
U.S. Federal Register Used Alibaba’s Qwen AI Days After FBI Warned Chinese Firms Were Harvesting American AI at Industrial Scale
A U.S. government website responsible for publishing federal regulations quietly offered an artificial-intelligence search option built on Alibaba’s Qwen model, creating an extraordinary contradiction just days after American intelligence and cybersecurity agencies warned that Chinese AI companies were conducting industrial-scale campaigns to extract capabilities from U.S. frontier models. The Federal Register website, operated by the National Archives and Records Administration, displayed Qwen-powered search options for users browsing proposed regulations and public comments before the feature was removed on September 16. Reuters confirmed the tool through screenshots and archived source code, although it remains unclear exactly when the Qwen option was first deployed.
The episode deserves American attention because the Federal Register is far from an obscure experimental website. It is the official daily journal of the United States government, publishing proposed and final regulations, agency notices, executive orders, proclamations and other presidential documents. Its contents are public, and the Qwen implementation therefore did not necessarily expose classified government information. The larger concern is institutional: a Chinese-developed AI model had become part of the search architecture of a federal information platform at the same moment U.S. security agencies were warning that China’s AI industry was aggressively seeking American model capabilities.
The timing is difficult to ignore. On September 8, the National Security Agency, FBI and Cybersecurity and Infrastructure Security Agency jointly released an advisory titled “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies.” The agencies said China-based AI companies were systematically extracting restricted proprietary functions and capabilities from American frontier models for use in training their own systems. The government advisory characterized the activity as aggressive and industrial in scale. Alibaba was among the Chinese companies identified in reporting on those campaigns.
That makes the Federal Register incident strategically important even if no sensitive data left government systems. AI dependence is not limited to whether a model immediately steals a secret file. Dependence can begin when organizations build workflows, search tools, retrieval systems and software around foreign models because those models are inexpensive, technically capable and readily available. Once a model becomes embedded in an institution’s software stack, replacing it can become more difficult, and developers may gradually build additional functions around the same technology.
Qwen is especially attractive for that reason. Unlike closed systems that generally require users to send requests to a vendor-operated service, Qwen is available as an open-weight model. Developers can download its model weights, modify the system and potentially run it on infrastructure they control. Reuters noted that this architecture can substantially reduce immediate data-security concerns because sensitive information does not necessarily have to travel to Alibaba-controlled servers. Georgetown Law Professor Anupam Chander similarly said that the Federal Register implementation did not appear to pose an immediate cybersecurity threat because the material being processed was already public.
That technical distinction is important, but it does not eliminate the strategic issue. A locally hosted Chinese model can avoid one category of risk while still creating technology dependence on a model developed by a company already under intense U.S. national-security scrutiny. The Pentagon placed Alibaba on its 2026 list of companies it considers connected to China’s military ecosystem, alongside other major Chinese technology firms. Alibaba rejected that designation and said it is not a Chinese military company.
The U.S. government’s own recent AI-security warning adds another dimension. American agencies said China-based AI companies were attempting to obtain capabilities that American companies spent enormous resources developing. Model distillation can allow one AI system to learn from outputs generated by a more capable system, reducing some of the cost and time required to reproduce aspects of the original model’s behavior. In the most aggressive cases described by U.S. officials, companies allegedly used large numbers of interactions with American models to gather training material at industrial scale.
The result is a peculiar strategic cycle. American companies invest billions of dollars building frontier models. U.S. security agencies warn that Chinese AI companies are attempting to extract those capabilities. Chinese firms then produce increasingly competitive models available at low cost or as open weights. Those models become attractive to developers around the world — including, apparently, developers working on an official U.S. government website. If that cycle continues, the United States could find itself financing the expensive frontier of AI innovation while increasingly depending on cheaper Chinese derivatives downstream.
The Federal Register case therefore matters less because of what one small search model may have done and more because of what it reveals about procurement discipline. The Qwen implementation was reportedly a relatively small Qwen3 model used for document retrieval. Reuters said it was offered alongside several other search modes, meaning the website was not wholly dependent on Alibaba technology. But its presence demonstrates how easily foreign AI models can enter software projects when developers optimize for performance, cost and convenience without a uniform government-wide approach to model provenance and strategic technology risk.
Lawmakers from both parties raised different aspects of that concern. Representative John Moolenaar, chairman of the House Select Committee on China, told Reuters that federal entities should not rely on Chinese AI models because doing so increases dependence. Senator Mark Warner, the Democratic vice chairman of the Senate Intelligence Committee, focused on the technical architecture, saying the risk depends substantially on whether U.S. data remained inside government-controlled systems or was processed by Alibaba-controlled infrastructure. Those positions highlight two different questions that federal technology reviews have to answer: where the data goes and whose technology becomes embedded in government systems.
The same issue is already appearing in the private sector. House committees previously questioned Airbnb about its use of Qwen and requested information concerning national-security risks created by integrating Chinese AI technology into platforms used by Americans. The concern extends beyond one model or one company. As open-weight Chinese AI improves, organizations can integrate it without signing an obvious cloud contract with a Chinese provider. A model can simply be downloaded and incorporated into an application, making traditional vendor-review procedures less effective at detecting dependency.
For American cybersecurity teams, this means AI provenance should increasingly be treated like software supply-chain provenance. Security personnel already care where libraries, firmware, networking equipment and encryption components come from. AI models now deserve similar scrutiny. Agencies need to know who developed a model, how it was trained, whether additional code communicates externally, what telemetry exists, where inference occurs, what licenses apply and whether model updates could change its behavior or dependencies.
The Federal Register incident also demonstrates why “public data” does not end the discussion. It substantially lowers the immediate confidentiality risk, but government AI systems can still affect search rankings, retrieval accuracy and the way citizens discover official information. A model used to navigate regulatory documents becomes an intermediary between the public and government records. That role makes transparency about model selection, testing and provenance important even when every underlying document is publicly available.
There is no evidence in the reported Federal Register case that Qwen secretly transmitted federal data to China, and Reuters’ experts specifically said an immediate cybersecurity risk was unlikely if the model ran inside controlled infrastructure. The documented concern is more structural: the federal government briefly used technology from a Chinese AI ecosystem that U.S. intelligence agencies had simultaneously identified as conducting aggressive model-distillation activity against American companies.
The removal of the Qwen search option therefore closes one small implementation question while leaving a much larger one unresolved. Open-weight Chinese models can be downloaded quickly, perform well and cost little to operate. Those advantages virtually guarantee that they will continue appearing in American commercial and technical environments. The challenge for the United States is developing procurement and security standards capable of distinguishing low-risk experimentation from strategic technological dependence before foreign models become deeply embedded across critical systems.
The Federal Register episode offers a useful warning about how quickly that dependence can happen. China does not need to force American institutions to adopt its AI. If Chinese companies can produce cheap, capable and easily deployable models, developers may select them voluntarily. That is precisely why model provenance, supply-chain review and transparent technical auditing matter. America’s AI competition with China will be shaped not only by who builds the most powerful model, but also by whose models quietly become infrastructure inside the systems Americans use every day.