US government website used Chinese model the FBI called "malicious"

US government website used Chinese model the FBI called “malicious”

美国政府网站使用了被 FBI 称为“恶意”的中国模型

On Wednesday, US government officials removed a Chinese AI search tool that was briefly deployed on the Federal Register website, Reuters reported. The change came after social media users noticed an apparent contradiction: The National Archives was using one of Alibaba’s Qwen AI models, even as top US law enforcement claimed that such models illegally copy US frontier models.

据路透社报道,周三,美国政府官员下架了一款曾短暂部署在《联邦公报》(Federal Register)网站上的中国 AI 搜索工具。此前,社交媒体用户注意到了一个明显的矛盾:美国国家档案馆(National Archives)竟然在使用阿里巴巴的通义千问(Qwen)AI 模型,而与此同时,美国最高执法机构却声称此类模型非法复制了美国的尖端模型。

Earlier this month, the Federal Bureau of Investigation (FBI) named Alibaba among six leading Chinese firms allegedly conducting “industrial-scale distillation” that the agency says is helping America’s biggest competitor cut costs and development time in the race for global AI leadership.

本月早些时候,美国联邦调查局(FBI)将阿里巴巴列为六家涉嫌进行“工业级蒸馏”(industrial-scale distillation)的中国领先企业之一。FBI 称,这种行为正在帮助美国最大的竞争对手在争夺全球 AI 领导地位的竞赛中降低成本并缩短开发时间。

It’s unclear when exactly the National Archives, which runs the Federal Register website, began offering visitors the option to use a Qwen model to search public comments on proposed regulations. So far, the independent agency tasked with increasing public access to federal government documents has not commented on the removal and did not respond to Ars’ request for comment. The White House and the FBI have also not commented.

目前尚不清楚负责运营《联邦公报》网站的国家档案馆究竟是从何时开始为访问者提供使用通义千问模型来搜索拟议法规公众评论选项的。截至目前,这个负责增加公众获取联邦政府文件渠道的独立机构尚未就下架一事发表评论,也未回应 Ars 的置评请求。白宫和 FBI 也未对此置评。

On X, a user with the handle “tleilax___” posted a widely shared screenshot showing the option displayed on the government website on September 15. Reuters’ report noted that an archived version of the site’s source code confirmed that the Qwen model was taken down on Wednesday, so the service was available for at least a day.

在 X(原推特)上,一位名为“tleilax___”的用户发布了一张被广泛转发的截图,显示该选项于 9 月 15 日出现在政府网站上。路透社的报道指出,该网站源代码的存档版本证实,通义千问模型于周三被下架,这意味着该服务至少在线运行了一天。

Daniel Castro, president of the Information Technology and Innovation Foundation, told Reuters that it is an “insane” disconnect for a US agency to use an Alibaba model while the FBI encourages stakeholders to use only American models.

信息技术与创新基金会(Information Technology and Innovation Foundation)主席丹尼尔·卡斯特罗(Daniel Castro)告诉路透社,美国机构在使用阿里巴巴模型的同时,FBI 却鼓励利益相关者仅使用美国模型,这种脱节是“疯狂的”。

Use probably posed no security risks

使用可能并未构成安全风险

Whether the government use of the Qwen model posed a security risk depends on how it was trained, Georgetown University Law Professor Anupam Chander told Reuters. It also matters if any US data was processed by “Alibaba-controlled systems,” Senator Marker Warner (D-Va.) said.

乔治城大学法学教授阿努帕姆·钱德(Anupam Chander)告诉路透社,政府使用通义千问模型是否构成安全风险,取决于该模型的训练方式。参议员马克·华纳(Mark Warner,民主党籍,弗吉尼亚州)表示,是否有任何美国数据被“阿里巴巴控制的系统”处理也很关键。

However, although the FBI suggested that using Chinese models could create national security concerns by locking in the US government’s reliance on Chinese technology, experts told Reuters that it’s unlikely the Qwen model’s deployment on the Federal Register site posed any substantial risks. Chander noted that the site’s content is “already public, so the model was not working with sensitive government information.”

然而,尽管 FBI 暗示使用中国模型可能会因锁定美国政府对中国技术的依赖而引发国家安全担忧,但专家告诉路透社,通义千问模型在《联邦公报》网站上的部署不太可能构成任何实质性风险。钱德指出,该网站的内容“已经是公开的,因此该模型并未处理敏感的政府信息。”

In a report discussing the particular model used in greater depth, the Chinese news site Sina.com explained that the Federal Register used a small open-weight model of “Qwen3 0.6B level,” which is not Alibaba’s largest flagship model. That model is open source, serves solely to retrieve documents, and does not provide complex reasoning or send government data to Alibaba or any third parties.

