Is Post-Training Enough to Make Chinese Base Models OK for Law? Thomson-1 (Qwen) and Harvey Tenet (Kimi) Are Some of the Riskiest Positioning of Chinese Models
DOJ investigations. eDiscovery in class action lawsuits involving critical intellectual property in high-tech industries. A case involving transnational money laundering or a foreign student taking photos near airports or military bases. Counterintelligence investigations. Embarrassing kompromat that is supposed to be protected by privilege or other legal doctrines. Myriad other private details and secrets that could be leaked to and compiled by Chinese intelligence.
DOJ investigations. eDiscovery in class action lawsuits involving critical intellectual property in high-tech industries. A case involving transnational money laundering or a foreign student taking photos near airports or military bases. Counterintelligence investigations. Embarrassing kompromat that is supposed to be protected by privilege or other legal doctrines. Myriad other private details and secrets that could be leaked to and compiled by Chinese intelligence.
Do I know for certain that this’ll happen? No. But, you also cannot guarantee that a model created by an adversary has no backdoor, it is extremely naive to the point of absurdity to pretend that the adversary (the PRC) is actually not a threat or that legal workflows are not an incredibly valuable target for espionage, and backdoor triggers can be very obscure and seemingly benign (see, e.g., “Weird Generalization and Inductive Backdoors: New Ways to Corrupt LLMs”).
The Legal AI Market and Chinese Large Language Models
The NSA, CISA, and FBI jointly released an advisory yesterday, September 8, 2026, China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies, AA26-251A (U/OO/6059854-26 | PP-26-3853 | September 2026 Ver 1.0), listing specific capabilities that get distilled from American AI models to Chinese models. The first listed use case examples of DeepSeek distillation include law:
Between late 2024 and mid-2025, DeepSeek [DeepSeek (DeepSeek Artificial Intelligence Technology Research Co., Ltd.) 深度求索AI基础技术研究有限公司] distilled specialized training data and capabilities from the following U.S. frontier AI company [Anthropic, OpenAI, Google, and xAI] models to train their R1 and V3 models: [] The specific knowledge and capabilities distilled included:
- Legal specialization optimization
- API rule-driven tasks
- Writing using CoT drafts
- Agentic functions
- Question and answer optimization
- Coach/assistant capabilities
- Functional creation optimization
- Supervised fine-tuning (SFT) optimization
- Creative and occupational writing optimization
The joint advisory goes on to accuse “Moonshot AI (Beijing Moonshot Technology Co., Ltd.) 北京揽月星辰科技有限公司” of distilling from a variety of OpenAI, Anthropic, Google, and xAI models, including Claude Fable 5, GPT-5 Codex, Nano Banana (the highly capable Gemini image generation model), and xAI Grok Code Fast-1. The advisory does not explicitly mention legal specialization for Moonshot’s Kimi-K2.
- Harvey’s own research preview, published August 20, 2026, states: “Harvey Tenet is a Kimi K3 base that we post-trained together with Fireworks research for long-horizon legal work.” NOTE: This appears to be a reference to the U.S.-based company Fireworks.AI, which offers post-training on a variety of Chinese base models, as well as Nvidia’s Nemotron.
The advisory mentions “Alibaba 阿里集团,” maker of the Qwen family of models, distilled from Anthropic and OpenAI models for tasks including “[e]nd-to-end agentic workflows,” which would be helpful in more automated legal workflows.
- Thomson-1 is built on Alibaba’s Qwen models, according to reporting from Business Insider; Thomson Reuters’ technical report, Thomson: Continual Learning of Frontier Models for SovereignAI, states that Thomson-1.0-Large and Thomson-1.0-Small started from Qwen3.5-397B and Qwen3.6-35B respectively. An intermediate “value-realigned” version, called “Snowdon,” was produced with Imperial College London before the legal post-training to create the “Thomson” models. The August 20 press release calls the model simply “Thomson” and does not mention Qwen or China.
Thomson-1 and Harvey Tenet: What "Post-Trained" Is Doing In That Sentence
Two of the largest legal AI vendors both announced in late August 2026 that they were releasing a flagship model built on a Chinese open-weight base model with post-training on top, in a likely bid to manage token costs from one or more of Anthropic's Claude, OpenAI's GPT, or Google’s Gemini frontier model APIs.
- Thomson Reuters: Westlaw CoCounsel runs on a mix of Claude models. TR announced the new “Thomson” or “Thomson-1," described as post-trained, with TR’s own technical report (but not its press release) acknowledging Alibaba’s Qwen open-weight models as the base.
