The Federal Register Qwen search option is gone. Reuters reported that the National Archives-run website briefly offered Alibaba’s Qwen model as one way to browse public comments on proposed federal regulations, then removed the option on September 17 as posts about it appeared on social media.
The removal left basic operational questions unanswered. Reuters reviewed screenshots and an archived version of the site’s code showing that Qwen had been taken down, but reported that it was unclear when the feature was added. The National Archives and the White House did not respond to Reuters’ requests for comment; the FBI declined comment.
The awkward part is timing and policy, not evidence that this particular search feature was itself malicious. Nine days before the removal, the FBI, CISA and NSA issued a joint advisory alleging that Alibaba and five other China-based companies had carried out high-volume, industrial-scale knowledge-distillation campaigns against U.S. AI companies. The agencies alleged Alibaba used the activity to improve its Qwen model family.
That advisory said distillation is a recognized, legitimate and useful AI-research technique, while alleging the firms’ activity was aggressive, malicious and targeted. It said the companies allegedly used routes including APIs, cloud providers, third-party aggregators and proxy networks, and allegedly violated U.S. AI companies’ terms of use and geographic restrictions.
Did the Federal Register Qwen search create a security risk?
There is no public evidence in the reporting that the Federal Register deployment created an immediate cybersecurity problem. Qwen is an open-weight model, meaning key components are available for developers to download and alter for a particular job. Such models can run on an organization’s own infrastructure rather than requiring every query to go to an outside provider.
Georgetown Law professor Anupam Chander told Reuters that the tool did not appear to pose an immediate risk, with an important qualification: the answer depends on how the model was trained. The material it searched was public, he noted, rather than sensitive government information.
Sen. Mark Warner, the Virginia Democrat who is vice chair of the Senate Intelligence Committee, identified the more concrete unanswered question: whether U.S. data crossed the government’s security boundary and was processed by systems controlled by Alibaba. Reuters’ reporting does not establish the tool’s hosting arrangement or its data flows.
The episode nevertheless exposed a gap between Washington’s warnings about Chinese AI development and the practical appeal of downloadable models for narrow tasks. Daniel Castro, president of the Information Technology and Innovation Foundation, told Reuters the agency’s use of a Chinese-made model clashed with the broader U.S.-China contest over AI.
Rep. John Moolenaar, the Michigan Republican who chairs the House China Committee, took the categorical position that no federal entity should use a Chinese AI model. He said such use could make the federal government more dependent on Chinese AI models. That is a policy view, not an explanation for why the National Archives removed this search option.
For now, the public record supports a narrower conclusion: a government website used an Alibaba-origin model to search public regulatory comments, then withdrew it after online attention. Who approved it, how long it ran and whether it communicated with Alibaba-controlled systems remain unresolved.
This story draws on original reporting from Ars Technica.