Washington Is Warning About Chinese AI. One of Its Own Websites Was Using It

Illustration of the US Federal Register website using Alibaba's Qwen AI against a Washington and China technology backdrop.

The FBI accused Alibaba last week of “malicious” copying of American AI technology on an “industrial scale”.

Days later, an Alibaba AI model was discovered running as a search option on a US government website.

Reuters found that the Federal Register, the official daily record of proposed federal regulations and other government notices, had been offering users a search tool powered by Alibaba’s Qwen model. The tool disappeared on Wednesday around the time social-media posts began drawing attention to it.

There is no evidence that Qwen compromised US government systems or sent sensitive information to China. The Federal Register material being searched was public, and Qwen is an open-weight model that could have been running entirely on infrastructure controlled by the US government.

That leaves a more revealing question: does the US government have clear visibility over which AI models are already running inside its own services?

The question matters because Washington increasingly treats advanced AI as an economic and national-security asset. The US has restricted Chinese access to some advanced American chips while accusing Chinese companies of improperly using American models to accelerate their own development.

Alibaba has become part of that dispute. The FBI last week accused the company of copying technology from Anthropic, one of America’s leading frontier AI developers. US officials described the wider practice by Chinese AI companies as malicious copying conducted on an industrial scale.

China has rejected American allegations of technology theft as baseless.

Against that backdrop, discovering Qwen on a federal website creates an obvious contradiction. Washington is warning about the strategic implications of Chinese AI development while one of its own public services was simultaneously offering a Chinese model to users.

But the apparent contradiction is much larger than the demonstrated security risk.

Calling Qwen a Chinese model tells us who developed it. It does not tell us where it was running, who controlled the infrastructure or whether information was being transmitted to Alibaba.

That distinction changes the security question. An organisation can download an open-weight model and operate it on its own computers without sending queries or data to the original developer. If the Federal Register deployed Qwen entirely inside a US-controlled environment, using the model would not by itself mean federal information was being processed in China.

The information involved also matters. The tool was searching public comments on proposed federal regulations, not classified material or information that was inherently sensitive.

Senator Mark Warner, the Democratic vice chairman of the Senate Intelligence Committee, identified the more useful test. He said the risk depends on whether US government data crossed the government’s security boundary and was processed on infrastructure controlled by Alibaba.

Reuters could not establish that it did.

It also could not establish when Qwen was introduced, who approved its use or where the model was being run. The National Archives, which operates the Federal Register website, did not respond to Reuters’ request for comment. Neither did the White House.

Those unanswered questions expose the governance problem more clearly than the nationality of the model.

Government agencies are likely to use increasing numbers of AI systems built by outside organisations. Some will be proprietary models accessed through external cloud services. Others will be open-weight models operated internally. Contractors may deploy models while providing government services, and individual applications may rely on several different systems.

The security characteristics of those arrangements can be completely different even when the underlying model has the same name.

A model running on infrastructure controlled by a foreign company creates one set of questions. The same model isolated inside a government-controlled environment creates another. A system handling classified intelligence requires different safeguards from one searching information already available to the public.

Model origin matters, particularly where governments have legitimate concerns about foreign technology and supply chains. But origin alone cannot describe the risk.

That means simply maintaining lists of approved or prohibited AI companies will not be enough to govern federal AI use.

Agencies need an inventory of what is actually deployed. That means knowing which model an application uses, where it executes, what information it can access, whether data leaves government-controlled infrastructure and who authorised the deployment.

Those are operational questions rather than geopolitical slogans, but they become increasingly important as AI moves deeper into government systems.

The Federal Register episode is a relatively forgiving example because the information involved was public and no security compromise has been demonstrated.

The next deployment may not be.

An AI model could eventually assist with internal correspondence, procurement documents, personal information, law-enforcement records or other material where the location and handling of data become considerably more consequential.

By that point, discovering the deployment after somebody notices a model name on a public website would be a poor substitute for knowing about it beforehand.

The Qwen episode also demonstrates why Washington needs something more sophisticated than “American AI safe, Chinese AI dangerous”.

American models can be deployed insecurely. Foreign models can potentially be operated inside tightly controlled infrastructure. Proprietary systems may transmit information externally, while open-weight models may operate without any connection to their original developer.

The security assessment has to follow the architecture and the data, not simply the flag attached to the company that trained the model.

That does not make the geopolitical argument irrelevant. Washington can still decide that particular foreign models create unacceptable risks because of their provenance, training, supply chain or other considerations.

But it should be able to make that decision knowing what is already running inside federal systems.

Qwen did not expose a demonstrated Chinese breach of the US government. It exposed a question about American oversight.

As agencies adopt more AI, model origin alone will tell policymakers increasingly little about the actual security risk. They will need to know where each model runs, what information it can access, where that information travels and who authorised the deployment.

The question exposed by Qwen is not simply whether Washington should trust Chinese AI.

It is whether Washington can reliably tell what AI is already running inside its own government.

Sources

Share this story