Technology7 min read

US Gov Site Used Chinese AI the FBI Called Malicious

A US government website briefly ran Alibaba's Qwen AI model — one the FBI named in an industrial-scale data theft probe. Here's what happened and why it matters.

US Gov Site Used Chinese AI the FBI Called Malicious

Key takeaways

  1. 1That detail, surfaced by social media users and reported by Reuters, set off a rapid reversal: government officials pulled the tool down in September 2026.
  2. 2The National Archives has not commented publicly on how the Qwen model came to be embedded in one of the government's most consequential public-facing platforms.
  3. 3Stanford's AI Index Report 2024 noted that frontier model training runs now routinely exceed $100 million in compute costs.
  4. 4The Broader Security Implications for Federal AI Adoption The concern with deploying Chinese-developed AI on a US government platform is not purely reputational.
Sections · 5

US Government Quietly Deployed a Chinese AI Model the FBI Flagged as Malicious

The Federal Register website — the official journal of the US government, managed by the National Archives — briefly offered visitors the option to search public comments on proposed regulations using a Qwen AI model built by Alibaba. That detail, surfaced by social media users and reported by Reuters, set off a rapid reversal: government officials pulled the tool down in September 2026. The episode stands as one of the clearest examples of a US government Chinese AI model deployment slipping through the cracks of federal procurement oversight, and it arrived at perhaps the worst possible moment.

Just weeks before the removal, the FBI had singled out Alibaba by name as a participant in what the agency characterized as "industrial-scale distillation" of American frontier AI systems. The contradiction was stark: a federal agency deploying a model built by a company that federal law enforcement had publicly accused of illegally replicating American AI capabilities.

The National Archives has not commented publicly on how the Qwen model came to be embedded in one of the government's most consequential public-facing platforms. The White House and FBI have similarly declined to respond to press inquiries. That silence is itself informative.

The FBI's Case Against Alibaba and Chinese AI Firms

The FBI's framing centers on a technical practice called model distillation — a process in which a smaller, more efficient model trains to mimic the behavior of a larger, more capable one. In standard AI research, distillation is a legitimate optimization technique. Engineers at every major lab use it. What the FBI alleges is different in scale and intent: that Alibaba and five other Chinese firms have been systematically using outputs from leading US frontier models to train their own systems without authorization.

Read next Laika's Wildwood: Stop-Motion Fantasy at TIFF 2026

The process works like this: a student model is exposed to the input-output behavior of a teacher model — the queries it receives, the responses it generates, the probability distributions it assigns. Over millions of examples, the student internalizes patterns it would otherwise require enormous compute budgets to learn from scratch. Stanford's AI Index Report 2024 noted that frontier model training runs now routinely exceed $100 million in compute costs. Distillation, conducted at industrial scale against a competitor's outputs, could compress years of expensive pre-training into a fraction of the time and cost.

The allegation positions this practice as intellectual property theft wrapped in machine learning methodology. If the FBI's characterization holds, Alibaba and the other named firms have been shortcutting the most expensive phase of AI development by harvesting the embedded capabilities of American models. Naming six firms specifically — rather than issuing a general advisory — represents a deliberate escalation in how US law enforcement frames the competitive threat. Previous warnings from agencies like CISA focused primarily on data security and supply chain integrity. The FBI's framing moves closer to an economic espionage narrative.

How a Chinese AI Tool Ended Up on a US Government Site

How a Chinese AI Tool Ended Up on a US Government Site — United states capitol building, washington
How a Chinese AI Tool Ended Up on a US Government Site — United states capitol building, washington

The Federal Register processes millions of public comments annually on proposed federal rules — from environmental policy to financial regulation. Embedding an AI search layer atop that corpus is a defensible product decision in the abstract. Citizens benefit from tools that make dense regulatory filings more navigable. The problem is which AI was chosen to do it.

It remains unclear exactly when the National Archives began deploying the Qwen model or through what procurement pathway it arrived. Federal agencies are subject to FedRAMP authorization requirements for cloud services, and Executive Order 14110 on AI — signed in October 2023 — directed agencies to conduct rigorous risk assessments before deploying AI tools in any sensitive context. Whether Qwen received that scrutiny, or whether it was introduced informally by a developer or a third-party vendor integration, has not been disclosed.

This ambiguity is not unusual. A 2023 GAO report on federal technology acquisition identified persistent gaps in how agencies track and govern third-party AI components embedded within larger software systems. When a capability arrives as a feature inside a platform rather than as a standalone procurement, it can move through — or around — the review processes designed to catch exactly this kind of risk. The Federal Register episode illustrates how a US government Chinese AI model can surface not through deliberate policy, but through the accumulation of small, low-visibility implementation decisions made below the threshold of formal oversight.

The Broader Security Implications for Federal AI Adoption

The concern with deploying Chinese-developed AI on a US government platform is not purely reputational. It is structural.

Large language models, including Qwen, are trained on data and shaped by architectural and fine-tuning decisions made under China's regulatory environment. Chinese law obliges domestic technology companies to cooperate with state intelligence agencies on request. That obligation does not dissolve when a model is deployed abroad. Security researchers and former federal officials have raised the possibility that model weights could encode subtle behaviors — selective omission patterns, framing biases in summarization, preference for certain political framings — that are difficult or impossible to detect through standard output benchmarking.

Former federal CISO perspectives, reflected in public testimony before the Senate Armed Services Committee and in published analysis from the Center for Strategic and International Studies, have consistently flagged AI model provenance as an underweighted variable in federal security reviews. Network-layer defenses have decades of procedural maturity; model-layer risk assessment is a newer discipline with fewer established tools and no standardized audit framework. A US government Chinese AI model embedded in a regulatory comment system — a platform that mediates between citizens and the rulemaking process — fits precisely the threat profile that security guidance has been slowly working toward.

CISA's 2024 AI security guidance, developed jointly with international partners including the UK's National Cyber Security Centre, explicitly directs agencies to assess not just the performance of AI tools but their origin and the data governance practices of the developing organization. The Federal Register deployment appears to have bypassed that evaluation.

The US-China AI competition adds further context. According to Georgetown University's Center for Security and Emerging Technology, China has elevated the pursuit of AI parity with the United States to a national strategic priority, with state-backed compute investment accelerating sharply since 2022. Alibaba's Qwen series has posted benchmark scores competitive with leading Western models, including strong results on MMLU and HumanEval. That performance is partly what makes the distillation allegation consequential: it suggests Chinese firms may be narrowing the capability gap faster than their domestic compute investment alone would explain.

What Happens Next: Accountability and Unanswered Questions

The swift removal of the Qwen tool signals that someone in government recognized the contradiction quickly once it became public. Speed of response is not the same as accountability.

Several questions remain unanswered. Did the Qwen model interact with any non-public data, or was its access strictly limited to publicly available Federal Register comments? What procurement or security review, if any, preceded its deployment? Are there other federal websites currently running AI components built by entities the FBI has flagged?

Congress has shown growing interest in federal AI procurement oversight. The Senate Homeland Security Committee examined AI supply chain risk in 2025, and the National Cybersecurity Strategy published in 2023 identified foreign-controlled technology in federal infrastructure as a first-tier concern. The Federal Register incident may accelerate legislative pressure to require agencies to affirmatively document and certify the provenance of AI components in public-facing systems — not just the applications themselves, but the models powering them.

For the National Archives and the broader federal technology community, the incident is a case study in a familiar failure mode: the pace of AI adoption outrunning the governance frameworks meant to contain it. A US government Chinese AI model appeared on one of the federal government's foundational public information platforms — not through espionage or deliberate subversion, but through the routine mechanics of software deployment decisions made faster than policy could follow. Closing that gap is the harder, less visible work. The removal of a single model solves the symptom. It leaves the underlying condition unaddressed.


Source: Ars Technica - All content

Published

29 September 2026

Author

Editorial

Comments

No comments yet. Be the first.

Leave a comment