DoorDash is the latest US firm two House panels are pressing on Chinese developed AI, where the real concern is 'open weight' models, whose parameters anyone can download and self host.
Two House committees are asking DoorDash CEO Tony Xu to justify his company's use of Chinese-developed AI, expanding a congressional probe that began in April and now reaches a consumer platform handling sensitive commercial and personal data.
The letter, signed Friday by House Select Committee on China Chairman John Moolenaar and House Committee on Homeland Security Chairman Andrew R. Garbarino, is the latest in a series of inquiries into how US companies are evaluating and deploying artificial intelligence models developed in the People's Republic of China. The committees want detailed information on the models DoorDash is reviewing, where they sit in the company's stack, and what safeguards are applied when they touch user data.
The lever committees are pressing is open-weight models. These are models whose underlying parameters, the giant numerical files that encode a model's behavior, are published openly. Anyone can download them, modify them, and run them on their own hardware, without going through a Chinese company or a US intermediary. That openness is the feature that makes them attractive to US developers and the surface committees want to defend. Once a model's parameters are public, the jurisdiction that produced them travels with the weights into every product that downloads them. A US company running an open-weight PRC model on its own servers is still running software that was designed, trained, and shaped under Chinese law.
The committees' own letter acknowledges the trade-off. They write that "U.S. companies, from large technology firms to startups, may evaluate and deploy PRC-developed open-weight models because they can provide competitive capabilities, lower costs, greater customisation, and alternatives to reliance on a small number of proprietary model providers." That sentence is the policy story: open-weight PRC models break the lock that a handful of US proprietary labs hold on frontier capability, because their cost and customisation make them a real alternative to a closed API subscription.
The federal response in the letter is two-pronged. First, strengthen the American open-weight stack so US firms have a domestic option that is competitive on cost, capability, and customization. Second, build "tailored safeguards" for the cases where open-weight models from any foreign jurisdiction touch sensitive systems. The first lever is industrial policy dressed up as a security ask: if the US wants companies to stop reaching for Chinese open-weight downloads, it has to produce something better to reach for. The second lever is harder. "Tailored safeguards" can mean anything from disclosure rules to outright deployment bans in high-risk contexts, and committees have not yet specified which.
DoorDash's exposure is not yet known. The company has not been quoted on the record in available coverage, the specific model or models under review are not named in the available excerpt, and the letter is an information request, not a finding. The committees are not alleging that DoorDash has mishandled data or that any user information has been exposed to Chinese authorities. They are asking what is in the stack and how it is governed.
The story is bigger than DoorDash. The April investigation that produced this letter already covered other American companies. DoorDash is the latest data point, and the data point that brings the open-weight question into a consumer-facing platform. A delivery app does not look like a defense contractor, but it sits on top of logistics, payments, and personal data flows that the committees have already flagged as sensitive.
The next test of the probe is whether the federal approach moves from letters to structure. That means an American open-weight strategy that can compete on the dimensions the committees themselves named, and a clear rule for when a downloadable model from a foreign jurisdiction is treated as a regulated input. Without both, US companies will keep downloading what is easiest to download.