How Chinese AI Labs Allegedly Built Billion-Dollar Models by Copying American Frontier AI
Chinese AI companies including DeepSeek, Alibaba, and Moonshot AI have allegedly conducted massive, coordinated campaigns to extract capabilities from American frontier AI models like Claude, GPT, Gemini, and Grok, according to joint warnings from the FBI, NSA, and CISA released on September 8, 2026. The scale of the alleged theft is unprecedented: Alibaba alone generated more than 151 million exchanges with Anthropic's Claude between May and July 2026, while DeepSeek conducted over 12 million distillation attacks in a single 14-day window in July.
The technique at the center of these accusations is called "distillation," a process where outputs from a more capable AI model are used to train another system. While distillation itself is a legitimate research practice, the scale and methods alleged here cross into industrial espionage territory. Anthropic's threat intelligence report details how the Chinese labs used fraudulent accounts, stolen payment credentials, and third-party routing services to systematically extract Claude's capabilities without authorization.
What Exactly Are These Chinese AI Companies Accused Of?
The allegations span multiple Chinese AI firms and their flagship models. Alibaba allegedly used Claude outputs to train its Qwen models, routing queries through more than 3,500 fraudulent accounts that peaked at nearly 3 million exchanges per day. Moonshot AI, the company behind the Kimi chatbot, routed customer requests to Claude without users' knowledge, with nearly 300,000 requests relayed during a single 10-day period and over 23 million total exchanges between May and July. DeepSeek faced similar accusations, with Anthropic observing more than 12 million distillation attacks over 14 days in July.
The federal advisory issued by the FBI, NSA, and CISA named six firms in total:
- DeepSeek: Accused of over 12 million distillation attacks in a 14-day window during July 2026.
- Moonshot AI: Alleged to have routed more than 23 million Claude exchanges without user consent between May and July.
- Alibaba Group: Accused of generating 151 million exchanges through over 3,500 fraudulent accounts, the largest distillation campaign Anthropic detected.
- MiniMax: Named in the federal advisory as conducting similar industrial-scale extraction campaigns.
- StepFun: Included in the NSA-CISA-FBI advisory as part of the coordinated distillation effort.
- Z.AI: Also named as running aggressive, targeted campaigns against American frontier models.
The advisory framed these campaigns as "aggressive, malicious, and targeted," and stated they were "likely with Chinese government awareness". This language marks a significant shift: distillation is no longer being treated as a commercial or licensing dispute, but as a national security threat.
Why Should American Tech Companies and Investors Care?
The implications extend far beyond Anthropic's legal team. Anthropic warned that distilled copies of Claude do not inherit the original model's safety guardrails, meaning systems trained on stolen outputs may be used to pursue dangerous capabilities without the protective measures built into the original. Additionally, some of the intercepted requests contained sensitive user information, raising privacy and terms-of-service violation concerns.
For Western enterprises, the risk is immediate and practical. Any company piloting or integrating a Chinese open-weight model now faces a provenance question: is this model built on legitimately trained data, or does it contain capabilities extracted from American frontier labs? Compliance officers at European banks and healthcare providers may soon face regulatory pressure to avoid models named in the federal advisory, even before any formal sanctions take effect.
Daniel Newman, CEO of Futurum Group, called the alleged activity "freaking insane" and argued that some Chinese AI models may not be as independently developed as widely portrayed. "Now can we talk about why these Chinese 'Open Weight' models are so good? Because it's basically all lifted from U.S. frontier labs," Newman stated on social media. His criticism highlights a broader concern: if the performance gains in Chinese models come from distilled American capabilities rather than independent innovation, the competitive advantage narrative shifts dramatically.
What Happens Next? Are Sanctions Coming?
Treasury Secretary Scott Bessent has already signaled that Washington can sanction overseas firms found to be stealing American models. The September federal advisory provides him with a specific list of names and detailed technical evidence of the campaigns. Sanctions are no longer a hypothetical threat; they are now a concrete policy option with named targets.
The Treasury Department has not yet issued a formal designation, but the timing is significant. The advisory was published during a period of heightened AI security focus in Congress, with bipartisan bills aimed at catastrophic AI risks gaining momentum. Michael Kratsios, who leads the White House Office of Science and Technology Policy, has already asserted that Moonshot AI distilled Anthropic's Fable model to build Kimi K3.
Anthropic's head of policy, Sarah Heck, has characterized these campaigns as industrial espionage rather than a commercial dispute, a framing that carries legal and political weight. If the Treasury Department moves forward with sanctions designations, the named Chinese labs would become entities that most Western firms cannot legally touch, fundamentally reshaping the global AI supply chain.
How to Assess Your Organization's Exposure to This Issue
If your organization uses, invests in, or procures AI models, here are the key steps to take now:
- Audit Your Model Pipeline: Pull the NSA-CISA-FBI advisory AA26-251A from cisa.gov and cross-reference any Chinese AI models in your current or planned deployments against the six named firms and their parent companies.
- Review Contract Language: Check your vendor agreements for intellectual property warranties and indemnity clauses, especially if you operate in finance or healthcare where regulatory scrutiny will be highest.
- Monitor Treasury Decisions: Watch the Treasury Department website for any formal designation tied to the September advisory or Anthropic's threat report; early movement in export controls may signal imminent sanctions before they are officially announced.
- Prepare for Compliance Review: Anticipate that your next procurement cycle may include a compliance review focused on model provenance, particularly if regulators begin pressuring financial institutions and healthcare providers to avoid flagged models.
The distinction between legitimate distillation and industrial extraction is now the line that policy can cite for enforcement action. Organizations that move quickly to audit their exposure and adjust their procurement strategies will be better positioned if sanctions are implemented in the coming quarters.
The broader question remains unresolved: why Washington had no legal category for industrial-scale model theft until now. The existing legal framework relies on contract law, trade-secret statutes, and export controls, none of which were designed for campaigns measured in millions of queries across fraudulently created accounts. China's domestic AI regulations, by contrast, focus on content safety and algorithm registration but do not expressly forbid distillation of foreign models, creating an asymmetry that has allowed appropriation by design.
As the Treasury Department weighs its next move, the stakes are clear: either sanctions land and the named labs become untouchable entities, or the same technique continues under contract terms written for a different era. The decision will shape not only the competitive landscape of AI development, but also the precedent for how the U.S. responds to state-adjacent technology theft in the years ahead.