Why U.S. Officials Fear Chinese AI Labs Are Stealing American Secrets at Industrial Scale
U.S. intelligence agencies have accused six Chinese AI companies of conducting large-scale, coordinated campaigns to extract capabilities from American frontier AI models, potentially narrowing the technology gap without bearing comparable development costs. On September 9, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) issued a joint advisory naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as the companies involved.
What Exactly Are These Companies Accused Of Doing?
The six firms allegedly engaged in what's called "knowledge distillation" at an industrial scale. Knowledge distillation is a machine learning technique where one AI model learns from the outputs of another model. While the technique is commonly used legitimately to create smaller or cheaper models, the agencies assessed that these companies misused it to extract restricted proprietary functions and capabilities from U.S. frontier models including Claude, GPT, Gemini, and Grok.
According to the advisory, the companies distributed their activity across multiple model providers, cloud platforms, and infrastructure to avoid detection. Some used third-party services to relay requests to U.S. models, allowing them to bypass geographic restrictions and other safeguards designed to prevent unauthorized access. The agencies assessed that this activity took place "likely with Chinese government awareness," though they did not state that Chinese authorities directly ordered the individual campaigns.
How Extensive Is the Alleged Extraction Campaign?
The scale of the alleged activity is substantial. The agencies reported that the six companies extracted billions of tokens through millions of requests to frontier models since at least late 2024. To put this in perspective, a token is roughly equivalent to a word or small piece of text; billions of tokens represent an enormous volume of data and model interactions.
DeepSeek, the most prominent of the accused companies, allegedly conducted an organized campaign to obtain reasoning capabilities, specialized optimizations, and other functions for use in its R1 and V3 models. Anthropic, the company behind Claude, had previously identified industrial-scale campaigns by DeepSeek, Moonshot AI, and MiniMax involving more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts that violated terms of service and regional access restrictions.
Why Does This Matter for U.S. Competitiveness?
Treasury Secretary Scott Bessent framed the AI competition with China as existential for American technological leadership. "Beating China, there is no day after tomorrow if China wins at this," Bessent stated at Breitbart News' "State of the Economy" event in Washington on September 9. "If they were to pull ahead of us on AI, then nothing else matters".
"If they were to pull ahead of us on AI, then nothing else matters," said Scott Bessent, U.S. Treasury Secretary.
Scott Bessent, U.S. Treasury Secretary
The concern is that large-scale distillation could allow Chinese AI developers to narrow the technology gap while avoiding some of the computing power, electricity, foundational research, and other costs required to independently develop frontier models. This creates an asymmetric advantage: Chinese companies benefit from years of American research and development investment without bearing the full cost of that innovation.
How Are U.S. Companies Responding?
American AI developers have raised alarms about these practices. OpenAI told the House Select Committee on the Chinese Communist Party in February that it had observed activity indicating continued attempts by DeepSeek to distill capabilities from OpenAI and other U.S. frontier models, including through increasingly obfuscated methods intended to make the activity harder to detect. Anthropic noted that while distillation is a legitimate training method, competitors can misuse it to acquire capabilities developed by other companies without bearing comparable development costs.
Steps to Strengthen AI Security and Detection
The federal advisory outlined several recommendations for protecting American AI systems:
- Improve Detection Systems: American AI companies and infrastructure providers should strengthen their ability to identify suspicious activity patterns that indicate large-scale distillation campaigns or unauthorized model access.
- Enhance Coordination: Model developers, cloud providers, and API providers need better coordination across the industry to share threat intelligence and detection methods, creating a unified defense against coordinated attacks.
- Strengthen Safeguards: Companies should reinforce geographic restrictions, authentication mechanisms, and other technical barriers designed to prevent unauthorized access and bypass attempts by foreign actors.
What's China's Response to These Allegations?
Beijing rejected the allegations on September 9. Chinese Ministry of Foreign Affairs spokeswoman Mao Ning said China's AI development came from domestic technological development and international cooperation. This denial stands in contrast to the detailed evidence presented by U.S. intelligence agencies and the earlier findings by Anthropic and OpenAI.
The dispute over model distillation has unfolded alongside a broader pattern of Chinese technical replication. In December 2024, researchers from Fudan University and the Shanghai AI Laboratory successfully replicated OpenAI's advanced o1 reasoning model, a key step toward replicating frontier AI capabilities. The release of DeepSeek's open-source reasoning model sent shockwaves through the tech industry, with the model rivaling OpenAI's systems at a fraction of the cost and running on standard hardware.
What Does This Mean for the Future of AI Development?
Bessent tied the competition with China to the U.S. buildout of data centers and other infrastructure needed for AI development. He said the United States currently has the lead because of its technology companies, advanced chips, financing, and startup ecosystem, but argued that development could not be paused. "We can't pause," