US government website used Chinese model the FBI called "malicious"
On September 15 the National Archives’ Federal Register portal displayed a “search with AI” button that routed queries to a locally hosted instance of Alibaba’s Qwen 3 0.6B model, a 600‑million‑parameter open‑weight version of the Chinese firm’s larger Qwen series. The feature was live for at most a day before the site’s code was updated to strip the integration, a change confirmed by archived source files. The removal came after social‑media users highlighted the contradiction between the agency’s use of a Chinese model and the FBI’s recent accusation that Alibaba is among six firms conducting “industrial‑scale distillation” of U.S. frontier AI, a practice the bureau says helps China shortcut development and erodes U.S. leadership.
The episode lands squarely in a widening policy clash over AI provenance. The FBI’s warning reflects a broader U.S. effort to bar federal entities from Chinese‑origin models, echoing statements from Rep. John Moolenaar that any use “makes the government more dependent on Chinese AI.” Yet the Qwen 0.6B deployment sidestepped many of the security concerns the bureau cites: the model is open source, runs entirely on government hardware, and processes only publicly available Federal Register content, meaning no classified data is transmitted to Alibaba’s cloud. Experts note that the U.S. export‑control regime targets high‑end, compute‑intensive frontier models, leaving a gap for smaller, open‑source tools that can be downloaded and operated locally. This gap fuels a debate among industry leaders, open‑source advocates, and policymakers about whether restrictions should extend to such lightweight models, especially as China accelerates its own open‑source AI ecosystem to compensate for U.S. curbs on advanced chip sales.
The fallout underscores three practical risks. First, the brief exposure may prompt stricter procurement guidelines that require agencies to certify model provenance, potentially slowing adoption of cost‑effective open‑source solutions. Second, the incident could intensify congressional scrutiny, leading to legislative language that bans any Chinese‑origin code, regardless of its open‑source status. Third, the episode highlights a strategic dilemma: restricting Chinese models may protect supply‑chain security but could also cede the “default” AI tooling market to foreign developers, weakening U.S. influence over emerging standards. Watch for an official memo from the Office of Management and Budget or a new directive from the National Archives clarifying acceptable AI sources, as well as any legislative proposals that codify the “no‑Chinese‑model” stance.
Key Takeaways
The Federal Register’s AI search tool used Alibaba’s open‑source Qwen 0.6B model for less than 24 hours before being removed.
FBI officials have labeled Alibaba as part of a “industrial‑scale distillation” effort that threatens U.S. AI leadership.
Because the Qwen model runs locally on public data, security experts assess the actual risk as minimal despite political backlash.
The incident may trigger tighter federal procurement rules and possible legislation banning any Chinese‑origin AI code, even open‑source variants.
About the Source
This analysis is based on reporting by Ars Technica. Here is a short excerpt for context:
The Federal Register website briefly used an open source Chinese AI search tool.Read the original at Ars Technica