News

US agencies accuse six Chinese AI firms

Distillation campaigns target US frontier models.

Shawnee Blackwood

Three US agencies just named six Chinese AI companies in a joint advisory, accusing them of systematically extracting American frontier model capabilities through industrial-scale distillation since late 2024.

NSA, CISA, and the FBI named six Chinese AI companies in a joint advisory Tuesday: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The advisory carries the formal title “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies,” filed as AA26-251A. The agencies accuse all six of running industrial-scale distillation campaigns against US frontier models since late 2024, likely with Chinese government awareness. Targets include variants of Claude, GPT, Gemini, and Grok. The agencies describe the extracted capabilities as the core of China’s AI development strategy, not a supplementary technique, saving Chinese firms billions in training costs and years of engineering work.

Table 1. Who distilled which models, per the joint advisory.

Operators bought fake accounts in bulk, routed traffic through proxy services to defeat geographic restrictions, and fired coordinated queries running from thousands to millions per topic. Prompt-injection jailbreaks then extracted hidden chain-of-thought reasoning directly. DeepSeek’s specific prompts instructed models to imagine their own internal reasoning behind a finished response, then write that reasoning out step by step, pulling agentic functions, writing optimization, and reasoning capability from Claude, Gemini, GPT, and Grok alike. Moonshot rotated across US models to extract fine-tuning, reinforcement learning, software engineering, and math capability. The advisory challenges DeepSeek’s widely-cited $5.6 million training cost directly, noting that figure excludes the cost of data obtained through the alleged distillation.

Figure 1. Six Chinese AI firms, one advisory, four targeted US model families.

These individual accusations carry real history. OpenAI flagged DeepSeek’s behavior last year. Google reported attackers prompting Gemini more than 100,000 times in an apparent cloning attempt. Anthropic separately accused Alibaba of running a Claude-cloning campaign at a scale it had never recorded before. China’s foreign ministry called the new accusations groundless, crediting the country’s progress instead to high-level scientific and technological self-reliance.

Figure 2. How industrial-scale distillation works, and where defenders intervene.

The advisory recommends US AI companies quietly degrade responses for high-confidence malicious accounts instead of blocking them outright, a detection strategy that assumes these campaigns keep running regardless of public disclosure.

What do we think?

DeepSeek’s challenged $5.6 million training figure matters more than any single technical detail here: If the advisory holds up, the number that convinced markets a frontier model could be built cheaply excluded the actual cost of the data behind it, reshaping how the whole industry should read China’s AI cost claims going forward.

Inflection point. Three separate US intelligence agencies formally naming six named companies marks a real inflection point: This moves distillation concerns from individual company allegations into coordinated government policy. If the recommended mitigation, quietly degrading suspect accounts instead of blocking them, becomes standard industry practice, every AI lab’s terms-of-service enforcement changes, and the gap between US and Chinese frontier models becomes a genuine national security metric.

LIKE IT? WE’VE GOT LOTS MORE. TELL EVERYONE YOU KNOW. WE’D LOVE TO HEAR FROM YOU AND THEM.

The Mag 7 borrows its future