How Chinese AI Labs Allegedly Built Billion-Dollar Models by Copying American Frontier AI
The U.S. government and Anthropic have accused major Chinese AI companies of systematically extracting capabilities from American frontier models through fraudulent accounts and unauthorized API access, marking a significant escalation from intellectual property disputes to potential national security sanctions. On September 8, the FBI, NSA, and CISA (Cybersecurity and Infrastructure Security Agency) issued a joint advisory naming six Chinese AI firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, describing their campaigns as "aggressive, malicious, and targeted" and "likely with Chinese government awareness".
What exactly are these Chinese companies accused of doing?
The practice at the center of the controversy is called "distillation," a technique where outputs from a more capable AI model are used to train another system. What distinguishes these cases from ordinary model use is the scale and method. Anthropic's threat intelligence report, released on September 10, detailed what it called "illicit distillation" involving unauthorized, large-scale extraction of Claude's capabilities.
Alibaba generated the largest detected operation, with more than 151 million exchanges with Claude between May and July 2026, according to Anthropic. The activity peaked at nearly 3 million exchanges per day across more than 3,500 fraudulent accounts. Anthropic said Alibaba used Claude outputs to help train its Qwen models and also relied on the model for reinforcement learning and model architecture research.
Moonshot AI, the company behind the Kimi chatbot, routed some customer requests to Claude without users' knowledge. During one 10-day period, nearly 300,000 requests were allegedly relayed to Anthropic, while more than 23 million exchanges were attributed to Moonshot between May and July. DeepSeek, another prominent Chinese AI lab, was observed conducting more than 12 million distillation attacks over a 14-day period in July.
The methods used to conduct these campaigns reveal a coordinated infrastructure. Anthropic identified stolen payment credentials, grey-market relay points called "transfer stations," and third-party routing services that relayed queries to Claude. Some of the intercepted requests contained sensitive information, raising concerns about privacy violations and terms-of-service breaches.
Why are U.S. officials treating this as a national security issue rather than a commercial dispute?
The shift in how Washington is framing this activity marks a critical turning point. Treasury Secretary Scott Bessent stated in July that the U.S. could sanction overseas firms found to be stealing from American companies. The joint NSA-CISA-FBI advisory did not read like a routine abuse notice; it framed the campaigns as a threat to U.S. technological leadership and tied them to variants of Claude, GPT, Gemini, and Grok.
Anthropic's head of policy, Sarah Heck, calls the campaigns "industrial espionage" rather than a commercial dispute. The advisory's language, "likely with Chinese government awareness," shifts the issue from intellectual property litigation to statecraft, placing the response in the hands of Treasury and national-security agencies rather than civil courts.
One additional concern compounds the national security angle: Anthropic warns that distilled copies do not inherit Claude's safety guardrails. Such systems may be used to pursue dangerous capabilities, creating a thread that runs from a stolen API key to a potential national-security concern.
How to Prepare for Potential Sanctions and Compliance Changes
- Enterprise Procurement Review: Western companies procuring or integrating Chinese AI models should pull the NSA-CISA-FBI advisory from cisa.gov and map it against any Chinese model in their pipeline. Check contracts for intellectual property warranties and indemnity clauses, especially in finance or healthcare sectors, and prepare for a compliance review before the next procurement cycle closes.
- Investment Monitoring: U.S.-based investors with exposure to Chinese AI companies should monitor the Treasury Department page for any designation decision tied to the advisory or Anthropic's September report. Assess whether positions include the six named firms or their parent companies, as early movement in export controls may be a leading indicator before formal sanctions.
- API Security Hardening: AI developers and researchers at Western frontier model labs should treat fraudulent accounts, transfer stations, and routing services as primary attack surfaces. Tightening anomaly detection and implementing stricter account verification can help prevent unauthorized large-scale extraction campaigns.
Daniel Newman, CEO of Futurum Group, criticized these practices as "freaking insane," arguing that some Chinese AI models may not be as independently developed as widely portrayed. "Now can we talk about why these Chinese 'Open Weight' models are so good? Because it's basically all lifted from U.S. frontier labs," Newman wrote on X (formerly Twitter) on September 10. "They are literally routing prompts through Claude" and using the resulting outputs to train their own models.
"Now can we talk about why these Chinese 'Open Weight' models are so good? Because it's basically all lifted from U.S. frontier labs. Sad how many people have fallen for the litany of narratives that China is building better, faster, cheaper models," said Daniel Newman.
Daniel Newman, CEO, Futurum Group
What happens next, and what's at stake?
The immediate Western exposure is procurement and regulatory risk, not just cyber risk. A compliance officer at a European bank piloting a Chinese open-weight model now faces a provenance question no standard vendor contract answers. Regulators could pressure banks and health providers to avoid models named in the advisory, even before sanctions take effect.
Treasury has not yet issued a formal designation, but its authority runs through existing economic sanctions frameworks rather than new legislation. The two frames remain surprisingly far apart. If sanctions land, the named labs stop being a warning and become entities few Western firms can legally touch. If they do not, the same technique continues under contract terms written for a different era.
The financial benefit of distillation accrues in layers. First, labs skip the training bill. Then app builders and cloud providers gain a low-cost model. Finally, state-linked integrators embed it in sectors where pricing matters more than provenance. With a designation decision possible within the coming quarters, the stakes for Western enterprises, investors, and policymakers are substantial.
Alibaba, Moonshot, DeepSeek, and Xiaomi did not immediately respond to requests for comment on the allegations.