Sweden's Arbetsförmedlingen and Försäkringskassan piloted Alibaba's Qwen 3 model on internal servers; Arbetsförmedlingen halted it over security concerns after Säpo named China a top threat, while Försäkringskassan kept it test-only before switching to a US model.
Details
Maturity
Discontinued
Promoter
Arbetsförmedlingen (Swedish Public Employment Service)
Period
Piloted internally in 2025; publicly reported December 2025 – March 2026; halted by Arbetsförmedlingen before wide deployment
Region (NUTS)
SE11
Keywords
public employment services, AI security, sovereign AI, e-government
Context
In 2025, Sweden's Arbetsförmedlingen (Public Employment Service) and Försäkringskassan (Social Insurance Agency) separately trialled Qwen 3, a large language model built by Chinese e-commerce group Alibaba, installed on powerful internal servers as agencies raced to adopt generative AI internally.
Objectives
Both agencies were evaluating a capable, low-cost large language model for internal government use.
Activities
Arbetsförmedlingen halted the tool without publicly disclosing its full reasoning; an Aftonbladet investigation (published December 2025) found staff had raised concerns about a Chinese-made model running on government infrastructure. Försäkringskassan's IT director Johan Gabrielsson said the agency only ran Qwen 3 'in our own test environments, within secure internal networks,' never in production, before switching to an American model.
Results
Former Defence Minister Peter Hultqvist criticised the choice, noting that Sweden's security service Säpo names Russia, Iran and China as the country's top security threats; AI-security expert Dan Bergh Johnsson pointed out that Qwen 3 refuses to answer questions about Chinese human-rights abuses and Tiananmen Square, a bias risk for government use.
Conclusions
No formal post-incident review or cost/impact figures have been published; this is a documented, multi-sourced cautionary case about AI vendor and model risk in government IT, not an evaluated success story.
Implementation
Indicative cost
Low (< €50k)
Time to results
Short (< 1 year)
Staffing & skills
Arbetsförmedlingen internal IT/AI evaluation team, Försäkringskassan IT Director Johan Gabrielsson
Conditions for success
Confining novel or foreign-origin models to isolated internal test environments before any production use
Staff empowered to raise security concerns that can trigger a halt
Common failure modes
A Chinese-developed model run on government infrastructure raised undisclosed security concerns
The model exhibited politically sensitive content refusals (e.g. Tiananmen Square, human rights), a bias risk for government use
Neither agency published its full rationale; the facts emerged via investigative journalism rather than proactive disclosure
Commonly funded by
National / regional programmes
Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.
Do you run this practice?
Claim it —
verified implementers get a public contact pathway and can propose corrections.
Data sources
Where this practice's information was retrieved from, and when.