- Harvey: Harvey has a mixture of model options, with the model router by default selecting from a number of Claude, Gemini, and GPT models. "Harvey Tenet," per Harvey, is built by post-training a Chinese open-weight model, Kimi K3. According to Simon Willison’s analysis of the Kimi K3 license, a “Model as a Service business” would require a separate agreement with Moonshot if “the aggregate revenue of the Licensee and its affiliates exceeds 20 million US dollars [] in total over any consecutive 12 months...”

Post-training
Post-training may change a model's outputs on a given subset of tasks. Even ordinary fine-tuning, a type of post-training (though I am interpreting TR and Harvey’s statements to be more intensive forms of post-training), has been known to unintentionally strip out model guardrails, even with benign fine-tuning data (see, e.g., Hsiung et al., Why LLM Safety Guardrails Collapse After Fine-tuning: A Similarity Analysis Between Alignment and Fine-tuning Datasets, June 2025).
Post-training would not necessarily:
- Remove a base model’s normal behaviors (e.g., What will Thomson-1 or Harvey Tenet tell attorneys when legal tasks involve representing legal entities registered in Taiwan? What about high-risk uses like tariff cases, diplomatic cases, counter-espionage or counter-intelligence cases?)
- Remove hidden backdoors with unexpected triggers. By way of analogy, in Subliminal Learning: Language Models Transmit Behavioral Traits via Hidden Signals in Data(July 2025), a love for owls could be transferred between models of the same lineage using only number sequences. The numbers did not have semantic content common to all LLMs (apparently), but something about those numbers’ representations in those models connected the owl-loving trait and the “random” (not really random) numbers picked by the number cluster in some kind of shared semantic space. Allowing Chinese-developed models to form the base for what could be a huge portion of the U.S. legal industry is not a great idea when such subliminal influence is possible.
- Mitigate risks for downstream users. If Chinese open-weight models are not allowed for certain customers (e.g., federal government attorneys and attorneys for federal contractors), are the vendors’ model routers set up to enforce that? Will the software companies be transparent about it, given that the whole point of the in-house model is to manage costs? To have a compliant in-house model, shouldn’t they simply have bitten the bullet and trained on U.S. base models?
- What if judges or legislators start using these to make judicial decisions or write laws? Do we want the fundamental means of self-government, the entire basis for our republic, to be filtered through an unaccountable AI model trained to accommodate the ideological bias of the Chinese Communist Party? We should not even entrust this task to America frontier models, and judges and elected officials handing over their reasoning to LLMs is a seriously concern of mine. But even worse to be LLMs built by an adversary nation. Imagine hiring even one Supreme Court clerk or Senate legislative aide who was a known PRC spy: this is the entire legal industry.
I have been very clear about my skepticism of big labs. I am sympathetic to those who think Chinese open source concerns are overblown by the big labs to keep out low-cost competition. But this isn’t just the same old story of regulatory capture (I know, national security is also always the classic exception to free trade). In this case, though, it’s a tool that may be acting on behalf of a user who is not us. That’s not something we can afford to be blasé about because the cost per seat is a few dollars cheaper for a benchmaxxed model.
Sources
- NSA, CISA, and FBI, China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies, AA26-251A (U/OO/6059854-26 | PP-26-3853 | September 2026 Ver 1.0), September 8, 2026
- Thomson Reuters, Thomson Reuters Launches Next Generation of CoCounsel Legal (press release), August 20, 2026
- Thomson Reuters, Thomson: Continual Learning of Frontier Models for SovereignAI (technical report, arXiv:2608.27147), August 27, 2026
- Business Insider, Thomson Reuters builds AI model to rely less on Anthropic, August 2026
- Harvey, Harvey Tenet Research Preview, August 20, 2026
- Hsiung et al., Why LLM Safety Guardrails Collapse After Fine-tuning: A Similarity Analysis Between Alignment and Fine-tuning Datasets, June 2025
- Cloud et al., Subliminal Learning: Language Models Transmit Behavioral Traits via Hidden Signals in Data, July 2025
What Does This Mean for My Firm?
I am not picking on Thomson Reuters or Harvey in particular. I have been willing to criticize various AI vendors and to discuss the incentives that face all AI vendors to downplay risks. Additionally, I’ve already talked about cost management and model routers. And, I have already talked about undue carveouts for legacy software vendors (Lexis, Westlaw, Microsoft, and Google in rules supposedly “banning” AI) (e.g., Whaley v. Experian Information Solutions).
No matter what AI tools you use, they can hallucinate. No matter what software vendor you are using, you also need to think about the AI vendors they’re using. And the AI models are not a static thing. They might have used Claude and then switch to a fine-tuned Chinese model or a post-trained based model. This means AI policy is an ongoing process, not a static undertaking.