Reuters reported on September 17 that the U.S. Federal Register website, operated by the National Archives and Records Administration (NARA), was found to have embedded an AI search tool powered by Alibaba's Qwen model. The tool was quietly taken offline on September 16 after social media users noticed it. Neither NARA nor the White House has publicly explained when the deployment began or how it operated.

According to screenshots and archived source code reviewed by Reuters, the Federal Register was using Qwen3 series' 0.6B-scale small model rather than Alibaba's flagship foundation. It targeted semantic matching and summarization of regulatory documents, running on government-owned on-premise infrastructure. Open-weight models allow agencies to download weights to local servers, avoiding per-query payments to model vendors and the need to transmit government documents to third-party APIs. Running a 0.6B-scale model locally can have marginal costs far lower than token-billed closed-source calls. ITIF chairman Daniel Castro put the contradiction bluntly: while the U.S. and China compete fiercely to build top-tier AI models, U.S. government agencies are choosing to use Chinese open-weight models — one of the most "incredible things" he has ever seen.

The Real Focus of the Security Controversy

Installing Qwen on the Federal Register does not mean the U.S. government handed sensitive data to Alibaba Cloud. Georgetown Law professor Anupam Chander noted that the Federal Register's daily content — proposed regulations, executive orders, agency notices — is already public, and Qwen was not processing classified government data. Senator Mark Warner, the Democratic leader of the Senate Intelligence Committee, emphasized the key question is whether data actually passed through Alibaba-controlled systems: if the weights were simply downloaded to a U.S.-based server with no data flowing back to China, does that count as a "Chinese service" or as software of Chinese origin now under U.S. institutional control?

This is precisely the new regulatory challenge open-weight models create. Huawei devices, TikTok, and Chinese cloud services can be delineated by "who the company is, where the servers sit, who controls the data." But once weights are public, they can propagate independently of the original vendor. You can sanction Alibaba, but it is much harder to stop an American developer from downloading Qwen weights and dropping them into a government search system.

FBI's Distillation Allegations Meet its Own Websites

The timing window is almost perfectly overlapping. In September, the FBI, NSA, and CISA issued a joint statement accusing six Chinese AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, Stepfun, and Zhipu — of conducting unauthorized distillation of U.S. frontier models at "industrial scale" since 2024, recommending that model providers adjust outputs in response to suspected malicious distillation and share intelligence with each other. China has denied the allegations.

The ATOM report provides a quantitative reference: in January 2024, Qwen's share of new open-source model fine-tuning and adaptation was just 1%, but by February 2026 it had risen to 69%. The penetration of Chinese open-source models into the U.S. technology stack has reached a level that is starting to blur traditional technology decoupling policies.

Regulatory Boundaries Enter the Open-Weight Era

The Trump administration's June national security AI policy requires U.S. government agencies to accelerate the adoption of advanced AI and explicitly calls for leveraging commercial and open-source AI technologies from diverse vendors, while establishing safety testing and supply chain assurance mechanisms. In the closed-source software and hardware era, the two goals — "use the best AI" and "reduce dependence on China" — could be partially separated by vendor blacklists. In the open-weight era, those two goals are on a collision course.

The Federal Register's brief use of Qwen followed by its quiet takedown is notable not as a one-off "gaffe" but as the first time regulators are forced to answer: does a Chinese open-weight model that has already been downloaded, copied, and deployed on U.S. servers still count as "Chinese technology" under law and regulation? There is no near-term answer. But as long as open-weight models continue to maintain the "public weights + locally deployable" characteristic, similar scenarios will become more frequent — and the next embarrassment may not be limited to a government regulatory search page.

Sources: Reuters original report (https://www.reuters.com/legal/litigation/us-government-website-used-ai-search-tool-china-that-fbi-said-copied-anthropic-2026-09-17/), Solidot Chinese reposting (https://www.solidot.org/story?sid=85417), Guancha.cn analysis (https://m.guancha.cn/GuoJi%C2%B7ZhanLue/2026_09_18_901121.shtml).