WASHINGTON, October 1, 2026 — U.S. Representative Ro Khanna, the ranking Democrat on the House Select Committee on China, has sought information from some of America's largest artificial intelligence companies about attempts by China or other hostile actors to obtain unauthorized access to their closely guarded AI model weights.
The requests were directed to OpenAI, Anthropic, Google, Meta and xAI. Khanna also asked the companies for details about the cybersecurity protections they use to prevent their most sensitive AI technology from being stolen or accessed illegally.
The move highlights a growing concern in Washington: as increasingly capable AI systems become strategically important, protecting the technology behind those systems is becoming a national-security issue alongside the traditional competition over advanced semiconductors, computing infrastructure and technical talent.
What Are AI Model Weights — and Why Do They Matter?
Model weights are the numerical parameters created during the training of an artificial intelligence model. They play a central role in determining how a trained model processes information and generates responses.
For frontier AI developers, the weights of their most advanced proprietary models can therefore represent one of their most valuable technological assets.
Congressional testimony earlier this year described model weights as a particularly significant security concern because possession of stolen weights could potentially allow another party to reproduce and deploy important capabilities of an advanced model without bearing the original cost of training it.
That makes protecting model weights different from simply preventing unauthorized access to an AI chatbot or API. A compromise involving the underlying weights could potentially expose far more of the model's capabilities.
Khanna Asks Companies to Disclose Attempted or Successful Access
According to Reuters, Khanna requested information about known attempts by China or other hostile actors to illegally obtain access to model weights held by the five companies. He also sought information about the cybersecurity measures being used to defend them.
Khanna argued in the letters that the consequences could extend beyond individual companies because a relatively small number of private technology firms now control some of the world's most capable AI systems.
His request does not itself establish that Chinese actors have successfully stolen the model weights of these companies.
Reuters reported that there are currently few publicly known cases of malicious actors actually stealing the weights of major frontier AI models.
That distinction is important when assessing the security concern raised by the lawmaker.
Model Distillation Is Not the Same as Stealing Model Weights
The congressional inquiry comes against a backdrop of separate disputes involving model distillation.
OpenAI and Anthropic have previously reported instances in which Chinese AI developers, including companies such as Moonshot AI and DeepSeek, allegedly used outputs from leading Western AI systems to help train or improve their own models.
Distillation broadly involves training one AI system using information generated by another model. Depending on how it is conducted, companies may argue that such activity violates their terms or improperly extracts capabilities.
But accessing outputs from a model and obtaining the model's underlying weights are technically different events.
The current inquiry is specifically significant because it focuses on whether hostile actors have attempted to penetrate the security surrounding the underlying parameters of advanced U.S. models.
AI Cybersecurity Becomes Part of the US-China Technology Competition
The issue fits into a wider congressional examination of artificial intelligence and China.
Earlier in 2026, House committees opened an investigation into security risks associated with U.S. companies using Chinese-developed open-weight AI systems, including models associated with DeepSeek, Alibaba, Moonshot AI and MiniMax. The committees said their investigation would examine cybersecurity, national-security and economic-security implications.
Other lawmakers have separately raised concerns about espionage targeting American AI developers. In May, Senator Jim Banks asked major AI companies about personnel screening, insider-threat detection and monitoring of employees with privileged access to sensitive systems.
Together, those initiatives show that Washington's AI-security debate is expanding beyond restrictions on advanced chips. Policymakers are increasingly examining how the software, trained models, employees and infrastructure surrounding frontier AI should be protected.
Why the Inquiry Matters
The economic stakes surrounding model security are substantial.
Developing a frontier AI model can require enormous investments in computing power, data, engineering and infrastructure. If an adversary were able to obtain the resulting model weights without reproducing that development process, it could potentially reduce the time and resources required to acquire comparable capabilities.
There is also a national-security dimension. Advanced AI systems are increasingly being examined for applications in cybersecurity, intelligence analysis, scientific research and defense-related tasks. That makes security around frontier models relevant not only to corporate intellectual property but also to government assessments of strategic technology.
However, the existence of a security risk should not be confused with evidence that the feared breach has already happened. The publicly reported information surrounding Khanna's inquiry does not establish that China has successfully stolen the model weights of the companies receiving the letters.
A Broader Debate Over Regulation and Corporate Responsibility
Khanna's request also feeds into a wider debate over who should be responsible for setting security standards for advanced artificial intelligence.
President Donald Trump has emphasized maintaining U.S. competitiveness in AI and has generally favored a lighter regulatory approach. Reuters reported that Trump recently announced voluntary standards agreed to by technology executives.
Khanna has taken a different approach, arguing for stronger oversight and international mechanisms addressing advanced AI risks. In September, he proposed provisions for a potential U.S.-China AI agreement that included verification mechanisms, inspections and auditing of advanced models.
These approaches illustrate an unresolved policy question: how governments can strengthen security around strategically important AI systems without imposing requirements that significantly slow domestic innovation.
What Happens Next?
Attention will now turn to how the five AI companies respond and whether they disclose previously unknown attempts to access their model weights.
The answers could help Congress determine whether existing corporate cybersecurity practices are considered sufficient or whether lawmakers pursue more formal security requirements for developers of advanced AI systems.
For now, the inquiry is best understood as a request for information about a potentially serious vulnerability — not evidence that a successful theft of leading U.S. model weights by China has occurred.
Balanced Analysis
Khanna's inquiry highlights a fundamental change in technology security. In previous technology competitions, governments focused heavily on physical assets such as semiconductor manufacturing equipment, chips and telecommunications infrastructure. Frontier AI introduces another strategic asset that exists primarily as digital information and may therefore be transferable if cybersecurity defenses fail.
Supporters of stronger oversight can argue that the potential consequences justify minimum security requirements for companies developing exceptionally capable models, particularly where a breach could affect national security.
A competing consideration is that cybersecurity requirements must evolve alongside rapidly changing AI architectures and development practices. Overly rigid rules could impose substantial compliance burdens while failing to address new attack methods.
The central policy challenge is therefore likely to be finding security standards capable of protecting highly valuable AI systems while allowing legitimate research and commercial development to continue.






