Three of America's top national security agencies have accused six Chinese companies of systematically copying the capabilities of leading US artificial intelligence models. In a joint cybersecurity advisory published on 8 September and catalogued as AA26-251A, the Cybersecurity and Infrastructure Security Agency, the National Security Agency and the FBI described what they called an "aggressive, malicious, and targeted" campaign of industrial-scale distillation running since at least late 2024.
The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It says the six drew on models built by Anthropic, OpenAI, Google and xAI, extracting proprietary behaviour across billions of tokens and millions of requests. The agencies assess that the activity took place likely with the awareness of the Chinese government.
What the agencies say happened
Knowledge distillation is a standard machine-learning technique. A smaller model is trained on the outputs of a larger, more capable one, in effect using the stronger system as a teacher. The CISA advisory argues that the named firms turned this research method into a central development strategy, using it to shortcut the cost and time of building frontier systems of their own.
The agencies frame the stakes in national security terms rather than commercial ones. They contend that industrial-scale distillation does more than lower research bills, and that it also strengthens China's military and cyber capabilities in ways that could affect the United States and its allies. The advisory recommends that American AI companies watch for anomalous prompts and accounts, monitor the ratio of subscriptions to actual usage, and flag sudden enterprise-scale throughput from new accounts. One suggestion goes further, urging firms to subtly alter responses to suspected distillation traffic so the payoff for copying drops.
Beijing pushes back
China rejected the accusations within a day. Its Ministry of Commerce said the claims lacked any factual or legal basis and accused Washington of using them to assert technological dominance and suppress competition. Distillation, the ministry argued, is a neutral and widely used industry practice, one that American companies rely on as well.
The response carried a threat. "If the US takes action to contain or suppress Chinese AI companies in the name of combating distillation, China will certainly take resolute measures in response," the ministry said, according to the South China Morning Post. Foreign ministry spokeswoman Mao Ning dismissed the advisory as unfounded smears. The timing is delicate. As the Washington Post noted, the exchange lands just ahead of planned talks between the two governments.
Why it matters
The dispute sharpens a question that has hung over the AI race for two years. If a frontier lab spends billions training a model, and a competitor can approximate much of that behaviour by querying it at scale, where does legitimate learning end and misappropriation begin? Several of the named firms are already central to the hardware and policy story here, from DeepSeek's turn to Huawei silicon to Beijing's own moves toward export controls. The advisory does not, by itself, carry new penalties. What it signals is that the US now treats the copying of model behaviour as a security matter, not merely a commercial grievance, and that the two largest AI powers are prepared to argue about it in public. It also arrives alongside China's plan to quadruple its AI computing capacity by 2030, a reminder that the contest is about infrastructure as much as intellectual property.
Sources
- i. www.cisa.gov
- ii. thehackernews.com
- iii. www.scmp.com
- iv. www.washingtonpost.com
- v. www.secureworld.io
Commentarii · 0