Feb 28, 2025 · 15m · a16z
How to use DeepSeek safely
gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions
In this episode of the a16z podcast, host Joel de la Garza and Promptfoo CEO Ian Webster analyze the security, censorship, and enterprise risks associated with China's open-source DeepSeek AI model. They outline key vulnerabilities, contrast its hardcoded political guardrails against Western alternatives, and provide actionable deployment guidance for enterprise security leaders.
How this conversation actually went
Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →
speaking balance: gold is the host, purple is the guest (3 minute bins)
The guest forcefully rejects widespread online chatter and host assumptions that locally running DeepSeek avoids political guardrails.
Hardest push from the host ▶ 11:05 Host asserts definition of censorshipWhen the guest equivocates on whether Western model refusals count as censorship, Joel firmly interrupts to insist that it is censorship.
Biggest teaching moment ▶ 11:10 Claude censorship parity revelationThe guest educates the host with benchmark data revealing Anthropic Claude censors sensitive Chinese political topics at the exact same 85% rate as DeepSeek.
The host holds their own ▶ 12:09 Critique of Western commentary hypocrisyJoel demonstrates strong analytical domain expertise by synthesizing the benchmark data to call out the hypocrisy of American commentators criticizing Chinese models while Western models do the same.
the scores for every segment, with the reasoning behind each
| Chapter | Topic | The host as informed peer | Guest teaching | Guest disagreement | The host pushing back | Why |
|---|---|---|---|---|---|---|
| a16z Podcast Title Sequence | 3 | 3 | 1 | 1 | Joel introduces the guest's blog post and sets up the framing around DeepSeek's open source release and China origins. The guest collaboratively explains red teaming research and prompt injection vulnerabilities without any conflict. | |
| Analyzing DeepSeek's Political Censorship and Guardrails | 4 | 5 | 2 | 2 | Joel offers domain context by bringing up Wiz research on DeepSeek infrastructure and OpenAI learning curves. The guest educates the host with benchmark data showing DeepSeek performs 20% worse than GPT on jailbreak resilience. | |
| Self-Hosting vs Cloud Hosting and Hidden Security Risks | 3 | 6 | 2 | 1 | The guest corrects a widespread internet misconception that self-hosting DeepSeek removes political censorship, clarifying that hard guardrails remain active regardless. Joel listens and acknowledges the security implications. | |
| Comparing Speech Restrictions: US Flagship Models vs DeepSeek | 6 | 5 | 1 | 4 | The guest reveals surprising data showing US models like Anthropic Claude censor Chinese political topics at rates equal to DeepSeek. When the guest hesitates on terminology, Joel firmly interjects to define the behavior as censorship and draws insightful conclusions on Western commentator hypocrisy. | |
| Enterprise Safety Recommendations and Deployment Strategy | 5 | 4 | 1 | 2 | Joel synthesizes the guest's technical warnings into a clean enterprise strategy recommendation to wait for alternative open source implementations. The guest agrees and elaborates on DeepSeek's usability flaws. |