12 Sources
[1]
US claims Chinese AI companies' core AI strategy is distilling American models
FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks 13 days ago Two US intelligence agencies and the nation's cyber-defense org CISA have accused Chinese AI companies of running "aggressive, malicious, and targeted distillation activities at an
[2]
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring
[3]
US accuses Chinese AI firms of 'industrial-scale' theft of AI technology
WASHINGTON, Sept 8 (Reuters) - U.S. cyber and law enforcement officials on Tuesday accused Chinese AI companies of "aggressive, industrial-scale distillation activities," according to a statement from three U.S. security agencies. Distillation is the process of training smaller AI models using
[4]
US authorities accuse Chinese AI companies of industrial-scale campaigns to copy American models - Engadget
American authorities are accusing Chinese companies of "distillation activities at an industrial scale." The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have issued a joint cybersecurity advisory, warning
[5]
U.S. Agencies Issue Stern Rebuke of China-Based AI Companies Over Alleged Distillation
The U.S. National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the FBI all released a statement on Tuesday accusing China-based AI companies of "Industrial-Scale Distillation Campaigns Against U.S. AI Companies." "Likely with Chinese government awareness,
[6]
US intelligence advisory names six Chinese AI firms and lists the US models each one targeted
Three US agencies have jointly named six Chinese AI companies as having systematically extracted capabilities from American frontier models since late 2024, in an advisory detailed enough to list which model each firm went after and how the requests were disguised. The National Security Agency,
[7]
FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are reportedly carrying out 'industrial-scale' distillation campaigns to boost their models
Attackers are teaching their models by asking GPT and Claude millions of questions * CISA, NSA, FBI warn Chinese AI firms of industrial‑scale knowledge distillation * Companies like DeepSeek, Moonshot, Alibaba allegedly extracted billions of tokens from US frontier models * Advisory urges
[8]
U.S. accuses Chinese AI firms of stealing American AI model capabilities
The National Security Agency, FBI, and Cybersecurity and Infrastructure Security Agency jointly accused six Chinese artificial intelligence companies of conducting systematic knowledge distillation campaigns against U.S. AI firms at an industrial scale, naming DeepSeek, Moonshot AI, Alibaba,
[9]
U.S. agencies say top Chinese AI companies systematically copied American models
In an alert published Tuesday, the FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency said top Chinese AI companies have systematically mined cutting-edge AI models from American companies since 2024, including Anthropic's Claude, OpenAI's ChatGPT, Google's
[10]
Chinese AI technology theft: US accuses Chinese AI firms of 'malicious' copying of AI technology
The Chinese companies copied U.S. AI labs' intellectual property through a technique known as distillation, according to a statement from U.S. law enforcement and intelligence officials. Distillation is the process of training smaller AI models using output from larger, more expensive ones as
[11]
Washington accuses several Chinese AI groups of copying American technologies
On Tuesday US authorities accused several Chinese artificial intelligence companies of exploiting US-developed models to train their own technologies. In a joint statement, the NSA, CISA and the FBI cited DeepSeek, Moonshot AI, Alibaba, MiniMax and StepFun. According to the three agencies, the
[12]
US accuses Chinese AI firms of 'malicious' copying of AI technology
WASHINGTON, Sept 8 (Reuters) - U.S. cyber and law enforcement officials accused Chinese AI companies on Tuesday of maliciously copying technology from sophisticated American-made AI models through a technique known as distillation, according to a statement from three U.S. security
Share
Copy Link
Three US intelligence agencies have accused six Chinese AI companies of conducting aggressive distillation campaigns to extract proprietary capabilities from American frontier models. The NSA, FBI, and CISA claim DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens from models like GPT, Claude, Gemini, and Grok since late 2024.
The National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint cybersecurity advisory accusing Chinese AI companies of conducting "aggressive, malicious, and targeted distillation activities at an industrial scale."
1
2
The agencies claim these campaigns extract restricted proprietary functionalities and capabilities from American frontier AI models, asserting that model distillation forms "the core - not merely a supplement" of their AI development strategy.1

Source: The Next Web
US agencies specifically named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as companies that extracted billions of tokens across millions of exchanges from US frontier AI models since at least late 2024.
2
4
The advisory alleges these Chinese AI companies targeted variants of Anthropic Claude, OpenAI GPT, Google Gemini, and SpaceXAI Grok, likely with Chinese government awareness.2
According to the agencies, DeepSeek conducted organized campaigns between late 2024 and mid-2025 targeting reasoning capabilities and domain-specific functions to train its R1 and V3 models.2
Moonshot AI allegedly extracted significant Claude Fable 5 data to train its Kimi-K3 model and GPT-4o data for Kimi-K2.2
4

Source: TechRadar
Model distillation involves a smaller model querying a larger model to learn response patterns, improving performance over time without expensive training.
1
While distillation is recognized as a legitimate technique in AI research, commercial model providers generally prohibit such activity through their terms of use to protect substantial investments in technology and training.1
5
The agencies claim China-based AI companies route distillation requests through multiple pathways including native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection.1
These operations also leverage a gray market of proxies known as "transfer stations" to bypass geographic restrictions and breach terms of use.1
The joint advisory details sophisticated methods employed in these industrial-scale distillation campaigns. Advanced tactics include chain-of-thought reasoning extraction, automated failover between pathways during blocking attempts, and quality evaluation frameworks to detect defensive countermeasures.
2
Alibaba allegedly leveraged industrial-scale distillation to improve its Qwen family of AI models by distilling Claude-4, Claude Opus, Claude Sonnet, and GPT-5 to enhance software engineering skills and customer service dialogue functionality in late 2025.1
2
MiniMax distilled chain-of-thought reasoning and software engineering capabilities from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro, and Gemini 3 Pro to improve its M2 model.2
The advisory specifically accuses DeepSeek of using distillation to generate synthetic data used to train its models, making its claim of creating them with trivial quantities of computing power false.
1
This is particularly significant because DeepSeek's claims about low computational requirements panicked investors who worried that billions pumped into AI infrastructure might not be needed.1
The agencies state that Chinese AI companies conducting industrial-scale distillation see significantly shorter AI development timelines and reduced financial expenditures in training frontier models.2

Source: Gizmodo
Related Stories
The NSA, CISA, and FBI recommend AI companies implement comprehensive detection measures to identify distillation attacks.
1
Immediate maximum usage from new accounts serves as one indicator of adverse action.1
The agencies suggest subtly altering responses for suspected malicious distillation attempts to reduce payoffs to companies conducting industrial-scale distillation campaigns.1
2
They also recommend correlating activity across different model providers, cloud platforms, and API aggregators to reveal distributed distillation campaigns.1
The agencies warn that illicitly distilled models lack necessary safeguards, creating significant national security risks.
5
US frontier AI models are officially restricted and not offered in China, forcing Chinese developers to rely on alternative access methods like virtual private networks, obfuscated accounts, and automated agents to bypass geographic controls.2
The timing of this advisory aligns with upcoming US-China talks on AI security, with Treasury Secretary Scott Bessent scheduled to meet Chinese officials this month.5
This is not the first time Chinese firms have faced such accusations—earlier this year, Anthropic identified industrial-scale campaigns conducted by DeepSeek, Moonshot AI, and MiniMax to illicitly extract proprietary functionalities.2
China has responded with counter-accusations that US companies distill Chinese models, plus veiled threats of retaliation against any US bans flowing from these allegations.1
Summarized by
Navi
[4]
13 Jul 2026•Policy and Regulation

23 Apr 2026•Policy and Regulation

31 Jul 2026•Policy and Regulation
