Two House committees are pressing DoorDash for documents on its use of artificial intelligence built in China, part of a widening congressional probe into whether American companies are handing Beijing a backdoor into U.S. technology infrastructure.
The chairmen of the House Committee on Homeland Security and the House Select Committee on the Chinese Communist Party sent a joint letter to the food-delivery giant requesting "information and documents" on how it evaluates and deploys AI systems developed by companies under the jurisdiction of the People's Republic of China, CNBC reported. The letter zeroed in on a social media post by DoorDash founder Andy Fang, who described on X how his company delegates lower-level AI work to Kimi K2.6, an open-weight model built by the Chinese firm Moonshot AI.
DoorDash is not the first company to receive this kind of letter. The same two committees previously contacted Cursor and Airbnb over their own use of, or exposure to, Chinese-developed AI. But the DoorDash inquiry sharpens the focus: a major American consumer platform, one familiar enough to deliver McDonald's to the Oval Office, is openly farming out tasks to software engineered under Beijing's legal authority.
Rep. Andrew Garbarino, the chairman of the House Homeland Security Committee, has not been subtle about the stakes. He previously told CNBC that China's progress in AI, particularly in tools that can find and exploit cybersecurity weaknesses, demands congressional attention.
Garbarino put it bluntly:
"The Chinese Communist Party is no longer just nipping at our heels in artificial intelligence; it is racing to close the gap in some of the exact capabilities that will shape the future of cybersecurity."
He added a more pointed warning about what that progress means in practice:
"Recent reporting that a Chinese open-weight model can match leading U.S. models in certain vulnerability discovery and cybersecurity tasks is highly alarming."
Vulnerability discovery, the ability of an AI model to identify flaws in software that hackers can exploit, is not an abstract concern. If a Chinese-built model excels at finding security holes, every American company running that model is handing a potential roadmap of its own weaknesses to software developed under a government with well-documented interests in cyber espionage.
The congressional letter acknowledged a real tension in the market. Open-weight AI models, systems that companies can download, modify, and run on their own servers, offer genuine advantages. They cost less than proprietary alternatives from American firms like OpenAI and Anthropic. They give companies more control over customization. And right now, the most capable open-weight models available happen to be Chinese-made.
The letter spelled out that trade-off directly:
"The Committees recognize that U.S. companies, from large technology firms to startups, may evaluate and deploy PRC-developed open-weight models because they can provide competitive capabilities, lower costs, greater customization, and alternatives to reliance on a small number of proprietary model providers."
But the committees did not stop there. The next line drew the boundary:
"Those practical considerations do not eliminate the need for risk-based safeguards or diminish the national security concerns associated with growing dependence on models developed by entities subject to PRC jurisdiction."
That framing matters. The committees are not arguing that every American company using a Chinese model is acting in bad faith. They are arguing that cost savings do not erase the security question, and that Washington has been too slow to force the issue.
DoorDash did not quietly adopt Kimi K2.6 behind closed doors. The company's AI research lab posted on X that Kimi K2.6 and Anthropic's Fable 5 "vastly outperform" other Anthropic models the lab had used, including what it described as "Sonnet 4.6 and Opus 4.8 harness at a cheaper cost." Fang's own post detailed the delegation of lower-level AI tasks to the Moonshot AI product.
DoorDash is hardly alone. Brian Armstrong of crypto firm Coinbase and Flo Crivello of AI startup Lindy have both publicly promoted their use of Chinese AI models to cut costs. The pattern is clear: American companies are gravitating toward Chinese-built tools because the price is right and the performance is competitive, or, in DoorDash's telling, superior.
A DoorDash spokesperson responded to the inquiry with a statement that leaned heavily on patriotism without directly addressing the security concerns:
"DoorDash proudly supports American AI leadership and is working to ensure AI benefits Main Street, not just the biggest companies. We look forward to engaging with the Committees on how we safely and responsibly use AI, including American-developed frontier models and open-weight models."
The company said it "looks forward to engaging." It did not say it planned to stop using Chinese models.
The timing of the congressional probe coincides with an acceleration in Chinese AI capability. Moonshot AI released its newest model, Kimi K3, earlier in July. The company claimed K3 had largely closed the performance gap with leading American models, a claim that, if accurate, would make the cost argument for Chinese AI even harder for U.S. companies to resist.
Meanwhile, a separate incident underscored the complicated relationship between American and Chinese AI systems. A cyber attack involving rogue OpenAI models targeting Hugging Face, a widely used AI platform, was reportedly stopped using a Chinese system. The episode illustrated an uncomfortable reality: Chinese AI tools are becoming embedded in the broader technology ecosystem in ways that go beyond any single company's procurement decisions.
Some government departments have already banned Chinese AI models like DeepSeek. But adoption by private U.S. companies remains unrestricted. The gap between what Washington bars its own agencies from using and what it permits American corporations to deploy is exactly the kind of inconsistency that invites exploitation.
A committee aide, speaking to CNBC on condition of anonymity because the probe is ongoing, pointed to a broader strategic failure behind the company-level inquiries:
"The Committees are also examining whether the United States has a sufficient open-weight AI strategy to ensure American companies and cyber defenders are not forced to choose between expensive or restricted U.S. models and cheap, capable PRC-developed alternatives."
That framing cuts to the core of the problem. If American companies face a choice between expensive, proprietary U.S. models and cheap, high-performing Chinese alternatives, many will choose the cheaper option every time. The committees' letter argued that the federal government should "scrutinize U.S. companies' reliance on PRC-developed models and strengthen the availability, security, and competitiveness of American open-weight alternatives."
In other words, Congress is not just asking DoorDash to explain itself. It is asking why the United States has allowed a market structure in which the most accessible, affordable AI tools are built under the authority of an adversarial government.
DoorDash, for its part, occupies an unusual position in the national spotlight. The company is familiar enough to most Americans that President Trump staged an Oval Office event earlier this year with a DoorDash driver delivering McDonald's to promote his no-tax-on-tips policy. A platform with that kind of consumer reach and public profile running Chinese AI under the hood is precisely the scenario that makes national security hawks uneasy.
When the delivery app millions of Americans trust with their lunch order is quietly outsourcing its AI work to Beijing, the question stops being theoretical. Congress is right to demand answers, and the real failure would be stopping at letters.