Three US national security agencies accused six Chinese artificial intelligence companies on September 8 of running industrial-scale campaigns to extract the capabilities of leading American AI models, an accusation China's government has firmly rejected.

The joint cybersecurity advisory, issued by the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI, named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The agencies said these companies extracted billions of tokens across millions of exchanges from American models, including Anthropic's Claude, OpenAI's GPT, Google's Gemini and xAI's Grok, in a pattern running since at least late 2024.

What the Advisory Describes

The technique at the center of the advisory is known as distillation, where a smaller model is trained to mimic the outputs of a larger, more advanced one. The agencies said distillation itself is a widely used and legitimate research technique, but described what they found as something different: "aggressive, malicious and targeted" extraction conducted at industrial scale, likely with the Chinese government's awareness.

AdvertisementAd Space
Responsive

According to the advisory, DeepSeek used multiple versions of Claude, GPT and Gemini to help train its R1 and V3 models. Moonshot AI is accused of drawing on Claude and GPT-4o outputs for its Kimi systems, while Alibaba, MiniMax, StepFun and Z.AI were each linked to extracting from specific Claude, GPT and Gemini variants for their own coding and reasoning models. The agencies said the companies used fraudulent accounts, bulk subscriptions and proxy routing to avoid detection.

Anthropic separately said it had disrupted a related campaign, describing an effort in which three Chinese labs generated more than 16 million exchanges with Claude through roughly 24,000 fraudulent accounts.

Washington's Response

Rather than recommending that AI companies simply block suspected traffic, the advisory recommends a less visible countermeasure, quietly and unpredictably degrading responses to high-confidence distillation attempts without notifying the user, so the affected companies cannot easily measure or adjust for the change.

US Treasury Secretary Scott Bessent, who had warned in July that Chinese AI models built through IP theft could face sanctions, repeated that warning after the advisory was published. "When PRC firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table," Bessent wrote.

China's Rejection

China's Ministry of Commerce rejected the advisory on September 9, saying the allegations "lack evidentiary and legal basis" and describing distillation as a neutral technical practice used by AI developers worldwide, including American companies. The ministry said the US was using the issue as a pretext to pursue technological dominance and suppress competition, and warned it would take "resolute countermeasures" if the US used anti-distillation measures to justify restrictions on Chinese firms.

China's Foreign Ministry separately said the country's AI progress reflected genuine technological self-reliance, and urged the US to avoid what it called unfounded accusations.

Why the Timing Matters

The advisory arrives weeks before President Donald Trump is set to host Chinese President Xi Jinping in Washington, with AI policy already expected to feature in their discussions. It is also not the first such exchange this year, China's Foreign Ministry, its Washington embassy and the Commerce Ministry have each rejected similar US distillation claims at earlier points in 2026, meaning this dispute is now a recurring feature of the two countries' AI relationship rather than a one-off accusation.