One of the most important regulatory public websites of the U.S. government, Alibaba’s Qwen model was recently discovered to provide AI search capabilities, then withdrawn after triggering security and procurement disputes. Reuters on September 17, that the Federal Register website operated by the U.S. National Archives and Records Administration, at least on September 16, had provided Qwen-based search options to help the public retrieve government documents such as proposed regulations.

原始来源 · reuters.comReuters:美国政府网站一度使用阿里Qwen搜索reuters.com ↗

The Federal Register has released public regulations, proposed rules, announcements and presidential documents, but a model developed by a Chinese company enters the U.S. government’s public information system, coinciding with Washington’s intensifying national security scrutiny of Chinese AI and chips on the one hand, and its preparation to discuss AI security with Beijing on the other hand, making the rapid deployment of small-scale technology a policy symbol.

原始来源 · archives.gov美国国家档案馆:Federal Register介绍archives.gov ↗

Disappears soon after the tool appears, and the deployment process remains opaque

According to Reuters’ website screens and archive source code, the Qwen search function was available on September 16 and was then withdrawn at the same time the feature began to be discussed on social media. It is unclear when it was launched, whether it was deployed by the national archive’s internal teams or external contractors, the model was running in the local U.S. infrastructure or called external services.

These technical details determine the nature of the risk. If only the open weight model is downloaded and run locally on servers controlled by the U.S. government, the data does not need to be sent to Alibaba; if it is called through an external API, it is necessary to further evaluate whether search queries and metadata leave the government system.

In the privacy statement of other AI search tools, the U.S. National Archives emphasizes that AI search results are not guaranteed complete or accurate, and users should look back at the original profile verification, while stating that the query information will be stored anonymously.

2026年新加坡千问大会阿里云AI展区资料图。|来源:阿里云
2026年新加坡千问大会阿里云AI展区资料图。|来源:阿里云
原始来源 · archives.gov美国国家档案馆AI搜索隐私与使用说明archives.gov ↗

The controversy arose against the backdrop of the US government’s strict defense of Chinese technology.

The incident triggered a rapid political reaction, related to the U.S. government's security policy on China's technology supply chain in recent years. The U.S. has restricted the export of some advanced chips to China, and continues to conduct supply chain review in areas such as telecommunications, drones, connected cars and AI. The U.S. Federal Bureau of Investigation has previously accused Chinese companies of mass acquisition or imitation of U.S. AI technology; Alibaba has denied the allegations of related "replicating Anthropic technology".

John Moolenaar, chairman of the U.S.-China Strategic Competition Special Committee of the U.S. House of Representatives, criticized the government’s website’s use of Qwen, arguing that federal agencies should not deploy Chinese AI models in the absence of security censorship. Technical policy researchers also pointed out that the Federal Register is dealing with public data, and if the model runs entirely locally, the risk of direct data breach may be limited.

These two views are not contradictory: a specific deployment can be detected without the actual leakage, while still exposing the unclear processes of government procurement and AI supply chain management.The key is not the label “from which country” of the model itself, but whether the government knows the model’s code source, weighted version, run location, data flow, update mechanism and third-party dependence.

Open-source models disperse the traditional “supplier” concept

Qwen is widely used in the global developer community due to its open weight and lower deployment costs. Unlike a closed model that can only be accessed through a company’s cloud API, the open weight model can be downloaded and run on its own servers by the organization, or re-packaged, fine-tuned and integrated by third parties.

美国Federal Register网站界面资料图。|来源:PageCrawl
美国Federal Register网站界面资料图。|来源:PageCrawl

This architecture brings new problems to government security scrutiny. Past scrutiny of a software product often identifies clear suppliers, licensing contracts and updating channels; while an open AI model may be re-released several times, and the actual code, weights, reasoning frameworks and plugins come from different subjects. Just forbidding the networking with the original development company can not automatically solve the problem of model integrity, backdoors, reliance on libraries and updating sources.

In turn, open weights also provide a security advantage: the government can deploy locally without transferring data to the original plant, and test the models independently.

China and the United States are about to talk about AI security, this insert provides a real-life sample

U.S. Treasury Secretary Bessent will meet with Chinese State Department Deputy Prime Minister Ho Chi Minh in New York this weekend on topics such as AI security, open-weight models, trade and rare earth.

原始来源 · reuters.comReuters:中美将讨论AI安全与开放权重模型reuters.com ↗

The Federal Register’s Qwen plot turns abstract policy debates into a concrete question: Should the U.S. government completely exclude Chinese models from the global technology ecosystem because of cost and performance, or establish unified model sources, data flow and security assessment rules?

For the public sector, more verifiable criteria include whether the model weighs the source can be tracked, whether the operating environment is isolated, whether all queries remain in the government control system, whether the model is allowed to network, whether auditing logs are kept, upgrades approved by who, and whether it can be restored to traditional searches after an error occurs.

Withdrawn is a search option, exposed is a gap in procurement governance

The Federal Register is administered by the U.S. National Archives’ Federal Gazette Office and is one of the official systems for the federal government to issue regulations, announcements and presidential documents on a daily basis. Its core value lies in openness and traceability.

There is currently no public evidence that Qwen has altered, generated or altered any formal regulatory content, nor is there evidence that sensitive government data has been accessed by Alibaba.

But it does show that open-source AI spreads faster than many government agencies have established unified procurement and security standards.A model can spread rapidly in the developer community and then enter government websites through contractors, open-source components or experimental features, and the decision chain may not be as clear as traditional large-scale IT procurement.

After Qwen’s search was dropped, it was really worth tracking whether the U.S. National Archives published the deployment sources, data architectures, and approval processes, and whether the federal government thus established transparent security standards for all AI models, not just for a particular Chinese brand.

MEMBER DISCUSSION

Article discussion

Verified members can discuss this report publicly and manage their own content.