evidoria

← Back to browse

Good practice Imported

Arbetsförmedlingen's Halted Pilot — Sweden's Public Employment Service Tests and Drops a Chinese AI Model Over Security Concerns

Sweden · Stockholm · See the Sweden profile · See the Stockholm profile

Evidence: Descriptive / self-reported Top 83% 40/100 · Ask Evidence Copilot about this practice

Sweden's Arbetsförmedlingen and Försäkringskassan piloted Alibaba's Qwen 3 model on internal servers; Arbetsförmedlingen halted it over security concerns after Säpo named China a top threat, while Försäkringskassan kept it test-only before switching to a US model.

Arbetsförmedlingen's Halted Pilot — Sweden's Public Employment Service Tests and Drops a Chinese AI Model Over Security Concerns

Details

Maturity
Discontinued
Promoter
Arbetsförmedlingen (Swedish Public Employment Service)
Period
Piloted internally in 2025; publicly reported December 2025 – March 2026; halted by Arbetsförmedlingen before wide deployment
Region (NUTS)
SE11
Keywords
public employment services, AI security, sovereign AI, e-government

Context

In 2025, Sweden's Arbetsförmedlingen (Public Employment Service) and Försäkringskassan (Social Insurance Agency) separately trialled Qwen 3, a large language model built by Chinese e-commerce group Alibaba, installed on powerful internal servers as agencies raced to adopt generative AI internally.

Objectives

Both agencies were evaluating a capable, low-cost large language model for internal government use.

Activities

Arbetsförmedlingen halted the tool without publicly disclosing its full reasoning; an Aftonbladet investigation (published December 2025) found staff had raised concerns about a Chinese-made model running on government infrastructure. Försäkringskassan's IT director Johan Gabrielsson said the agency only ran Qwen 3 'in our own test environments, within secure internal networks,' never in production, before switching to an American model.

Results

Former Defence Minister Peter Hultqvist criticised the choice, noting that Sweden's security service Säpo names Russia, Iran and China as the country's top security threats; AI-security expert Dan Bergh Johnsson pointed out that Qwen 3 refuses to answer questions about Chinese human-rights abuses and Tiananmen Square, a bias risk for government use.

Conclusions

No formal post-incident review or cost/impact figures have been published; this is a documented, multi-sourced cautionary case about AI vendor and model risk in government IT, not an evaluated success story.

Implementation

Indicative cost
Low (< €50k)
Time to results
Short (< 1 year)
Staffing & skills
Arbetsförmedlingen internal IT/AI evaluation team, Försäkringskassan IT Director Johan Gabrielsson

Conditions for success

  • Confining novel or foreign-origin models to isolated internal test environments before any production use
  • Staff empowered to raise security concerns that can trigger a halt

Common failure modes

  • A Chinese-developed model run on government infrastructure raised undisclosed security concerns
  • The model exhibited politically sensitive content refusals (e.g. Tiananmen Square, human rights), a bias risk for government use
  • Neither agency published its full rationale; the facts emerged via investigative journalism rather than proactive disclosure

Commonly funded by

National / regional programmes

Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful