U.S. Accuses Six Chinese AI Firms of Industrial-Scale Model Distillation
A joint FBI, NSA, and CISA advisory claims Chinese companies cloned U.S. frontier models to bypass billions in R&D costs.
The U.S. government has accused six leading Chinese artificial intelligence companies of conducting industrial-scale "distillation" attacks to clone the intelligence of American frontier models. A joint advisory from the FBI, NSA, and CISA warns that these firms systematically extracted patterns from U.S. systems to accelerate their own development while bypassing critical safety guardrails.
According to the federal advisory, the targeted models include OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini, and xAI’s Grok. The U.S. government specifically named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as the entities responsible for these campaigns. Officials claim the firms sent millions of queries to these models to capture their underlying logic and intelligence. In one specific instance, the U.S. alleges that Moonshot AI distilled Anthropic’s advanced Fable model to develop its own Kimi K3 system.
The Mechanics of Distillation
Knowledge distillation is a standard practice in AI development used to create smaller, more efficient "student" models from larger, more complex "teacher" models. However, when performed covertly against a competitor's proprietary system, the practice typically violates terms of service and constitutes intellectual property theft. The U.S. government asserts that for these six firms, this was not a marginal technique but a primary strategy. A joint report from the FBI, NSA, and CISA stated that the scale and sophistication of these campaigns indicate that distillation is not a supplement to these companies’ AI model development, but the "critical core of it."
Economic and Security Implications
This escalation represents a systemic "freeloading" on American research and development. By cloning the outputs of frontier models, Chinese firms can potentially achieve similar performance levels while avoiding the billions of dollars in compute and data costs required to train a model from scratch. This threatens to erase the competitive advantage currently held by U.S. AI laboratories.
Beyond the economic impact, Washington has raised significant national security concerns. The U.S. claims that by distilling these models, Chinese firms can circumvent the safety guardrails and alignment protocols built into American systems, potentially creating powerful AI tools without the corresponding ethical or safety constraints.
Geopolitical Friction
The accusations come amid a broader geopolitical race for AI supremacy and ongoing tensions between Washington and Beijing over industrial espionage. The Chinese government has dismissed the claims. Mao Ning, a spokesperson for the Chinese Ministry of Foreign Affairs, stated that China’s AI development is a result of "high-level scientific and technological self-reliance."
As the U.S. continues to tighten export controls on high-end semiconductors to slow China's AI progress, the focus now shifts to whether the U.S. will implement new regulatory or legal measures to prevent the programmatic extraction of model intelligence by foreign adversaries.