中国新闻网站新浪网在深入探讨该特定模型的报道中解释称,《联邦公报》使用的是“Qwen3 0.6B 级别”的小型开放权重模型,这并非阿里巴巴最大的旗舰模型。该模型是开源的,仅用于检索文档,不提供复杂的推理功能,也不会将政府数据发送给阿里巴巴或任何第三方。

For US agencies, the Qwen search tool gives the government more control over data because the models can be downloaded and run locally rather than requiring queries to be sent to larger models run externally, security experts told Reuters. The ability to avoid sharing sensitive data is partly why it has become a “default” AI search tool, Sina.com reported, along with its lower, more predictable pricing.

安全专家告诉路透社,对于美国机构而言,通义千问搜索工具赋予了政府对数据更多的控制权,因为这些模型可以下载并在本地运行,而无需将查询发送到外部运行的大型模型。新浪网报道称,能够避免共享敏感数据是它成为“默认”AI 搜索工具的部分原因,此外还有其更低、更可预测的定价。

These models could arguably not even be considered Chinese services once a business takes control of them, Sina.com’s report suggested. But the US has only recently started grappling with whether AI models that originate in China but are controlled by American institutions should face the same restrictions as other Chinese services considered higher security risks.

新浪网的报道指出,一旦企业接管了这些模型,它们甚至可以说不再被视为中国服务。但美国最近才开始着手处理一个问题:即源自中国但由美国机构控制的 AI 模型,是否应该面临与其他被认为具有更高安全风险的中国服务相同的限制。

Lawmaker: US should never use Chinese models

立法者:美国绝不应使用中国模型

Reuters noted that the Federal Register scandal comes “amid a global reckoning about AI safety and a US debate over whether regulatory safeguards on AI are needed or would put the country at a competitive disadvantage.” Many business owners who increasingly rely on open source models have urged the Trump administration not to restrict access to Chinese models. And China, which has dismissed accusations of frontier model copying, has called on the US to listen to its business community or else risk putting the US at a further economic disadvantage.

路透社指出,《联邦公报》事件发生时,“全球正处于对 AI 安全的重新审视之中,美国国内也在争论是否需要对 AI 进行监管保障,或者这样做是否会使国家处于竞争劣势。”许多越来越依赖开源模型的企业主敦促特朗普政府不要限制对中国模型的访问。而中国在驳斥有关复制尖端模型的指控的同时,也呼吁美国倾听其商业界的意见,否则可能会使美国在经济上处于进一步的劣势。

Policy research conducted for Congress and submitted to the US-China Economic and Security Review Commission in March suggested that the US may already be at a disadvantage because it focused too heavily on maintaining a lead in frontier AI while failing to advance its own open source ecosystem. In the meantime, China recognized this gap and moved to fill it.

今年 3 月为国会进行并提交给美中经济与安全审查委员会(USCC)的政策研究表明,美国可能已经处于劣势,因为它过于专注于保持在尖端 AI 领域的领先地位,却未能推进自己的开源生态系统。与此同时,中国意识到了这一差距并采取行动填补了它。

As researchers explained: US export controls are calibrated to constrain frontier training by restricting access to advanced semiconductors. They do not address the small-model deployment cycle, which requires less advanced compute, draws on openly available base models, and generates advantage through application rather than pre-training. If the models that matter most for industrial AI are small, specialized, and open, the current US policy framework could be targeting the wrong layer of the competition.

正如研究人员所解释的那样:美国的出口管制旨在通过限制先进半导体的获取来约束尖端模型的训练。它们并未解决小型模型的部署周期问题,因为小型模型对计算能力要求较低,利用公开的基础模型,并通过应用而非预训练来产生优势。如果对工业 AI 最重要的模型是小型、专业且开放的,那么当前的美国政策框架可能瞄准了竞争中错误的层面。

Companies like Nvidia and Meta have vowed to help the US catch up. Researchers have warned that if the US loses a broad user base to China, it could set back America’s “ability to set the technical standards and norms that will govern AI development for years to come.” And that loss of global leadership could harm national security and the US economy, some in Congress fear.

英伟达(Nvidia)和 Meta 等公司已承诺帮助美国追赶。研究人员警告称,如果美国失去广泛的用户群而转向中国,可能会阻碍美国“制定未来几年主导 AI 发展的技术标准和规范的能力”。国会中的一些人担心,这种全球领导地位的丧失可能会损害国家安全和美国经济。

US Rep. John Moolenaar (R-Mich.), who chairs the House China Committee, has taken a hard stance, maintaining that “no federal government entity should use a Chinese AI model,” Reuters reported. “Doing so only makes the federal government more dependent on Chinese AI models, and that is not in the [US interest].”

据路透社报道,众议院中国问题特别委员会主席、美国众议员约翰·穆勒纳尔(John Moolenaar,共和党籍,密歇根州)采取了强硬立场,坚持认为“任何联邦政府实体都不应使用中国 AI 模型”。他表示:“这样做只会让联邦政府更加依赖中国 AI 模型,这不符合[美国的利益]。”