Zhipu AI AI Vendor Risk Profile
Chinese AI company spun out of Tsinghua University, developing the GLM (General Language Model) family. One of China's leading AI labs with strong academic research foundation.
Risk overview
Risk score: 67/100
Risk tier: High
Safety rating: 34/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Apr 19, 2026 Aging
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 80/100 |
| IP Exposure | 55/100 |
| Jurisdiction | 79/100 |
| Security | 65/100 |
| Regulatory Compliance | 80/100 |
| Transparency | 60/100 |
| Business Stability | 29/100 |
| Dependency Chain | Not assessed |
| Agent Governance | Not assessed |
Analyst summary
Rating: Avoid
Zhipu AI is a Beijing-based frontier AI company spun out of Tsinghua University, producing the GLM model family. It was added to the US BIS Entity List in January 2025, making it effectively off-limits for US government contractors, export-controlled industries, and any organization with US business ties.
Bottom line: Off-limits for most Western enterprises due to Entity List designation and PRC jurisdictional exposure.
Strengths
- Strong model capability (GLM-4, ChatGLM) with competitive benchmarks
- Open-source research contributions and academic credibility from Tsinghua origins
- Large domestic deployment base in China for mainland-only workloads
Concerns
- Added to US BIS Entity List in January 2025 (export control restrictions)
- Hosted services store data on PRC servers under Cybersecurity Law and National Intelligence Law
- No SOC 2 Type II, no FedRAMP, no HIPAA BAA disclosed
- No GDPR DPA available; not a realistic option for EU processing
- Chinese state-linked funding creates concentration of government influence
Best for
- Research and benchmarking against Chinese frontier models (read-only, non-sensitive)
- Workloads already operating entirely within mainland China
Avoid if
- You operate under US jurisdiction and are subject to BIS export controls
- You are a US government contractor, defense-adjacent, or critical infrastructure
- You process EU personal data or operate under GDPR enforcement
- You need to avoid PRC jurisdictional exposure and CLOUD Act alternatives (use Anthropic, Mistral, or Cohere instead)
Citations
- Data Handling — Data Residency Options
Zhipu AI stores and processes user data on servers located in the People's Republic of China.
- Data Handling — Trains On User Data
Zhipu AI's service agreement permits use of user inputs and outputs for model training and service improvement unless an enterprise agreement provides otherwise.
- Governance — Government Ties
Zhipu AI has received investment from Chinese state-linked funds and operates under China's National Intelligence Law requiring cooperation with state authorities.
- Jurisdiction Profiles — Export Control Restrictions
Zhipu AI is subject to US export control restrictions following its January 2025 addition to the BIS Entity List.
- Jurisdiction Profiles — Incorporation Country
Zhipu AI (Beijing Zhipu Huazhang Technology Co., Ltd.) is headquartered in Beijing, China, and was spun out of Tsinghua University's Knowledge Engineering Lab.
- Jurisdiction Profiles — Sanctions Risk
The US Bureau of Industry and Security added Zhipu AI and subsidiaries to the Entity List in January 2025, citing concerns about military-civil fusion and AI capabilities used against US interests.
- Security Compliance — Gdpr Compliant
Zhipu AI's privacy policy does not reference GDPR compliance or offer a Data Processing Addendum for EU customers.
- Security Compliance — Soc2 Type2
Zhipu AI has not publicly disclosed SOC 2 Type II certification as of April 2026.