US Scrutiny of Chinese Model Use
- title
- US Scrutiny of Chinese Model Use
- type
- analysis
- summary
- House probes of Airbnb, Cursor and DoorDash over Chinese AI models, set against Western companies moving to Chinese open weights to cut costs
- tags
- ai, open-weights, china, policy, geopolitics, enterprise
- sources
- house-probes-airbnb-cursor-chinese-ai, doordash-chinese-ai-models-lawmakers, thomson-reuters-thomson-1-model
- created
- 2026-09-14
- updated
- 2026-09-14
Nathan Lambert's open-source-ai-reading-list has a short section saying that "prominent uses of Chinese models by Western companies have prompted meaningful regulatory attention." It points in two directions. Lawmakers have questioned companies for using Chinese models. Other Western companies have publicly moved from American closed models to Chinese open ones to save money. This page combines the three news reports that could be fetched, a Semafor exclusive (April 2026), a CNBC report (July 2026) and a Business Insider piece (August 2026), with the executive-branch measures Lambert quotes in kimi-k3-open-weights-escalation. Three other links on the list were blocked by paywalls or bot checks and were not read. Wherever they are mentioned below, the only information comes from Lambert's one-line description.
Timeline
| Date | What happened | Source |
|---|---|---|
| 2025-01-28 | Perplexity adopts DeepSeek R1 in its search product | Forbes, not read |
| 2025-05-17 | Trump administration reported concerned about a deal to put Alibaba's AI in iPhones | Reuters citing NYT, not read |
| 2026-03 | Anysphere releases Composer 2, later disclosed as built on Moonshot's Kimi | Semafor |
| 2026-04-29 | Two House committees send letters to Airbnb and Anysphere | Semafor; Bloomberg, not read |
| 2026-07-20 | Axios reports executive-branch measures considered against Chinese labs | quoted in Lambert's K3 essay |
| 2026-07-31 | Same committees request information from DoorDash | CNBC |
| 2026-08-24 | Thomson Reuters launches Thomson-1, built on a realigned Qwen | Business Insider |
The House investigation
The inquiry is a joint investigation by the House Committee on Homeland Security, chaired by Andrew Garbarino (R-NY), and the House Select Committee on the Chinese Communist Party, chaired by John Moolenaar (R-MI). Its first step, reported by Semafor on April 29, was letters to the CEOs of Airbnb and Anysphere, the company behind Cursor. The letters asked which Chinese models the companies used, why they chose them, and what communications they had with the Chinese model providers. They also asked the employees involved in those decisions to attend an in-person briefing.
Both companies had said publicly what they used. Anysphere had released Composer 2 the previous month, claiming it performed comparably to top OpenAI and Anthropic models at a fraction of the cost, and its technical report later disclosed that the model was built on Kimi. (The HN discussion on swe-1-7 notes that Cursor's Composer 2.5 was also RL-trained from a Kimi base.) Airbnb had built its customer-service agent on Alibaba's Qwen, which Brian Chesky had called "fast and cheap." Moolenaar's statement to Semafor was that these models "are trained by China's censorship regime and introduce hidden vulnerabilities that put Americans' data and businesses at risk." Semafor described the committees' concern as the national-security risk of sharing large amounts of data with Chinese AI companies.
The Bloomberg report on the same letters is on the reading list at https://www.bloomberg.com/news/articles/2026-04-29/us-house-probes-airbnb-anysphere-s-use-of-chinese-ai-models. It was not read.
The DoorDash letter, reported by CNBC on July 31, was the next step. It cited a post on X by DoorDash co-founder Andy Fang describing how the company sends lower-level AI work to Moonshot's Kimi K2.6. DoorDash's AI research lab had separately posted that Kimi K2.6 and Anthropic's Fable 5 far outperformed the Anthropic models it had used before, "Sonnet 4.6 and Opus 4.8 harness at a cheaper cost." DoorDash's reply mentioned "American-developed frontier models and open-weight models" without saying where those open-weight models came from.
The letter itself is more measured than Moolenaar's statement. It acknowledges why companies make this choice:
The Committees recognize that U.S. companies, from large technology firms to startups, may evaluate and deploy PRC-developed open-weight models because they can provide competitive capabilities, lower costs, greater customization, and alternatives to reliance on a small number of proprietary model providers.
It says those considerations "do not eliminate the need for risk-based safeguards," and its recommendation has two parts: examine how much US companies rely on Chinese models, and "strengthen the availability, security, and competitiveness of American open-weight alternatives." A committee aide told CNBC that the committees were also examining whether the US has an adequate open-weight strategy, so that American companies and cyber defenders are not "forced to choose between expensive or restricted U.S. models and cheap, capable PRC-developed alternatives." Garbarino framed the issue around cyber capability, calling reports that a Chinese open-weight model could match leading US models at vulnerability discovery "highly alarming."
CNBC adds that some government departments have banned Chinese models such as DeepSeek, but US companies are not prohibited from using them. Tech executives including Coinbase's Brian Armstrong and Lindy's Flo Crivello had publicly promoted Chinese models as a way to cut costs. The report also says the rogue OpenAI-model attack on Hugging Face was stopped using "a Chinese system." Emad Mostaque, on mostaque-internet-offline, names that model as GLM, and openai-huggingface-incident-autonomous-hacking covers the incident.
