Congressional Investigations Monitor

Could Using Cheaper Chinese AI Lead to Costly Congressional Scrutiny? 

  • Two House committees are jointly investigating the national security, cybersecurity and economic security risks of U.S. companies adopting PRC-developed AI models.  
  • Anysphere (Cursor), Airbnb and DoorDash have already received congressional inquiry letters regarding their use of Chinese-developed AI. 
  • Companies may expect potential demands for document production, internal communications, cybersecurity assessments and in-person personnel briefings.  
  • Companies using PRC-based AI should assess data security, vendor contracts, customer disclosures and compliance documentation now.

On April 29, 2026, the House Committee on Homeland Security and the House Select Committee on the Chinese Communist Party announced a joint investigation “into the national security and cybersecurity risks posed by the growing adoption of PRC-developed artificial intelligence models.”

The Committees opened this investigation amid allegations and disclosures that PRC-based AI laboratories, including DeepSeek, Moonshot AI and MiniMax, used adversarial distillation and related techniques to extract proprietary capabilities from U.S. AI systems to train PRC-developed AI models. The investigation examines whether U.S. companies’ adoption of PRC-developed AI models, including both models accessed through APIs and self-hosted open-weight models, creates unacceptable risks in three domains:

  • National Security: whether PRC-based AI models enable data exfiltration, intelligence collection or the compromise of critical infrastructure;
  • Cybersecurity: whether models developed by entities subject to PRC law introduce exploitable vulnerabilities, backdoors or other supply-chain vulnerabilities; and
  • Economic Security: whether the rapid displacement of U.S.-developed AI by lower-cost PRC alternatives undermines domestic AI capabilities and creates strategic dependencies.

The Committees initially sent letters to Anysphere, Inc. (the developer of AI coding platform Cursor) and Airbnb. With respect to Anysphere, the Committees expressed concern that the company’s integration of PRC-based AI models — specifically, Kimi K2.5, an open-weight model developed by Moonshot AI — into its consumer-facing products raised serious national security and data-security concerns.

The Committees noted allegations that distillation took capabilities from U.S. frontier models, but not necessarily their guardrails against “being used to develop weapons, automate software vulnerability discovery and exploitation, generate tailored disinformation, or assist in the synthesis of dangerous chemical or biological agents.” The Committees also expressed concern about Anysphere’s failure to disclose Cursor’s alleged connection to Moonshot AI, particularly given Cursor’s significant market share, including more than half the Fortune 500 and more than 1 million active daily users. 

The Committees raised concerns about Airbnb’s reported use of the PRC-based Qwen model because of its conformance with Chinese regulatory requirements that generative AI content reflect “socialist core values,” and because the Committees warned that such a model may “covertly censor and manipulate information pursuant to Chinese law.” The Committees noted the obligation of PRC-based models to “support, assist, and cooperate with national intelligence work” under a 2017 National Intelligence Law. The Committees also referenced safety deficiencies of the Qwen model, stating that comparable PRC-developed models had complied with malicious prompts at a far greater degree than U.S.-based AI models.

The Committees made numerous, detailed information requests to Anysphere and Airbnb, tailored to the issues raised in each party’s letter, including internal deliberations about the implications of using PRC developed models; related data use and storage policies; agreements with model providers and third-party vendors; cybersecurity analyses; and communications, including among directors, about whether to publicly disclose the use of PRC-developed models.  The Committees also asked that “appropriate personnel” from each company appear for an in-person briefing by May 20, 2026. 

On July 31, 2026, the Committees sent a similar letter to DoorDash after DoorDash publicly acknowledged using an AI model developed by PRC-based Moonshot AI for lower-level work to cut AI-related costs. The Committees stated that U.S. companies may be attracted to PRC-developed open-weight models because they can offer competitive capabilities, lower costs, customization and alternatives to a small number of proprietary providers. The Committees nevertheless emphasized that those practical benefits “do not eliminate the need for risk-based safeguards” or diminish national security concerns associated with dependence on models developed by entities subject to PRC jurisdiction. The Committees’ letter references a July 22, 2026, statement by the White House Office of Science and Technology Policy director that the U.S. government has evidence that Moonshot AI may have operated a covert platform to conduct large-scale distillation against U.S. AI models and may have trained models using advanced systems it was not authorized to obtain.

The Committees also appeared to raise the challenge for companies that use PRC-developed AI models by requesting a briefing from “personnel with responsibility for DoorDash’s AI infrastructure, software security, model evaluation, procurement, and legal or compliance review appear for an in-person briefing no later than August 21, 2026.” The prior letters had sought briefings only from the “appropriate personnel,” which arguably offered more latitude in selecting briefers. 

Companies employing PRC-developed AI models, even in limited capacities, should consider a variety of issues including where and how data is stored and transmitted, cybersecurity assessments and plans, disclosures to customers and other stakeholders, vendor contracts and relationships, and documentation of compliance and legal reviews.

The risk of incorporating PRC-based AI models is particularly high for companies operating consumer-facing platforms in the United States that collect sensitive personal information. The congressional inquiries this summer suggest that any company incorporating PRC-based AI into its products should be aware of the risk of potential congressional scrutiny, which could include production of documents and data as well as possible on-the-record testimony. Publicly traded companies, in particular, should also consider the reputational and investor-relations implications of being identified as reliant on AI systems developed by entities connected to the Chinese military-industrial complex.

McGuireWoods continues to monitor these developments and their impact on businesses. For questions, contact the authors or a member of the McGuireWoods Congressional Investigations or Artificial Intelligence teams.

This alert is part of an ongoing series from the McGuireWoods Congressional Investigations team tracking the investigative and oversight priorities heading into a new Congress.

Subscribe