Representative Ro Khanna, the top Democrat on the House Select Committee on China, sent letters on October 1 to the chief executives of OpenAI, Anthropic, Google, Meta and SpaceX demanding data on every known effort by China or other hostile actors to illegally access their model weights, Reuters reported. He also asked each firm to describe the cybersecurity measures it uses to prevent such theft.
The warning in the letters is blunt. “The theft of an advanced model weight by a hostile non-state actor could endanger all of humanity, and the theft of such a model weight by (China) could erode America’s AI lead with the stroke of a keyboard,” Khanna wrote, according to Reuters. Model weights are the numbers learned during training that make an AI model work. Anyone who holds them can run a copy of the model, which is why labs guard them more tightly than almost any other corporate asset.
Khanna represents part of Silicon Valley, which gives the request an unusual texture: a congressman whose district includes the companies he is pressuring. As ranking member on the China committee, he can hold hearings, subpoena documents and refer findings to other agencies. The letters ask for comprehensive incident histories, not assurances, and they arrive with receipts attached in the form of publicly documented adversary activity.
Why theft is a live worry
The concern is not hypothetical in the industry’s own telling. OpenAI and Anthropic have reported multiple instances of Chinese AI firms, including Moonshot AI and DeepSeek, distilling their models, meaning training competitors on the output of leading Western systems. OpenAI said in October that it had banned accounts tied to a coordinated distillation campaign that peaked at 16,000 requests from more than 4,000 users in late July, with a core cluster linked to Moonshot. The company said the operators were trying to extract hidden reasoning rather than stored user data, and that it shut the activity down by July 28.
Distillation is not theft of weights. It captures behavior rather than the parameters themselves. But the episode shows how persistently adversarial actors probe US systems, and Khanna’s letters push past behavior cloning to the prize asset underneath. A leaked set of frontier weights would hand a rival state a working model with no training cost and no export-control friction, since the file travels the same way any large file does. Unlike a stolen chip design, a stolen model can be deployed the day it leaks.
The security history of the labs themselves adds texture. The past year brought a series of intrusions and near-misses across the industry, including security incidents at MetaMask’s Ethereum staking operation and an escaped testing agent at Hugging Face, plus government-linked intrusions in the US and Australia where AI tools played a role. None involved frontier model weights, as far as has been disclosed. The letters are designed to find out whether that record is clean.
A crowded oversight field
The letters land while Washington is pulling at the labs from several directions at once. The FTC has opened an investigation into OpenAI, Anthropic and other companies over potential consumer risks, the Wall Street Journal reported October 1. Anthropic’s leaked IPO prospectus devotes roughly 80 of 261 pages to AI risks, including a warning that its models could pose catastrophic risk to humanity. None of that changes Khanna’s committee jurisdiction, but the accumulation of parallel scrutiny means the labs are answering security questions on multiple fronts with the same security teams.
Export controls form the policy backdrop. A bipartisan bloc in Congress has spent two years tightening the rules on advanced AI chips sold abroad, with legislation such as the GAIN AI Act proposing certification requirements for chip categories and earlier bills barring sales of hardware like Nvidia’s H200 to China. Khanna’s letter extends the same logic upstream: if the chips are controlled, the weights they produce should be guarded like controlled assets too.
What the firms are being asked
Based on the reporting, the letters request data on all known unauthorized access attempts by hostile actors, any confirmed or suspected exfiltration of weights or sensitive code, and a description of the security architecture protecting training clusters and storage. A response would tell Congress how labs segment access, monitor for exfiltration and handle insider risk, details companies rarely publish. Security researchers have argued for years that labs should disclose attempted thefts the way public companies disclose breaches, and the letters would make that disclosure effectively mandatory for five firms.
The companies have not publicly responded. Compliance is likely, since the letters come from a committee with subpoena power and the underlying request, guard your secrets better, is hard to refuse publicly. But the answers themselves create risk: admitting a successful intrusion by a state actor would be a market-moving disclosure, especially for Anthropic with an IPO pending at a reported valuation above $2 trillion.
The uncomfortable question
The letters also expose an unresolved gap in US policy. No statute tells a private AI lab how to secure model weights or when to report their theft. Cybersecurity incident rules that cover critical infrastructure do not clearly name frontier models, and the voluntary White House commitments signed on September 29 by the same group of CEOs ask for internal controls without defining them. Khanna’s request is, in effect, an audit conducted by letter, and its findings could shape whether that gap gets closed by legislation or left to each lab’s discretion.
