Loading the catalogue…
Loading the catalogue…
Tencent is a Shenzhen-based technology group publishing AI models under the Hunyuan brand. It is not CLOUD Act exposed, but as a PRC entity it is subject to China's 2017 National Intelligence Law, a state-access regime with no EU adequacy decision or judicial remedy for EU data subjects. A distinctive and serious risk for Stav's customers: several current Hunyuan open-weight models (video, image, 3D, motion) carry a custom licence that explicitly excludes the EU, UK, and South Korea from the permitted territory, meaning those specific models cannot legally be used in the EU under their own terms — though Tencent's July 2026 flagship text model (Hy3) switched to an unrestricted Apache 2.0 licence. Tencent also remains on the US Department of Defense's Chinese Military Company list as of the most recent 2026 update, adding geopolitical scrutiny on top of the jurisdictional and licensing risks.
Several current Hunyuan open-weight models (HunyuanVideo, Hunyuan-Large, Hunyuan3D-2, HunyuanImage, HunyuanWorld-Voyager, HY-Motion 1.0) are licensed under a 'Tencent Hunyuan Community License Agreement' whose defined Territory explicitly excludes the European Union, United Kingdom, and South Korea — meaning use of these specific models is not permitted in the EU under the licence's own terms, independent of any AI Act analysis.
Tencent is a PRC-domiciled entity subject to China's 2017 National Intelligence Law, obliging cooperation with state intelligence agencies on request, with no independent judicial oversight mechanism available to EU data subjects.
Tencent remains on the US DoD's Section 1260H 'Chinese Military Company' list as of the Pentagon's June 2026 list republication, despite disputing the designation. Not a sanctions instrument, but signals sustained elevated geopolitical scrutiny.
No EU AI Act compliance statement, GPAI Code of Practice signature, or EU-format training data summary has been identified for any Hunyuan model.
Tencent's corporate privacy policy explicitly states personal data is processed on PRC-based servers; EU SCCs cannot structurally remedy access risk under China's National Intelligence Law.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
Tencent's July 2026 flagship Hy3 model shifted from a restrictive, EU-excluding community licence to a standard Apache 2.0 licence with no territorial or field-of-use restriction, directly responding to community and (implicitly) regulatory feedback.
Tencent Cloud holds an extensive portfolio of international security certifications, including SOC 1/2/3, ISO 27001:2022, ISO 27017, ISO 27018, ISO 27701, ISO 22301, and CSA STAR Gold.
Tencent Cloud publishes a GDPR-oriented Data Processing and Security Agreement incorporating EU Standard Contractual Clauses for cross-border personal data transfers.
Tencent has appointed a designated Data Protection Officer reachable at dataprotection@tencent.com and states it conducts Privacy Impact Assessments across its products.
Tencent continues an active, high-cadence open-weight release schedule across text, image, video, and 3D modalities, with accompanying technical documentation and framework integrations.
Published safeguards & certifications