US Accuses Chinese AI Firms of Stealing American AI Secrets
US Accuses Chinese AI Firms of Stealing American AI Secrets
Imagine spending billions of dollars building some of the world's most powerful AI models only to discover that someone else may be repeatedly questioning your AI, collecting its answers, and using them to build a competing system.
That is essentially the accusation now coming from the United States.
On September 8, the FBI, NSA, and Cybersecurity and Infrastructure Security Agency (CISA) accused six Chinese AI companies of running what they described as industrial-scale campaigns to extract capabilities from leading American AI models. The companies named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
And the method at the centre of the controversy is called AI distillation.
So, what is AI distillation?
The idea itself is not illegal.
Think of it like an experienced teacher helping a student learn.
A smaller AI model can study the answers produced by a more powerful model and learn how to produce similar results. This can be a legitimate way to create cheaper and more efficient AI systems.
But US officials say the Chinese companies allegedly took the practice much further.
According to the advisory, the companies sent millions of requests and extracted billions of tokens from American AI models, including systems from Anthropic, OpenAI, Google and xAI. The alleged goal was to capture valuable capabilities such as reasoning, coding, software engineering and AI-agent skills without having to develop everything independently.
The agencies also claim some operations used fake accounts and proxy infrastructure known as “transfer stations” to get around geographical restrictions, usage limits and security controls.
In other words, Washington is not describing this as someone simply trying ChatGPT or Claude a few times.
It is describing a much bigger operation.
DeepSeek, Alibaba and others are at the centre
The accusations involve six Chinese AI companies, with DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI all named in the US advisory.
The US agencies say these campaigns have been running since at least late 2024.
The accusations are particularly significant because Chinese AI companies have become serious competitors in the global AI race.
Chinese open-weight models have gained attention partly because they can be cheaper, more customizable and easier for developers to run themselves.
The US now argues that some of that progress may also have been accelerated by extracting capabilities from American frontier models.
But there is an important point here:
These are allegations, not court-proven findings.
China has strongly rejected them.
China says the accusations are unfounded
Beijing pushed back quickly.
Chinese officials argued that the US is unfairly portraying a legitimate AI development technique as wrongdoing and said China's progress comes from its own scientific and technological capabilities.
China has also accused Washington of using AI competition to restrict its technological development.
That means this story is no longer just about AI companies.
It is becoming another chapter in the much larger US-China technology rivalry.
And the timing makes it even more interesting.
The two countries are preparing for discussions on AI safety, while President Donald Trump and Chinese President Xi Jinping are expected to meet later this month. AI is expected to be part of those conversations.
Anthropic says this has happened before
This is not the first warning about AI distillation.
Earlier this year, Anthropic accused DeepSeek, Moonshot and MiniMax of running large-scale campaigns against Claude.
Anthropic said the three companies generated more than 16 million exchanges through roughly 24,000 fraudulent accounts to extract capabilities from Claude.
And Google is now reporting something similar.
Google Threat Intelligence says some model-distillation campaigns targeting its AI systems have grown to more than 100 million prompts, with attackers using thousands of compromised or fraudulent accounts and proxy infrastructure to hide where the requests are coming from.
So the bigger story may be this:
AI companies are no longer just competing to build better models. They are increasingly competing to protect what those models know.
The AI race just became a lot more complicated
The US accusations could lead to sanctions or even companies being added to restricted trade lists.
Treasury Secretary Scott Bessent has already warned that sanctions and Entity List designations could be considered if Chinese companies cross the line into intellectual-property theft.
But there is also a bigger question.
If AI systems can teach other AI systems, how do you stop one company from simply learning from another company's model at enormous scale?
That question is becoming harder to ignore.
Because the next big battle in AI may not only be about who builds the smartest model.
It may be about who can protect it from being copied.