ai-cybersecuritytrade-pressNewsThe Broadside3 min read

House probes DoorDash over Chinese AI model in code review

The investigation moves from theory to named production systems, with Moonshot AI's alleged covert distillation and military investor ties sharpening the risk calculus.


TL;DR

House Homeland Security Chair Garbarino and China select committee Chair Moolenaar sent a July 31 letter to DoorDash CEO Tony Xu demanding internal documents on the company's use of Moonshot AI's Kimi K2.6 in an AI-assisted code review system. The request follows a White House OSTP statement that Moonshot operated a covert distillation platform against American models and trained on unauthorized GB300 hardware. Alibaba, a Defense Department-designated Chinese military company, is a Moonshot investor. Lawmakers want a full inventory of PRC-developed models DoorDash has evaluated or deployed since January 2025, plus DashBench methodology, risk assessments, and decision records. Responses are due August 14, with a briefing by August 21.

The joint investigation by the House Homeland Security and China select committees has now named a specific model deployed in a specific production workflow at a specific company. That's a shift from the investigation's April launch, when letters to Anysphere and Airbnb framed the inquiry around the general risk profile of Chinese-developed open-weight models. The DoorDash letter puts Kimi K2.6 (inside a code review pipeline that touches DoorDash's secure development environment) at the center of the inquiry.

The distillation allegation changes the threat model

Open-weight models from Chinese developers have been debated primarily on two axes: performance-per-dollar competitiveness and the risk that model weights could harbor backdoors or censorship logic. The White House OSTP statement on July 22 introduced a materially different concern: Moonshot allegedly operated a covert platform for "industrial scale" distillation of American frontier models, used Anthropic's Fable model in developing Kimi K3, and trained on GB300 systems it wasn't authorized to obtain. Treasury separately flagged possible sanctions or trade restrictions.

If the distillation allegation holds, the lineage question isn't just "did a Chinese lab train this model?", it's "was this model produced by extracting capabilities from an American model in violation of terms of service and export controls, on hardware obtained illicitly?" That's a sharper liability surface than the standard open-weight adoption debate, and it directly implicates downstream users who integrated the resulting model into production systems.

The Alibaba connection isn't theoretical either

The Defense Department designated Alibaba Group a Chinese military company on June 8. Alibaba is an investor in Moonshot AI. The lawmakers' letter is careful to note that the designation "does not itself establish that Moonshot's models are compromised or prohibit private sector use," but it does make Alibaba's financing relationship relevant to a supply-chain risk assessment. For a contractor like DoorDash (which holds government contracts and operates in the defense-industrial supply chain) the military-company designation on an investor creates a due-diligence question that didn't exist when the model was first evaluated.

What DoorDash has to produce, and what it means for everyone else

The document request is extensive and specific: a complete inventory of every PRC-developed model evaluated or used since January 2025; DashBench methodology, test sets, scoring criteria, and validation results for the Kimi K2.6 configuration; all risk assessments, decision memoranda, and approval materials; policies governing third-party AI model acquisition; and any assessment conducted after learning of the distillation allegations, including who decided whether to continue using the model.

That requests-list doubles as a compliance template. Any company using or evaluating Chinese-developed open-weight models in development workflows should read it as the minimum set of documents counsel will want ready if (and increasingly when) a similar inquiry arrives. The August 14 document deadline and August 21 briefing requirement also set a pace that suggests the committees aren't treating this as an exploratory fishing expedition.

The open question is enforcement: whether the White House will impose sanctions or trade restrictions on Moonshot or its investors, and whether DoorDash (or any other user of Moonshot models) will be required to cease use. For now, the letter doesn't demand cessation. It demands answers. But the direction of travel is clear enough that compliance teams evaluating Chinese-origin AI models should treat the DoorDash letter as precedent-setting, not anomalous.


Published ·Updated ·Deep Fathom

House probes DoorDash over Chinese AI model in code review — The Broadside