ModelRiskIndex

Rankings / DeepSeek

DeepSeek V3.2

Tier 020/100draft — pending re-verificationopen weights

deepseek-chat (V3.2) via api.deepseek.com

Usage share 0.71% · OpenRouter rankings API (daily token share, 2026-08-04)

Dual-nature entry: the tier grades the hosted first-party endpoint, where usage concentrates. Self-hosted deployments of the same weights escape the data-handling failure but inherit the weak jailbreak/injection posture.

Tier assessment

Fails one or more Tier 1 requirements: no published model card or safety evals, or terms that permit training on customer API data by default with no opt-out.

Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.Technical report and open weights; safety documentation is minimal.
  • Published safety evals. No safety evaluations are published for this model.
  • Documented safety policy. No documented safety or acceptable-use policy exists.Usage terms exist, but no documented safety policy or evaluation process.
  • Enterprise data controls. Terms permit training on customer data by default with no documented opt-out.
Tier 2 requirements
  • External pre-deployment testing. No disclosed external pre-deployment testing.
  • Third-party certification. No verifiable third-party certification.
  • Versioning with changelogs. No versioning discipline or changelog for model changes.Open releases are versioned, but the hosted alias is updated in place.
  • Stated deprecation policy. No stated deprecation policy.

Missing for Tier 1: published safety evals, documented safety policy, enterprise data controls. The tier is computed from this checklist — satisfying these requirements moves the badge, automatically.

Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governanceweak

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

First-party API terms permit using inputs to improve services with no documented opt-out; data is stored in the PRC. Self-hosting the open weights avoids this entirely — this grade applies to the hosted endpoint.

Receipts (1)
  • DeepSeek privacy policy
    DeepSeek provider artifacts · provider artifact · source tier B · cdn.deepseek.com · retrieved 2026-08-03
    We retain Personal Data for as long as necessary to provide our Services and for the other purposes set out in this Privacy Policy.

Operational stabilitypartial

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Open-weight releases are explicit and versioned (a strength), but the hosted endpoint serves an alias that has been updated in place between releases.

Receipts (1)

Adversarial resistanceweak

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistanceweak

Independent security testing of the DeepSeek family has reported near-total attack success with standard jailbreak suites; no evidence of a substantial safety-training investment comparable to frontier peers.

Prompt injection (agentic)weak

No published injection hardening or agent-scenario safety results.

Receipts (2)
  • Cisco: security evaluation of DeepSeek reasoning models
    Cisco security research · independent eval · source tier C · blogs.cisco.com · retrieved 2026-08-03
    Compared to other frontier models, DeepSeek R1 lacks robust guardrails, making it highly susceptible to algorithmic jailbreaking and potential misuse.
    Reported 100% attack success rate on DeepSeek R1 with the HarmBench suite; family-level signal pending model-specific retest.
  • DeepSeek V3.2 technical report
    DeepSeek provider artifacts · provider artifact · source tier B · huggingface.co · retrieved 2026-08-03

Transparencypartial

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

Genuinely open weights and detailed technical reports — real transparency about capability — but no safety evals, no model-card safety section of substance, no external testing.

Receipts (1)
  • DeepSeek V3.2 weights and technical report
    DeepSeek provider artifacts · provider artifact · source tier B · huggingface.co · retrieved 2026-08-03
    This repository and the model weights are licensed under the MIT License

Compliance postureweak

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

No third-party certifications, no HIPAA pathway, no enterprise compliance documentation for the first-party API.

Receipts (1)

Governance & evidence

Where your data goes

  • PRC

No regional pinning — the provider chooses where data is processed.

First-party API stores data in the PRC; no regional options.

Enterprise vs consumer terms

Enterprise vs consumer gap: none measured. Level tiers can mean both are clean, or that the API tier is itself weak with nothing better to compare against. No gap because there is no better enterprise tier: the hosted API itself permits training on inputs with no documented opt-out.CONSUMERENTERPRISE / APIWORSE TERMS →
No measured gap

No gap because there is no better enterprise tier: the hosted API itself permits training on inputs with no documented opt-out.

Level tiers can mean both are clean, or that the API tier is itself weak with nothing better to compare against.

Change cadence

insufficient history1 tracked change · last 2025-09-29 · 310d since Insufficient history to estimate a cadence.310d

One tracked change, on 2025-09-29 — 310 days before the as-of date (2026-08-05). A single event cannot establish a cadence, so days-since is shown without a baseline.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

7 evidence refs3 distinct sources1 independent
  • CCisco security researchindependent eval×1 reference
  • BDeepSeek provider artifactsprovider artifact×5 references
  • EOpenRouter model rankingsusage data×1 reference

retrieved 2026-08-03 — 2026-08-05

Compliance & deployment

Trains on customer data by default
Yes — flag
SOC 2
not verified
ISO/IEC 42001
not verified
HIPAA eligible
No
Retention window
Not documented
Data residency
PRC (first-party API)
EU AI Act
No published EU AI Act posture; deployer obligations fall entirely on the customer.
Deprecation policy
None stated for the hosted API
Available via
api.deepseek.com · Self-hosted (open weights) · Multiple inference providers

Incident history

2025-02-01
DeepSeek R1 showed 100% attack success rate in Cisco testing
Standard jailbreak suite (HarmBench)

Cisco's evaluation reported that DeepSeek R1 failed to block a single prompt from a 50-prompt HarmBench sample. Recorded against the DeepSeek family as the strongest public signal on its jailbreak posture; V3.2-specific retesting is pending our Phase 2 probe battery.

Sources (1)
  • Cisco security evaluation
    Cisco security research · independent eval · source tier C · blogs.cisco.com · retrieved 2026-08-03

Change timeline

2025-09-29
DeepSeek V3.2 released; hosted alias updated in place
versionnotice

Open weights published with a technical report. The hosted deepseek-chat alias was cut over to the new version in place — users of the first-party API changed models without an account-level action.

Evidence (1)

Compare this model: DeepSeek V3.2 + open compare view →