DoorDash, the largest online food delivery platform in the United States, is under scrutiny from two House committees over its use of Moonshot AI’s open-weight Kimi K2.6 model in its internal code review process.
On July 31, John Moolenaar, chair of the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party, and Mark Green Garbarino, chair of the House Homeland Security Committee as identified in the source, sent a joint letter to DoorDash CEO Tony Xu. The letter asked the company to explain the cybersecurity risks tied to bringing Moonshot AI’s Kimi K2.6 into its code review workflow. It also set two deadlines: Aug. 14 for a full AI strategy report and Aug. 21 for testimony before Congress.
DoorDash had publicly framed the move as a lower-cost setup
The issue grew out of a public post about engineering efficiency. In early July, DoorDash co-founder Andy Fang wrote on X that the company had repeatedly validated through internal coding benchmarks that open-weight models could be introduced into its AI code reviewer without hurting quality.
He said the hardest work was assigned to the frontier model Fable, while lower-level work was delegated to Kimi K2.6. In his post, Fang wrote: “With our internal coding benchmark, we're able to confidently introduce open-weight models into our AI code reviewer w/o degrading code quality. Have the frontier model (Fable) to the hardest work, delegate lower-level work to Kimi K2.6 Better quality, cheaper cost.”
DoorDash’s AI research lab later added on X that the combination of Kimi and Fable was cheaper than the company’s earlier arrangement, which relied only on U.S. models.
House committees want details on model use, testing, and data exposure
In their letter, the committee chairs asked DoorDash to provide a full account of its AI strategy. That includes which Chinese models the company has used, what cybersecurity testing it conducted, the results of its risk assessments, internal decision records, cost details and alternatives, and whether any U.S. user data or business information was shared with model developers during training, fine-tuning, or deployment.
The company’s relevant executives were also asked to appear before Congress by Aug. 21.
The committees said the inquiry goes beyond DoorDash. According to their statement, it is part of an ongoing joint investigation into U.S. companies that integrate Chinese open-weight models into consumer platforms, enterprise software, or systems that can access sensitive commercial or personal information.
The stated purpose is to assess the national security, cybersecurity, and economic security implications of those integrations. By that framing, DoorDash may not be the last company to receive such a letter. It is the first one publicly named.
Lawmakers cited possible risks but said public evidence is lacking
The two chairs said plainly in the letter that even if Chinese open-source models are “cheaper” and “more efficient,” companies still have a duty to manage risk. They raised concerns that open-weight models could contain malicious code, be used to launch cyberattacks, or help bypass security controls.
At the same time, the letter also said there is currently no public evidence showing that such risks are widespread. That leaves the investigation focused not on a confirmed incident already on the record, but on a possibility that has not been proven and has not been ruled out.
Moonshot AI had already been mentioned in a separate U.S. accusation
A separate line of allegations involving Moonshot AI had already surfaced before the House letter. On July 22, the director of the White House Office of Science and Technology Policy accused the company of possibly operating a covert platform to carry out large-scale model distillation of U.S. AI systems and of using advanced systems obtained without authorization to train its own models.
DoorDash’s deadline to hand over documents and appear before Congress came against that backdrop.

