U.S. Agencies Accuse Chinese Firms of Industrial-Scale AI Model Copying

The allegations were issued jointly by the U.S. National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI.
The agencies described the activity as “aggressive, malicious and targeted distillation activities at an industrial scale,” characterizing the alleged conduct as deliberate and focused rather than incidental copying.
The stated purpose of distillation is to reduce the cost of developing new AI tools by using the outputs of larger, more expensive models to train smaller systems.
The planned U.S.-China AI-safety dialogue is scheduled for mid-September, ahead of Chinese President Xi Jinping’s planned visit to the United States in late September.
The U.S. National Security Agency, FBI, and Cybersecurity and Infrastructure Security Agency accused six Chinese AI companies of systematically copying American artificial intelligence models on an industrial scale. The Register reported that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been using a technique called distillation—training smaller, cheaper AI systems on outputs from larger American models—to bypass years of costly research and development.
The agencies characterized the activity as "aggressive, malicious, and targeted" rather than accidental copying. The Edge Singapore noted that U.S. security agencies believe Chinese firms extracted proprietary knowledge from OpenAI, Anthropic, Google, and xAI. The timing complicates ongoing U.S.-China relations as the two countries prepare for AI safety talks in mid-September and Chinese President Xi Jinping's planned visit to the United States later that month.
Because models like ChatGPT and Claude are geo-blocked in China, Chinese companies built workarounds. The Edge Malaysia reported they routed traffic through transfer stations, third-party APIs, and remote cloud providers to hide their identity and access U.S. models in violation of terms of service. This allowed them to send millions of queries and extract billions of tokens without detection.
The obfuscation was deliberate and sophisticated. Chinese firms masked metadata and rotated IP addresses to avoid account flags. U.S. agencies concluded this organized, hidden approach proved the activity was intentional corporate strategy—not casual experimentation or isolated incidents by individual developers.
Knowledge distillation is a standard machine learning technique where a smaller "student" model learns from a larger "teacher" model's responses. The FP noted that American companies spend $700 billion annually building AI infrastructure, chips, and data centers. Distillation lets competitors skip those costs by copying outputs rather than building from scratch.
When done openly, distillation is legal and common. But U.S. agencies argue the Chinese firms weaponized it. They extracted data from four ChatGPT variants, two Google Gemini variants, four Claude variants, and Grok to train DeepSeek's R1 and V3 models—essentially getting a free, comprehensive education from America's top AI labs.
The NSA, CISA, and FBI advised U.S. AI developers to fight back quietly. Rather than ban suspected Chinese accounts outright, they should subtly degrade or alter model responses to suspected malicious queries. This prevents Chinese actors from realizing their training data has been poisoned, keeping them from adapting their tactics.
The strategy signals a shift in how U.S. tech companies may defend themselves. Instead of transparent enforcement, developers face pressure to deploy active countermeasures—treating model outputs as potential exfiltration vectors and using responses as a battleground.
The accusation lands days before scheduled U.S.-China AI safety talks in mid-September and weeks before President Xi's late-September U.S. visit. Treasury Secretary Scott Bessent declared that Chinese firms are "stealing and copying," asserting that China "can never get ahead" of America in AI through theft.
U.S. security officials framed the distillation campaigns as evidence China lacks genuine scientific breakthroughs and relies entirely on copying American innovation. The public accusation raises pressure on both countries to address AI security in formal talks, though the confrontational tone suggests deeper mistrust ahead of high-level negotiations.
Publishers
60
Articles
225
Reach
285