
WASHINGTON — The artificial intelligence race between the United States and China has taken a sharper turn after U.S. security agencies accused six Chinese AI companies of conducting what they described as “aggressive, malicious and targeted” efforts to extract capabilities from American AI models at an industrial scale.
The allegations, issued Tuesday by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and FBI, center on a technique known as AI model distillation.
The companies identified by the agencies are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. U.S. officials allege that the companies have used large numbers of queries and other methods to extract information from advanced American AI systems since at least 2024.
The accusations represent a significant escalation in Washington’s campaign to protect America’s lead in frontier artificial intelligence and come at a particularly sensitive moment in U.S.-China relations.
What is AI distillation?
Distillation itself is not inherently illegal or malicious.
It is a legitimate AI-development technique in which a smaller or less expensive model learns from the responses generated by a more powerful model. Companies can use the process to create faster, cheaper and more efficient AI systems.
The controversy arises when companies allegedly use the technique to extract proprietary capabilities from another company’s closed AI models without authorization.
Anthropic, for example, said earlier this year that it identified large-scale campaigns involving Chinese AI laboratories that generated millions of exchanges with Claude through thousands of accounts. The company said those campaigns violated its terms of service and access restrictions.
The U.S. government now alleges that similar activity has been conducted on a much broader scale.
Billions of tokens allegedly extracted
According to the joint U.S. advisory, the six Chinese companies allegedly extracted billions of tokens from American frontier AI models through millions of interactions.
The targeted systems reportedly included variants of Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini and xAI’s Grok.
U.S. officials allege that the companies did not simply use the systems as ordinary customers.
Instead, the agencies say they deliberately structured large-scale requests to obtain specific capabilities — including reasoning, mathematics, coding and other specialized functions — that could then be incorporated into their own AI models.
The advisory also alleges that some of the activity involved multiple accounts, proxy services, cloud providers and third-party aggregators designed to make the requests more difficult to detect.
U.S. says China-linked firms bypassed safeguards
The three U.S. agencies said Chinese AI companies allegedly routed their activities through multiple channels to circumvent geographic restrictions, usage limitations and other safeguards imposed by American AI developers.
The agencies characterized this as a systematic attempt to obtain proprietary functionality while reducing the cost and time required to develop competing AI systems independently.
Reuters reported that U.S. officials believe the activity was likely conducted with Chinese government awareness, an allegation that significantly raises the national-security stakes.
Washington also argues that the issue extends beyond commercial competition.
U.S. officials said the alleged extraction of AI capabilities could potentially strengthen China’s military and cyber capabilities, including capabilities that could ultimately be used against the United States and its allies.
Chinese government rejects the accusations
Beijing has pushed back against Washington’s claims.
Chinese Foreign Ministry spokesperson Mao Ning said China’s progress in artificial intelligence reflects its own technological development and called on Washington to stop making what Beijing considers unfounded accusations.
China has also urged the two countries to cooperate on AI rather than allowing technological competition to further damage bilateral relations.
The companies named in the latest U.S. advisory have also faced previous allegations involving model distillation, although allegations of unauthorized use do not by themselves establish that every company committed a crime.
That distinction is important because distillation is a standard technique throughout the AI industry. The central dispute is whether particular companies used it legitimately or crossed contractual, intellectual-property or other legal boundaries.
Anthropic had already raised the alarm
The latest U.S. government warning follows months of increasingly serious allegations from American AI companies.
In February, Anthropic said it had identified campaigns involving DeepSeek, Moonshot AI and MiniMax that collectively generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.
Anthropic said the activity was designed to extract Claude’s capabilities and use them to improve competing AI systems.
Later reporting also described allegations involving Alibaba.
The Washington Post reported that Anthropic had accused Alibaba’s Qwen team of using roughly 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude.
These allegations illustrate why Washington is increasingly treating AI-model access as a national-security issue rather than simply a dispute between technology companies.
Why the accusations matter
The battle is ultimately about how quickly countries can develop frontier AI without spending the enormous amounts of money and computing resources required to build the technology from scratch.
If a smaller model can repeatedly query a more advanced model and learn from its responses, developers may be able to reproduce certain capabilities more cheaply and quickly.
That does not necessarily mean the resulting model is a direct copy of the original.
But U.S. officials argue that industrial-scale extraction can significantly reduce the technological advantage enjoyed by American AI companies.
The Wall Street Journal reported that U.S. agencies believe distillation has helped narrow the technological gap between Chinese and American AI developers, while also emphasizing that legitimate forms of distillation remain common in the industry.
The allegations arrive at a critical diplomatic moment
The timing could make the dispute even more consequential.
The accusations come as Washington and Beijing prepare for further discussions on AI safety and ahead of a planned visit to the United States by Chinese President Xi Jinping later this month.
AI has increasingly become one of the central battlegrounds in the broader U.S.-China technology rivalry, alongside advanced semiconductors, computing infrastructure and export controls.
Reuters reported that the United States had already raised similar concerns earlier this year, meaning the latest advisory represents another escalation rather than an isolated accusation.
U.S. agencies tell AI companies to fight back
The NSA, CISA and FBI are urging American AI developers to strengthen their defenses against suspected distillation campaigns.
Their recommendations include improving the detection of suspicious activity, changing responses to suspected malicious extraction attempts and increasing intelligence-sharing among AI companies.
The dispute could therefore lead to tighter controls on access to American AI models — particularly for users or organizations operating through intermediaries and other access routes.
It could also intensify calls in Washington for additional restrictions against Chinese technology companies and tighter controls on the computing hardware needed to train advanced AI systems.
The bigger AI race
At stake is more than the success of individual chatbots.
The United States and China are competing to establish technological leadership in a field increasingly linked to economic growth, cybersecurity, military capabilities and global influence.
American officials argue that unauthorized model distillation could allow Chinese companies to close the technological gap faster than would otherwise be possible.
Beijing, meanwhile, rejects the broader narrative that China’s AI progress is simply the result of copying American technology.
The latest accusations therefore add another layer to an already intense technology rivalry — one in which AI models, computer chips, data centers and intellectual property have become strategic assets.
And as the two countries prepare for further diplomatic talks, the question is no longer simply who can build the most powerful AI model.
It is increasingly becoming a question of who controls the technology behind the next generation of artificial intelligence — and how far each side is willing to go to stay ahead.
Source cross-check: Reuters, Channel NewsAsia, Bloomberg, The Straits Times, The Wall Street Journal, Washington Post, Anthropic, and the U.S. security-agency advisory were reviewed for this rewrite. The allegations remain allegations and should not be presented as judicially established findings.

Leave a Reply