The executive branch
Congress was not the only part of government looking at this. In his July essay on Kimi K3, Lambert quotes an Axios report on measures the administration had considered in 2025. They included adding Chinese AI labs to the Commerce Department's Entity List, a joint NSA and National Cyber Director advisory that would effectively discourage companies from using Chinese models, an executive order allowing US companies to host Chinese models only if they guaranteed security and accepted liability for breaches, and draft Commerce supply-chain rules aimed at Chinese open-source models. None of these is reported as adopted.
The earliest case on the list is from the same administration. Reuters reported on May 17, 2025, citing the New York Times, that the Trump administration was concerned about a deal to put Alibaba's AI into iPhones: https://www.reuters.com/world/china/trump-administration-is-concerned-by-deal-put-alibabas-ai-iphones-nyt-reports-2025-05-17/. It was not read, so this page can say nothing beyond the headline.
Switching to cut costs
The reading list's other example is companies moving openly in the opposite direction. Its earliest case is Perplexity, which "prominently and rapidly adopted DeepSeek R1" in January 2025, per Forbes at https://www.forbes.com/sites/luisromero/2025/01/28/deepseek-now-in-perplexitys-ai-search-us-ai-dominance-challenged/. That article was not read either.
The best-documented case is Thomson Reuters. On August 24, 2026 it launched its first AI model, Thomson-1. CTO Joel Hron told Business Insider that Thomson-1 is based on Snowdon, a model built by "realigning" an open-source Qwen model. A joint team from Thomson Reuters and Imperial College London spent several months on the adaptation, and Hron said the result was "ethically and politically de-biased and safe to use." Thomson-1 will take over some tasks Claude used to handle, beginning with document review. It is not meant to replace Anthropic. Thomson Reuters had expanded its Anthropic partnership for the CoCounsel legal assistant in May, and CoCounsel still relies mostly on Claude. Hron's stated goal is for Thomson to power more and more of CoCounsel over time. His reasons were cost and building on the company's own expertise. He compared it to renting versus buying a house: renting keeps a roof over your head, "but you're not building any equity that compounds into something valuable for you long term." He also said "there's nothing that necessarily ties us to Qwen."
The same article records the pushback. Anthropic has said Chinese labs are illicitly distilling its models and has asked for US restrictions (anthropic-threat-report-september-2026 is the later, detailed version). Senator Tom Cotton has raised concerns about Airbnb and Cursor using Chinese open-source models, citing possible backdoors. Airbnb told Business Insider that it overwhelmingly uses US models, and that the few Chinese models it uses are open-source and run through US cloud providers.
Reading the two directions together
The investigators and the adopters are describing the same trade-off. The DoorDash letter lists capability, cost, customization and less dependence on a few providers as reasons to use Chinese open weights. Hron's rent-versus-buy argument is a version of the customization and dependence points, and DoorDash's lab post is about capability per dollar. The committees do not deny any of this. Their proposed remedy, better American open-weight alternatives, is the same argument Lambert makes in atom-project-american-truly-open-models.
The two concerns in the record also fit these cases unevenly. Semafor describes the fear as data flowing to Chinese companies. That applies to calling a Chinese company's API, but not to open weights run on American infrastructure, which is how Airbnb says it uses Qwen, how Cursor uses Kimi inside its own model, and how Thomson Reuters built Thomson-1. For those cases the remaining concern is what the weights contain, which is Moolenaar's censorship and hidden-vulnerabilities point and Cotton's backdoor point. arguments-against-open-source-ai argues that this concern has no obvious limit: is a model still Chinese after an American company fine-tunes it? Composer 2 and Thomson-1 are exactly that case, and Thomson Reuters' account (a de-biasing pass, a new name for the intermediate model, and a statement that nothing ties it to Qwen) reads as if written with that question in mind.
"Restricted" in the aide's comment is not rhetoric. In June 2026 the US imposed an export restriction on Claude Fable 5 that Lambert calls an effective ban (glm-5-2-step-change-for-open-agents), and Lambert's Kimi K3 essay makes the same asymmetry point from the other side. Guardrailed American models alongside unrestricted Chinese open weights leave defenders worse equipped than attackers. The committee aide and Lambert see the same imbalance and want different fixes. The committees want to scrutinize reliance on Chinese models. Lambert wants to avoid restricting open models at all.
The probes also select their targets in a particular way. Every company named so far had described its own use in public: a founder's post on X, a CEO quote, a technical report. An investigation that works from public disclosures gives other companies a reason to stay quiet rather than to stop. The sources do not report any outcome from the letters, any company's actual briefing, or whether any use of Chinese models was changed as a result.
Related
glm-5-3-how-chinese-labs-keep-stride explains why the models companies are switching to keep getting better. six-months-to-live-for-open-models is Lambert's argument that vague federal oversight is heading toward a ban. telnyx and CrofAI are examples of the US-hosted providers that make Airbnb-style use possible: catalogs made entirely of Chinese open-weight models.
- Nathan Lambert on China's AI Ecosystem and the Open Model Gap
- The Arguments Against Open Source AI are Very Bad
- From Open Source Software to Open Source Strategy
- GLM-5.2 is the step change for open agents
- Kimi K3: The open-weights escalation
- LLM Distillation
- Open-Source AI & Open Models Reading List
- 6 months to live for open models
- SWE-1.7 — Cognition's Coding Model
- Z.ai (Zhipu AI)