Key Takeaways
- The U.S. House Homeland Security and Select Committee on China have launched a joint probe into national‑security and cybersecurity risks posed by AI models developed in China, especially low‑cost, open‑weight, and API‑accessible systems such as DeepSeek, Alibaba’s Qwen, Moonshot AI’s Kimi, and MiniMax.
- Lawmakers allege that PRC‑based firms are conducting large‑scale, unauthorized model‑distillation campaigns to strip capabilities from leading U.S. frontier models and repackaging them without equivalent safety controls.
- Initial investigative letters were sent to Anysphere (maker of the Cursor AI‑coding assistant) and Airbnb, requesting detailed records on their use of Chinese‑origin models, model provenance, data‑flow practices, and compliance with U.S. security standards.
- The committees seek in‑person briefings from both companies by May 20 2026 and have set a May 13 2026 deadline for document production.
- The investigation reflects broader concerns highlighted in a White House OSTP memo, recent congressional hearings on PRC‑linked AI, robotics, and autonomous sensing, and warnings from the World Economic Forum about AI‑driven acceleration of cyber threats.
Background and Scope of the Investigation
The House Committee on Homeland Security, through its Subcommittee on Cybersecurity and Infrastructure Protection, and the House Select Committee on the Strategic Competition between the United States and the Chinese Communist Party have joined forces to examine how AI technologies originating from the People’s Republic of China (PRC) may threaten U.S. national security. Their focus is on low‑cost, open‑weight models and API‑accessible systems that are increasingly adopted by American developers and enterprises. The committees argue that these models, while offering performance and price advantages, may have been derived through illicit distillation of U.S. frontier AI systems, thereby bypassing the safety, security, and intellectual‑property safeguards built into the original models. By scrutinizing specific companies that integrate such PRC‑origin AI, the lawmakers aim to uncover whether the adoption of these systems creates supply‑chain vulnerabilities, data‑exposure risks, or enables hostile actors to weaponize advanced AI capabilities.
White House Memo and Model Distillation Concerns
In April 2026 the White House Office of Science and Technology Policy issued a memo warning that foreign actors—principally based in China—are conducting deliberate, industrial‑scale campaigns to distill U.S. frontier AI models. The memo described how adversaries use proxy accounts, coordinated networks, and evasion of access restrictions to extract model capabilities without authorization. While model distillation can be a legitimate technique for creating smaller, efficient models, the committees contend that when it is performed through fraudulent means, it strips away the rigorous security testing, guardrails, and ethical constraints that U.S. AI developers embed in their frontier systems. The resulting “stripped‑down” models may lack equivalent protections against misuse for weapon development, vulnerability discovery, disinformation generation, or synthesis of harmful chemical or biological agents, thereby posing a direct threat to U.S. security interests.
Letter to Anysphere (Cursor)
The committee chairs addressed their first letter to Anysphere, the company behind Cursor’s AI‑coding assistant, specifically highlighting the Cursor Composer 2 model. According to the letter, Composer 2 was reportedly built on an open‑weight model developed by Moonshot AI, a PRC‑based firm that has been publicly implicated in large‑scale distillation efforts targeting American AI systems. The lawmakers expressed concern that billions of dollars invested by U.S. firms in foundational research, compute infrastructure, and security engineering are being undercut by a low‑cost extraction campaign that repackages U.S. capabilities without comparable safeguards. They warned that such models, once disseminated, could be accessed by hostile state actors, terrorist organizations, or criminal enterprises seeking to exploit advanced AI for malicious purposes.
Security Implications and Requests to Anysphere
The letter also noted Cursor’s April 21 partnership with Chainguard, an open‑source security firm, which aims to steer AI‑generated code toward vetted open‑source components and reduce the risk of pulling vulnerable libraries into production. The committees framed this partnership as an acknowledgment by Cursor that agentic, “vibe‑coded” development can outpace human review, underscoring that the security of an AI coding environment depends not only on the model itself but also on the provenance and integrity of the packages, libraries, and container images it incorporates. In light of these risks, the committees requested detailed records from Anysphere, including any ties to Chinese AI firms (Moonshot AI, DeepSeek, MiniMax, Alibaba, Zhipu AI, ByteDance, Tencent, Baidu), licensing arrangements, technical collaborations, and financial relationships. They also asked for documentation on the use of Moonshot AI’s Kimi K2.5 model in Composer 2, alternative models considered, risk assessments, legal and security analyses, disclosure decisions, technical explanations of data flows, third‑party data‑handling agreements, security testing of integrated models, and steps taken to prevent data exposure to PRC‑linked systems. Finally, the committees asked for an in‑person briefing by May 20 2026.
