← BACK TO FEED
AlibabaQwenUS governmentAI policyopen source AI

A US Government Website Was Running Alibaba's AI While the FBI Called It a Security Threat

The US National Archives briefly deployed an Alibaba Qwen AI model on the Federal Register website, drawing criticism given that the FBI had recently labelled such Chinese AI models as "malicious" and accused Alibaba of illegally copying US frontier models. The tool was quietly removed after social media users flagged the contradiction, though security experts noted it likely posed minimal risk, as it only handled already-public data and did not share information with Alibaba. The incident has reignited broader debate about whether US agencies and businesses should be permitted to use open-source Chinese AI models, with some lawmakers insisting they should be banned outright while business groups warn that restrictions could put the US at a competitive disadvantage.

The Federal Register, the official US government website for public regulatory documents, spent at least a day running an Alibaba AI model to help users search public comments on proposed rules. When social media users noticed, officials quietly pulled it. No explanation followed.

The awkwardness here is hard to overstate. Earlier this month, the FBI specifically named Alibaba as one of six Chinese companies allegedly engaged in what the agency called 'industrial-scale distillation' of American frontier AI models. The accusation is essentially that these firms are copying proprietary US technology to close the development gap faster and cheaper. And yet, one US government body was cheerfully deploying their search tool on a publicly accessible federal website.

The National Archives, which runs the Federal Register, has said nothing about when the tool was added, why it was added, or why it was removed. The White House and the FBI are equally tight-lipped. An archived version of the site's source code confirmed the model disappeared on Wednesday. A screenshot posted to X on 15 September showed it was there, so it ran for at least a day.

Daniel Castro, president of the Information Technology and Innovation Foundation, told Reuters the situation was simply 'insane.' Hard to argue with that framing.

Actual Risk Probably Low

Before this becomes a full-blown security panic, it's worth looking at what was actually deployed. The Federal Register was running a small open-weight model, reportedly Qwen3 at the 0.6B parameter level. That is not some vast, cloud-connected reasoning system phoning home to Alibaba's servers. It is a compact, open-source retrieval model that can be downloaded and run entirely locally.

Georgetown Law Professor Anupam Chander pointed out that the Federal Register's content is already public. There was no sensitive government data for the model to touch. Open-weight models downloaded and run on local infrastructure do not send queries to external systems. Security experts told Reuters that the real-world risk from this specific deployment was minimal.

In fact, small locally-run open-weight models are increasingly popular in government and enterprise settings precisely because they keep data on-premises. The irony is that the properties that made Qwen convenient for the National Archives, its compact size, open weights, local deployment, and predictable cost, are the same properties that make it a low security risk.

Senator Mark Warner (D-Va.) acknowledged the nuance, noting risk depends partly on whether US data passed through Alibaba-controlled infrastructure. In this case, it apparently did not.

The Bigger Policy Mess

Still, the optics are dreadful, and the underlying policy confusion they expose is real.

The US government has been heavy-handed on restricting advanced chip exports to China, trying to slow frontier AI training. What it hasn't done is develop a coherent framework for small, open-weight models that originate in China but are deployed and controlled by American institutions. These models sit in a grey zone that current export controls and security guidance don't clearly address.

Policy research submitted to the US-China Economic and Security Review Commission in March made the point bluntly: US controls are aimed at restricting access to semiconductors for frontier training. They say nothing useful about the small-model deployment cycle, which needs less compute, builds on open-source foundations, and generates advantage through application, not pre-training. If small, specialised, open models are what actually matter for industrial AI adoption, the US may be focusing its competitive anxiety at the wrong target.

Meanwhile, China saw the gap in the open-source AI ecosystem and moved deliberately to fill it. Models like Qwen are now widely used by businesses globally, including, briefly, by a US government website.

Rep. John Moolenaar (R-Mich.), who chairs the House China Committee, has a simple position: no federal entity should use a Chinese AI model, full stop. 'Doing so only makes the federal government more dependent on Chinese AI models, and that is not in the national interest,' he said.

That's a defensible stance politically. Whether blanket prohibition is workable in practice when Chinese-origin open-weight models are embedded across global software infrastructure is a harder question. One the US government clearly hasn't figured out yet, given what just happened.

READ NEXT
China Claims US Firms Distil Its Models Too, As AI Trade War Rhetoric EscalatesFlagged as a Pentagon Supply Chain Risk, Anthropic Is Probably Getting the NSA Contract AnywayAI Doomsday Warnings Are a Shakedown, Not a Safety Briefing