Skip to content

Evaluations

Liang Wenfeng's 2026 net worth hides DeepSeek's legal risk

Liang Wenfeng's 2026 fortune is the entry point, not the verdict. The verified record behind the headlines — government-device bans, an exposed database finding, an IP dispute, and a 50% legal-task accuracy benchmark — is what procurement teams need before putting DeepSeek in a firm workflow.

By Editorial TeamUpdated Jul 31, 2026
Tool
DeepSeek
Benchmark source
Cambridge International Journal of Legal Information
Hallucination rate
30%
Test methodology
50 legal questions tested Dec 2024–Apr 2025 across ChatGPT-4, Copilot, DeepSeek, Lexis+ AI, and Llama 3; responses scored as accurate, incomplete, or fabricated.
Test date
Jun 30, 2025

Liang Wenfeng’s 2026 net worth depends on which July snapshot you use. Bloomberg estimated the DeepSeek founder at $36 billion on July 14, 2026, up from about $16.7 billion previously; its Billionaires Index profile later showed $37.9 billion and world rank No. 58 as of July 30, 2026. Forbes’ real-time profile put him higher, at $39.5 billion and rank No. 50 on July 25, 2026. Press coverage also circulated still-higher figures, including an AFR-reported $54 billion estimate and valuation speculation built around a hypothetical $150 billion company value. None of these numbers is an audited wealth statement. They are private-company estimates built from assumptions about DeepSeek’s equity value and Liang’s ownership. [1][2][3]

The method matters more than the leaderboard. Bloomberg’s July calculation used an 81.7% ownership stake attributed to Qichacha, reported financing of more than $7.4 billion in June 2026 at roughly a $50 billion valuation, and excluded High-Flyer’s approximately 70 billion yuan, or about $10 billion, in assets under management to avoid double counting. Forbes used a similar private-company valuation frame, with a reported $52 billion DeepSeek valuation and Liang’s $3 billion personal investment among the relevant inputs. DeepSeek did not respond to Bloomberg’s request for comment. [1][3]

Justice scale weighing gold and cash against legal documents, a warning ribbon, and a gavel

That is the finance answer to the search query. It is also the wrong place for a legal team to stop. A founder’s July 2026 wealth explains why DeepSeek is suddenly appearing in law-firm procurement conversations, why partners are forwarding screenshots, and why cheaper inference has become a boardroom topic. It does not answer whether the tool belongs inside a workflow that contains client confidences, privileged work product, legal research, or filing decisions.

Treat the wealth headline as a procurement trigger

DeepSeek’s commercial pressure on legal-AI incumbents is real enough to evaluate. A cheaper or more efficient model can change budget conversations, especially where firms are comparing general-purpose AI, retrieval systems, local deployments, and premium legal research assistants. But procurement does not get to inherit market excitement as a control.

The file a risk committee needs is narrower and less glamorous: what regulators have actually done, what security researchers have actually found, what competitors have alleged but not proved, what legal-task studies have measured, and what has not been measured at all. For teams comparing current model behavior, this record should sit alongside a current DeepSeek V4 Flash scorecard, any local DeepSeek deployment workflow, and the firm’s own data-classification rules.

What is verified: privacy actions, government-device restrictions, and one confirmed database exposure

The first correction is vocabulary. DeepSeek has not been “banned in the U.S.” in the broad consumer-market sense. The verified U.S. record is government-device and government-network restrictions, proposed federal legislation, state-level bans, and an attorney-general investigation. Those are procurement-relevant signals, but they are not the same legal event.

Italy’s privacy authority, the Garante, blocked DeepSeek on Jan. 30, 2025 after saying the company’s response to information requests was “totally insufficient,” and it opened an investigation. That is a national data-protection authority action, not a benchmark dispute or a competitor complaint. For a law firm, it goes directly to privacy diligence and vendor responsiveness. [4]

South Korea’s record is different. The Personal Information Protection Commission suspended downloads of DeepSeek on Feb. 15, 2025, and the app became available again in April 2025 after compliance steps were reported. That history should be read as a suspension-and-resumption record, not as a permanent ban. It still belongs in the diligence file because it shows another privacy regulator found enough concern to interrupt distribution. [5]

In the United States, federal restrictions moved quickly after DeepSeek’s January 2025 surge. Reported measures included a U.S. Navy memo on Jan. 24, 2025, a Defense Information Systems Agency network block on Jan. 28, a NASA memo on Jan. 31, and Commerce Department bureau restrictions in March 2025. H.R. 1121, the “No DeepSeek on Government Devices Act,” was introduced on Feb. 7, 2025. Those facts support a careful phrase: DeepSeek has faced U.S. government-device and government-network restrictions, plus proposed federal legislation. [6][7]

