In brief: On 16 September, the Federal Register briefly offered and then removed a Qwen-powered search for public comments. This is not a demonstrated security incident: essential hosting, data-flow and approval details are missing. Model origin alone does not answer those questions.
What is confirmed — and what is not
Reuters found the option in screenshots and archived source code; its deployment date is unknown. The US National Archives-operated site took it offline around the time social-media posts appeared. Reuters said the National Archives and White House did not respond.
Qwen is an Alibaba model family. Its public Qwen3 weights can run on an organisation's infrastructure with Transformers, llama.cpp, Ollama, SGLang or vLLM. Using Qwen therefore does not automatically mean sending queries to Alibaba Cloud. Local inference does not prove the complete system was secure either.
Public evidence does not identify the model, hosting, logged queries or whether data crossed a US government security boundary. The processed public comments were not secret, but queries, usage metadata and logs can create additional information. Without architecture and log data, claims of exfiltration or Alibaba access are unsupported.
Pandorex Analysis
A useful review starts with the data path: local or external inference, network destinations, logging, retention and access. Next comes the model and runtime supply chain: provenance, version, checksum, dependencies and reproducible deployment. Geopolitical origin is an additional procurement and risk factor.
OMB memorandum M-25-21 requires US agencies to update IT, data, cybersecurity and privacy policies, establish generative-AI rules and maintain an AI-use inventory. Here, who approved, documented and monitored the search remains unresolved. NIST's draft GenAI extension to the Secure Software Development Framework treats model weights, pipelines and other components as artifacts to protect: local open-weight models still have a software supply chain.
The separate, disputed FBI allegation that Alibaba copied US models through distillation is not evidence of malicious code or a backdoor here. Removal shows a governance response. A prior technical compromise is currently not sufficiently supported.
