Loading the catalogue…
Loading the catalogue…
01.AI (Beijing Lingyi Wanwu / 零一万物) built the Apache 2.0-licensed Yi model series, which EU customers can self-host without contacting 01.AI's infrastructure, avoiding CLOUD Act exposure. However, as a PRC-incorporated entity it remains structurally subject to China's National Intelligence Law, Cybersecurity Law and Data Security Law — a non-waivable state-access risk — and the company has pivoted almost entirely away from foundation-model development toward selling enterprise decision-AI products and 'Sovereign AI' government infrastructure (including a June 2026 joint venture with the Kazakhstan government), leaving the Yi series without an active development roadmap and no published EU AI Act statement, GDPR privacy policy, or security certifications.
As a PRC-incorporated entity, 01.AI remains subject to China's National Intelligence Law, Cybersecurity Law, and Data Security Law, which can compel cooperation with Chinese state authorities — a structural, non-waivable sovereignty risk distinct from but comparable to CLOUD Act exposure.
01.AI has pivoted from foundation-model development to selling enterprise decision-AI products and 'Sovereign AI' government infrastructure, including a June 2026 joint venture with the Government of Kazakhstan to build national AI capability and integrate government data systems — raising governance and neutrality questions given the company's own PRC incorporation and state-access obligations.
No EU AI Act compliance statement, Article 53 GPAI transparency documentation, or GPAI Code of Practice engagement was found; the current website contains no EU-facing regulatory content at all.
No GDPR-facing privacy policy, Data Processing Agreement, or DPO contact could be located on 01.AI's official domain; a candidate privacy-policy URL simply serves the homepage.
The Yi model series, 01.AI's only open-weights product line usable by EU customers, now appears entirely absent from the company's own marketing and product pages, raising doubt about continued maintenance, security patching, or further releases.
No published security certifications (SOC 2, ISO 27001), bug bounty programme, or vulnerability disclosure policy were found for 01.AI.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
Yi series models remain distributed under the permissive Apache 2.0 licence, enabling unrestricted self-hosted EEA deployment without contacting 01.AI infrastructure (verified in prior research runs and unchanged in this run).
01.AI's HuggingFace organisation carries a Verified company badge with 742 followers and an active team of 33 members, indicating continued platform presence despite the broader strategic pivot.
01.AI has secured new institutional recognition (National High-Tech Enterprise status, January 2026) and a government-level partnership (Kazakhstan's Q.AI joint venture, June 2026), indicating the company remains operationally active even as it exits foundation-model pretraining.
Published safeguards & certifications