Logo
FrontierNews.ai

Why China's AI Models Are Thriving Despite US Chip Bans: The Distillation Workaround

US chip export controls have delayed China's access to cutting-edge computing power, but they have not stopped Chinese AI development. Instead of building models from scratch with expensive hardware, Chinese companies are using a technique called distillation, where they train smaller models on the responses of larger American AI systems. This workaround means that benchmark comparisons between Chinese and American AI models may mask deeper capability gaps that only emerge during complex, prolonged tasks.

Are US Chip Controls Actually Failing?

The emergence of Chinese models like Kimi K3, DeepSeek V4 Pro, and GLM 5.3 has led many observers to conclude that American export restrictions have failed. However, the reality is more nuanced. According to the Epoch Capabilities Index, a composite benchmark scale, Kimi K3 scored 158 points in September 2026, compared to Anthropic's Claude Fable 5 at 163 points and OpenAI's GPT 6 Astra at 169 points. This gap represents roughly four to ten months of progress based on recent development rates.

More telling is how these models perform under stress. In July 2026, researchers from the US Center for Artificial Intelligence Standards and Innovation and its British counterpart tested Kimi K3 in a 32-step cyberattack simulation. The model reached an average of step 17, while leading American models reached step 28.5. This significant difference reveals that public benchmarks often hide real capability gaps in difficult, sustained tasks.

"Benchmarks do not fully capture performance on difficult and open problems during prolonged work, which explains why the cyberattack test showed a larger gap than standard benchmarks," explained Erich Grunewald, researcher at the Institute for AI Policy and Strategy in Washington.

Erich Grunewald, Researcher, Institute for AI Policy and Strategy

Moonshot AI, the creator of Kimi K3, suspended new subscriptions shortly after launch when demand exceeded its available computing capacity. This suggests that the company lacks sufficient hardware to serve users at scale, despite producing a competitive model.

How Much Computing Power Does China Actually Control?

The computing power gap between China and the United States remains substantial, even when accounting for smuggling and remote access. At the end of 2025, Chinese companies held approximately 5 percent of the world's AI computing power through official channels, according to estimates by Epoch AI. This is smaller than the computing capacity of any single American cloud provider.

Smuggling and remote server rentals have provided some relief but have not closed the gap. In March 2026, US prosecutors charged a co-founder of Super Micro, a server maker, with conspiring to divert up to $2.5 billion worth of Nvidia equipment to China through a virtual company in Southeast Asia. Epoch AI estimates that up to one-third of China's total AI computing power in 2025 may have been smuggled into the country, equivalent to roughly 3 percent of global AI computing power, though this figure may vary significantly. Cloud-leased computing power adds at least another 3 percent of access, though this source is difficult to measure and often remains legal as long as chip owners are not based in China.

Token usage data, which measures actual AI consumption, reveals a more complex picture. According to a study of 100 trillion tokens by OpenRouter in collaboration with investment fund Andreessen Horowitz, open-source Chinese models grew from 1.2 percent of global usage at the end of 2024 to nearly 30 percent within a few months, averaging about 13 percent weekly in 2026. However, researcher Wang Peng from the Beijing Academy of Social Sciences observed that Chinese developers account for just over 6 percent of OpenRouter users, indicating that most usage of Chinese models comes from international users, not from China's own AI development efforts.

How Distillation Lets China Bypass Chip Restrictions

Distillation has emerged as the primary workaround for chip export controls. This technique involves training a smaller, more efficient model on the outputs of a larger, more powerful system. Because distillation requires far less computing power than training a model from scratch, Chinese companies can produce competitive AI systems without needing massive hardware investments.

In April 2026, Michael Kratsios, director of the White House Office of Science and Technology, disclosed that Chinese entities were running industrial-scale distillation campaigns against American AI systems. According to Kratsios, these operations used tens of thousands of fake accounts and circumvention techniques to extract proprietary information from cutting-edge American models.

Anthropic reported in February 2026 that DeepSeek, Moonshot AI, and MiniMax had conducted over 16 million exchanges through approximately 24,000 fraudulent accounts, with 3.4 million exchanges linked exclusively to Moonshot AI. In July 2026, Kratsios specifically accused Moonshot AI of distilling Anthropic's Claude Fable 5 model to develop Kimi K3, while also acquiring Nvidia GB300 servers through Thailand to bypass export restrictions. Kimi K3 costs around $3 per million incoming tokens, compared to $10 for Claude Fable 5, while scoring higher in the Frontend Code Arena rankings. Moonshot AI denied the allegations, arguing that its development is based on its own innovations.

In September 2026, the National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation issued a joint warning about aggressive distillation tactics by Chinese companies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. These campaigns allegedly extracted billions of tokens from conversations with cutting-edge American models as of 2024, likely with knowledge of the Chinese government.

Steps to Understanding the Distillation Threat

  • What Distillation Is: A machine learning technique where a smaller model learns to replicate the behavior of a larger, more capable model by training on its outputs rather than raw data.
  • Why It Bypasses Chip Controls: Distillation requires significantly less computing power than training models from scratch, allowing Chinese firms to create competitive AI systems without access to the most advanced chips.
  • How It's Being Deployed: Chinese companies use fake accounts and circumvention techniques to extract millions of responses from American AI systems, then use those responses to train their own models at a fraction of the cost.
  • The Scale of the Problem: US intelligence agencies have documented billions of tokens extracted through coordinated distillation campaigns, suggesting systematic, government-level involvement.

Treasury Secretary Scott Bessent warned that covert, industrial-scale distillation attacks that go beyond intellectual property theft could lead to sanctions and inclusion on restricted entity lists.

The distillation workaround reveals a fundamental challenge for US export control policy: restricting hardware access does not prevent access to the knowledge embedded in advanced AI models. As long as Chinese companies can interact with American AI systems, they can extract the information needed to build competing models. This suggests that future export control strategies may need to address not just hardware access but also the flow of information from American AI systems to foreign entities.