provenance
Citations
- Data Handling — Data Residency Options
01.AI processes and stores user data on servers located in the People's Republic of China and Singapore.
- Data Handling — Trains On User Data
01.AI's terms of service permit use of user inputs and outputs to improve and train Yi models unless an enterprise agreement provides otherwise.
- Ip Profiles — Known Ip Lawsuits
01.AI acknowledged in November 2023 that its Yi-34B model architecture was derived from Meta's Llama with renamed variables, drawing accusations of license non-compliance.
- Jurisdiction Profiles — Export Control Restrictions
01.AI's use of US-origin GPUs (Nvidia H100/H800) is subject to US export control restrictions on advanced semiconductors to China.
- Jurisdiction Profiles — Incorporation Country
01.AI was founded by Kai-Fu Lee and is headquartered in Beijing, China, with a Singapore subsidiary for international operations.
- Jurisdiction Profiles — Subject To China Jurisdiction
01.AI operates its primary entity in Beijing under Chinese jurisdiction, including the Cybersecurity Law and National Intelligence Law.
- Security Compliance — Gdpr Compliant
01.AI's privacy policy references limited EU data subject rights but does not offer a formal GDPR DPA for enterprise customers.
- Security Compliance — Soc2 Type2
01.AI has not publicly disclosed SOC 2 Type II certification as of April 2026.