US security agencies accuse Chinese AI firms of intellectual property theft

1 hour ago 25

Three of America’s most powerful security agencies just pointed a very large finger at six Chinese AI companies, accusing them of systematically siphoning knowledge from the country’s most advanced AI models. The joint advisory from CISA, the NSA, and the FBI describes what officials are calling an industrial-scale extraction campaign that has been running since late 2024.

The targets: Anthropic’s Claude, OpenAI’s GPT series, Google’s Gemini, and xAI’s Grok. The accused: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The method: knowledge distillation, a machine learning technique that’s perfectly legal on its own but allegedly weaponized here to copy the outputs of frontier AI systems at a staggering scale.

How distillation becomes espionage

Knowledge distillation is a well-known technique in machine learning. A smaller “student” model learns to mimic the behavior of a larger “teacher” model by studying its outputs. The technique itself isn’t controversial. Researchers use it all the time to build lighter, faster models.

What makes this case different, according to US officials, is the sheer scale and the alleged coordination behind it. The advisory describes millions of requests made against American AI systems, resulting in the extraction of billions of tokens worth of output data.

The accused firms allegedly used proxies, shared accounts, and various evasion tactics to circumvent the terms of service that govern access to these models.

US officials went further, suggesting these weren’t rogue corporate operations. The advisory states that the extraction efforts were likely conducted with the knowledge of the Chinese government, framing the activity as part of Beijing’s broader strategy to close the AI gap with the United States.

Escalation from earlier warnings

This advisory didn’t arrive out of nowhere. It builds on accusations first made by the White House back in April 2026, which flagged similar industrial-scale distillation campaigns and noted the use of advanced circumvention measures to avoid detection. The September advisory essentially upgrades those warnings from “we’ve noticed something” to “here are the names.”

US Treasury Secretary Scott Bessent has already indicated that sanctions or Entity List designations could be on the table. Being placed on the Entity List would restrict American companies from doing business with the named firms, cutting off access to US technology, cloud services, and potentially even hardware.

China’s response has been predictable. Officials in Beijing dismissed the allegations as baseless.

What’s actually at stake

American AI companies whose models were targeted, including Anthropic, OpenAI, Google, and xAI, will face pressure to demonstrate that their systems can detect and prevent large-scale extraction attempts. The advisory explicitly encourages US AI providers to adopt detection and mitigation measures.

The advisory also raises a thorny technical question: how do you actually prevent distillation at scale? Unlike stealing source code or hardware designs, distillation works by interacting with a model through its normal interface. Every API call returns useful data. Drawing the line between legitimate heavy usage and systematic extraction isn’t straightforward, and any detection system risks flagging legitimate researchers alongside bad actors.

American AI companies have built their businesses partly on broad API access. Locking that down too aggressively could undermine adoption and revenue. Not locking it down enough, according to three federal agencies, means handing your most valuable intellectual property to competitors backed by a rival government.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article