At the state level, Texas was the first state to ban DeepSeek on government devices on Jan. 31, 2025, and StateTech later tracked bans across more than 13 states. Texas Attorney General Ken Paxton then announced an investigation on Feb. 14, 2025, notified DeepSeek of an alleged Texas Data Privacy and Security Act violation, and issued civil investigative demands to Google and Apple. That is not an adjudicated violation, but it is an active enforcement posture from a state attorney general. [8][9]

Timeline of DeepSeek risk events from 2025 to 2026 with privacy, government, database, and document icons

The security record includes one unusually concrete researcher disclosure. Wiz Research reported finding a publicly accessible, unauthenticated ClickHouse database at oauth2callback.deepseek.com:9000 and dev.deepseek.com:9000, containing more than one million log lines dating from Jan. 6, 2025, including chat history, API secrets, operational metadata, and backend details. Wiz said the exposure allowed full database control and that DeepSeek secured it after responsible disclosure. This is not a regulator’s sanction or a court finding. It is a confirmed security-research disclosure, and for procurement purposes that distinction does not make it irrelevant. [10]

RecordSource statusProcurement meaning
Italy Garante block and investigation, Jan. 30, 2025National data-protection authority actionPrivacy and regulator-response risk; last verified Aug. 1, 2026. [4]
South Korea download suspension on Feb. 15, 2025, followed by April 2025 resumptionPrivacy regulator suspension-and-resumption recordCompliance history, not a permanent-ban finding; last verified Aug. 1, 2026. [5]
U.S. federal and state government-device restrictionsGovernment-use restrictions and proposed legislationUse precise language: restricted on government devices/networks, not categorically banned in the U.S.; last verified Aug. 1, 2026. [6][7][8]
Texas AG investigation and TDPSA violation notice, Feb. 14, 2025State attorney-general enforcement activityOpen investigation posture, not adjudicated liability; last verified Aug. 1, 2026. [9]
Exposed ClickHouse database disclosed by WizSecurity-research disclosureConcrete data-exposure signal to test against any client-data workflow; last verified Aug. 1, 2026. [10]

What is alleged or unresolved: the OpenAI distillation accusation

The intellectual-property file is less settled than the privacy and security record. OpenAI’s Feb. 12, 2026 memo to the House Select Committee on Strategic Competition accused DeepSeek of “ongoing efforts to free-ride” through obfuscated third-party routers and programmatic distillation code. That is a serious accusation in a congressional-policy setting. It is not a judicial finding that DeepSeek infringed OpenAI’s rights, misappropriated trade secrets, or violated any particular contract. [11]

For legal procurement, the unresolved status still matters. A firm does not need to decide the merits of OpenAI’s claim to recognize the risk category: if a model’s training, distillation, or output provenance becomes the subject of litigation, client-facing use may create uncomfortable questions about vendor indemnity, contractual representations, and downstream reliance. The right entry in a risk register is not “proved infringement.” It is “active, unresolved IP accusation from a major model provider; no court finding in the reviewed record.”

The strongest reliability evidence for a legal team is the Cambridge International Journal of Legal Information study published on June 30, 2025. It tested 50 legal questions from December 2024 through April 2025 across ChatGPT-4, Copilot, DeepSeek, Lexis+ AI, and Llama 3. DeepSeek produced 50% accurate answers, 20% incomplete answers, and 30% fabricated responses. Lexis+ AI, by comparison, scored 58% accurate, 22% incomplete, and 20% fabricated; the authors still found hallucinations across all tools. [12]

Magnifying glass over a legal document with red X marks and green check marks suggesting a reliability audit

That 50% figure should not be inflated beyond the study’s design, but it should not be softened either. It was a legal-operations study asking legal questions during a defined window. For a lawyer deciding whether to let a general model assist with research, drafting, or matter analysis, “30% fabricated responses” is not an academic nuisance. It is the number that determines how much human verification must sit between the model and any client-facing work product.

Other reliability data is useful only when kept in its lane. Vectara’s HHEM 2.1 evaluation found DeepSeek-R1 hallucinated at 14.3% on summarization grounding, compared with 3.9% for DeepSeek-V3 — roughly a fourfold gap. That tells a buyer something about grounded summarization behavior in that benchmark. It does not tell the buyer whether DeepSeek can accurately cite cases, distinguish binding from persuasive authority, or avoid inventing docket facts. [13]

The same scope discipline applies to the Europe PMC preprint reporting that DeepSeek-R1 had the highest hallucination rate, 91.43%, in scientific figure interpretation and reference-retrieval tasks, compared with 39.14% for ChatGPT-4o. The number is too striking to ignore, but it is a preprint and the task domain is scientific, not legal. It should be cited as a warning about hallucination behavior under a particular scientific setup, not as a measured legal-citation failure rate. [14]

Stanford RegLab and HAI provide the broader legal-AI environment. Their benchmark found general-purpose chatbots hallucinated on 58% to 82% of legal queries, while retrieval-augmented legal products also hallucinated: Lexis+ AI and Ask Practical Law AI above 17%, and Westlaw AI-Assisted Research above 34%, on a preregistered dataset of more than 200 queries. This is not a DeepSeek-specific benchmark. It is the background condition that makes any unverified legal answer from any AI system suspect. [15]

What remains unmeasured

As of Aug. 1, 2026, the reviewed record does not include a published, methodologically described DeepSeek-specific legal-citation benchmark. That absence is itself a finding. It means a risk committee should not pretend that general hallucination rates, scientific-task preprints, or summarization-grounding scores answer the citation question lawyers actually care about: whether the system can identify real authorities, represent holdings accurately, preserve jurisdictional boundaries, and flag uncertainty rather than inventing support.