Letter to Airbnb
A second letter was sent to Airbnb, focusing on the company’s reported use of Alibaba’s Qwen model in its customer‑service operations. The lawmakers cited Airbnb’s justification—Qwen’s “fast and cheap” performance—as a potential red flag, arguing that cost and performance decisions should not override national‑security considerations. They outlined three primary concerns: (1) ideological control and censorship embedded in Chinese AI systems under PRC law; (2) elevated safety vulnerabilities and higher failure rates in resisting malicious prompts compared with U.S.–developed models; and (3) data‑exposure risks when using API‑based foreign models that may be subject to Chinese legal obligations requiring cooperation with state authorities. The committees contended that these factors transform the adoption of PRC‑origin AI from a mere commercial choice into a structural national‑security risk, particularly given the potential for downstream misuse in commercial and public‑sector contexts.
Requests and Concerns Regarding Airbnb’s Use of Qwen
To substantiate their concerns, the committees demanded extensive documentation from Airbnb, including a comprehensive inventory of all Chinese‑developed models currently used, tested, or evaluated, along with details on deployment methods (API, self‑hosted, or third‑party) and any independent security testing of model weights prior to use. They also requested technical disclosures describing how user and corporate data flow to PRC‑linked model providers—covering infrastructure routes, server locations, and entities subject to Chinese jurisdiction. Additional requests included internal analyses comparing PRC and non‑PRC models, assessments of training‑data provenance and potential adversarial distillation, documentation of supply‑chain and model‑integrity audits, records of communications with Chinese AI providers, and logs of all Airbnb customer and employee data processed by these models over time. As with Anysphere, the committees asked for appropriate Airbnb personnel to appear for an in‑person briefing by May 20 2026.
Broader Context: Hearings, WEF Warning, and National‑Security Landscape
The investigative letters follow a March hearing held by the Subcommittee on Cybersecurity and Infrastructure Protection, which examined the growing national‑security and economic risks posed by AI, robotics, and autonomous sensing technologies developed by PRC‑linked companies. Witnesses testified that technologies originating from adversarial‑controlled ecosystems can create significant vulnerabilities, enable surveillance, expose sensitive data, and provide pathways to critical‑infrastructure systems. Adding urgency to the probe, the World Economic Forum recently warned that advanced AI systems such as Anthropic’s Mythos represent a turning point for cybersecurity: machines can now autonomously discover unknown vulnerabilities, generate exploits, and execute complex attack chains with minimal human input. This development collapses the traditional defender‑attacker gap, accelerating both threat discovery and weaponization while suggesting that existing security models may be ill‑equipped to manage the speed and scale of AI‑driven cyber risk.
Conclusion and Next Steps
The joint House investigation underscores a growing bipartisan apprehension that the United States’ technological edge in AI is being eroded through unauthorized extraction and repackaging of its frontier models by PRC‑based actors. By targeting specific adopters—Anysphere’s Cursor and Airbnb—the committees aim to illuminate how Chinese‑origin AI infiltrates critical sectors such as software development and consumer services, and to evaluate whether adequate safeguards are in place to protect intellectual property, data integrity, and national security. The requested documentation and impending briefings will provide lawmakers with a clearer picture of the extent of model‑distillation practices, the robustness of corporate due‑diligence processes, and the potential need for tighter export‑control, licensing, or procurement policies. Should the investigation substantiate claims of illicit distillation and insufficient safeguards, it could prompt legislative action, stricter vetting of AI supply chains, and heightened scrutiny of foreign‑sourced AI technologies across the U.S. economy.

