US agencies accuse Chinese firms of AI model distillation as Beijing threatens countermeasures
Three US security agencies warned that Chinese firms extracted billions of tokens from American AI models, prompting Beijing to reject the claims and threaten retaliatory countermeasures.
Federal agencies allege industrial-scale distillation
On 8 September 2026, a joint cybersecurity advisory from the Federal Bureau of Investigation, the National Security Agency, and the Cybersecurity and Infrastructure Security Agency accused Chinese technology companies of extracting proprietary capabilities from American artificial intelligence models. The advisory named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as participants in widespread knowledge distillation campaigns operating since at least late 2024. According to the agencies, these firms extracted billions of tokens across millions of requests from frontier systems built by Anthropic, OpenAI, Google, and xAI. The US agencies asserted that the distillation efforts occurred with the awareness of the Chinese government and formed the core basis of model development rather than a supplementary research practice. The document urged American artificial intelligence providers to implement defensive measures, including detecting malicious prompts, returning deceptive outputs to distillation queries, and sharing cross-provider threat intelligence.
Model distillation and specific allegations
Knowledge distillation involves querying a large, capable model to generate extensive datasets that train a smaller or newer model to imitate the original system. The federal advisory stated that Chinese developers routed queries through intermediary platforms to mask their activities while extracting data from models such as Claude, GPT, Gemini, and Grok. Specifically, investigators stated that DeepSeek utilized data from multiple American models to train its R1 reasoning system, which was released in early 2025. Moonshot AI allegedly extracted data from Anthropic's Fable system to build its Kimi K3 model, while using OpenAI's GPT-4o data for its Kimi K2 system. Anthropic had initially built Fable to share selected capabilities from Mythos, a cybersecurity model restricted to participants in Project Glasswing. The advisory argued that Chinese firms bypassed months of costly research by systematic querying of American infrastructure.
| Late 2024 | Chinese AI firms allegedly begin large-scale distillation campaigns against US frontier models. |
|---|---|
| Early 2025 | DeepSeek releases its R1 reasoning model using extracted training data. |
| Early 2026 | OpenAI, Anthropic, and Michael Kratsios accuse Chinese developers of copying US models. |
| 2026-09-08 | CISA, NSA, and FBI issue a joint security advisory warning of industrial-scale distillation. |
| 2026-09-09 | China's Commerce and Foreign Ministries reject allegations and threaten countermeasures. |
| Late September 2026 | Donald Trump and Xi Jinping are scheduled to meet for a summit discussing AI policy. |
Beijing rejects claims and warns of countermeasures
On 9 September 2026, the Chinese Ministry of Commerce dismissed the US allegations as unfounded, describing the advisory as an example of double standards designed to stifle competition. The ministry argued that knowledge distillation is a recognized machine learning technique utilized across the global industry, including by American firms learning from Chinese models. Ministry officials warned that China would take resolute countermeasures if Washington used distillation concerns to penalize Chinese technology companies. Speaking at a press briefing in Beijing, Chinese Foreign Ministry spokesperson Mao Ning called on the United States to stop making groundless accusations against domestic firms.
China's AI development is the result of high-level technological self-reliance and strength. We maintain that all parties should strengthen cooperation to promote AI development that is open, inclusive, universally beneficial and oriented toward the common good.
Preceding industry tensions and diplomatic backdrop
The confrontation follows earlier intellectual property disputes within the artificial intelligence sector throughout 2026. Prior to the federal advisory, Anthropic, OpenAI, and US technology advisor Michael Kratsios had accused Chinese developers of copying Western frontier models. OpenAI had previously banned accounts suspected of distilling its outputs, while also noting during legal proceedings that xAI had used OpenAI data. The release of the tripartite advisory occurred several weeks before a planned summit in late September 2026 between US President Donald Trump and Chinese President Xi Jinping. The bilateral meeting in the United States is scheduled to cover artificial intelligence policy, with reports indicating that a delegation of Chinese business executives may accompany President Xi during the visit.
Sources
- China slams US claims of 'industrial-scale' AI theft
Al Jazeera Online · Sep 9 - Les entreprises américaines distillent également "massivement" des modèles chinois: Pékin juge "sans fondement" les accusations américaines de détournement d'IA
BFMTV · Sep 9 - La Chine juge "sans fondement" les accusations américaines de détournement d'IA
Le Figaro.fr · Sep 9 - La Chine juge "sans fondement" les accusations américaines de détournement d'IA
La Libre.be · Sep 9 - FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are reportedly carrying out 'industrial-scale' distillation campaigns to boost their models
TechRadar · Sep 9 - Federal Trial Against Huawei Is Underway
The New York Times · Sep 9 - US authorities accuse Chinese AI companies of industrial-scale campaigns to copy American models - Engadget
engadget · Sep 9 - China's Huawei Comes to Brooklyn for Sweeping US Criminal Trial
Bloomberg Business · Sep 9