A vendor or internal champion may respond that newer models are different. They may be. DeepSeek’s April 24, 2026 V4 preview is a genuine model-line update, and the July 24, 2026 retirement of legacy deepseek-chat and deepseek-reasoner models is procurement-relevant because it changes what a buyer is actually testing. But a release note or model retirement does not erase earlier risk records unless the update is tied to the specific issue: privacy controls, data retention, security architecture, training or distillation provenance, legal-task accuracy, or citation reliability. [16]

That is why current testing should be version-specific. A firm evaluating V4 should test V4, not rely on R1 commentary or V3 summarization numbers. A firm considering local deployment should document whether prompts, logs, embeddings, retrieval stores, and output review remain inside the firm’s controlled environment. Pricing comparisons belong in a different column of the same file; they matter, but they do not substitute for privacy and reliability controls. For that narrower cost question, see the DeepSeek V4 Flash vs. OpenAI pricing analysis. For the regulatory-enforceability problem raised by Chinese model providers, keep a separate note against Chinese AI model U.S. regulation.

The defensible procurement position on Aug. 1, 2026

Liang Wenfeng’s 2026 net worth is a useful top card in the due-diligence file. It explains why DeepSeek is now too visible for many firms to ignore, and why legal-AI vendors with higher price points are being asked harder questions. It does not answer whether DeepSeek should touch client data or legal work product.

The defensible answer is conditional. A legal team evaluating DeepSeek should treat the government-device restrictions, Italy and South Korea privacy actions, Texas AG activity, Wiz database exposure, unresolved OpenAI distillation accusation, Cambridge legal-task accuracy result, and missing DeepSeek-specific legal-citation benchmark as live risk signals. None of those signals automatically makes DeepSeek unusable in every setting. None is neutralized by founder wealth, viral benchmarks, the April 2026 V4 preview, or the July 2026 legacy-model retirement.

If DeepSeek is tested at all in a law-firm environment, the first approval should be for controlled evaluation, not open-ended use: no confidential client facts in public interfaces, no unsupervised citation reliance, no filing or advice based on unverified output, and no assumption that a cheaper model has earned the same workflow permissions as a vetted legal research platform. The wealth headline opened the question. The risk record still controls the answer.

References

  1. DeepSeek’s Liang Tops Amodei and Brockman as Richest AI Founder, Bloomberg, July 14, 2026
  2. Wenfeng Liang, Bloomberg Billionaires Index
  3. Liang Wenfeng, Forbes
  4. Italy's privacy watchdog blocks Chinese AI app DeepSeek, Reuters, Jan. 30, 2025
  5. DeepSeek available for download again in South Korea after suspension, Reuters, April 28, 2025
  6. U.S. Federal and States Governments Moving Quickly to Restrict Use of DeepSeek, Inside Government Contracts
  7. H.R.1121 - No DeepSeek on Government Devices Act, Congress.gov, Feb. 7, 2025
  8. These States Have Banned DeepSeek, StateTech, April 2025
  9. Attorney General Ken Paxton Announces Investigation into DeepSeek and Notifies Chinese AI Company of Its Violation of Texas Data Privacy Law, Texas Attorney General, Feb. 14, 2025
  10. Wiz Research Uncovers Exposed DeepSeek Database Leak, Wiz
  11. OpenAI accuses DeepSeek of distilling US models to gain advantage, Bloomberg News reports, Reuters, Feb. 12, 2026
  12. Evaluating AI in Legal Operations: A Comparative Analysis of Accuracy, Completeness, and Hallucinations in ChatGPT-4, Copilot, DeepSeek, Lexis AI, and Llama 3, International Journal of Legal Information, June 30, 2025
  13. DeepSeek-R1 hallucinates more than DeepSeek-V3, Vectara
  14. Europe PMC preprint PPR1040466, Europe PMC
  15. AI on Trial: Legal Models Hallucinate in 1 out of 6 (or More) Benchmarking Queries, Stanford HAI
  16. DeepSeek V4 preview release, DeepSeek API Docs, April 24, 2026

Chronological incident history

No sanction cases have named this tool in the tracked record set to date. This does not imply the tool is safe — see Risk Digest for ongoing monitoring.

← Compare peer tools

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this tool profile should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →