Federal Register website uses Chinese AI tool flagged as malicious by FBI
The Federal Register's website unintentionally used a Chinese AI tool flagged by the FBI as "malicious," raising concerns about cybersecurity and data risks in government systems. This incident has pโฆ
The Federal Registerโs public website briefly displayed search results generated by an openโsource Chinese artificialโintelligence tool on Wednesday, a glitch that was discovered and corrected within hours after the agency was alerted that the model had been flagged by the FBI as โmalicious.โ The site, which publishes federal rules, notices and executive orders, inadvertently routed user queries through the Chinese AI before reverting to its standard search engine.
The incident comes amid growing U.S. government scrutiny of Chinese AI technologies. In recent months, the FBI and the Department of Commerce have warned that certain Chinese models can be weaponized to harvest data, spread misinformation, or embed hidden code. Federal procurement rules now require agencies to vet software for nationalโsecurity risks, and the Office of Management and Budget has issued guidance to avoid โunvetted foreign AI services.โ The Federal Registerโs lapse highlights how quickly such tools can slip into government workflows despite these safeguards.
Cybersecurity experts say the episode underscores the need for tighter controls on thirdโparty code used in publicโsector platforms. โEven a brief exposure can create a backdoor for data exfiltration,โ said Laura Chen, a senior analyst at the Center for Strategic Cyber Studies. Congressional staffers have already requested a briefing from the Office of the Chief Information Officer on how many other government sites might be using similar services. The Federal Registerโs IT team confirmed that the Chinese AI was part of an experimental feature that had not undergone the required security review.
The agency says it will conduct a full audit of all thirdโparty tools and tighten its vetting process. The incident is expected to prompt a broader review across federal websites to ensure compliance with the new AI procurement rules. Lawmakers are likely to push for stricter reporting requirements, and the administration may consider expanding the list of prohibited foreign AI services to prevent future breaches.
Read Full Story at Ars Technica โ


