Perhaps it is a non-Chinese fine-tune of a parent Chinese model, and they’re actively trying to update the model by ablating the trained-in censorship out as it’s revealed in the response logs.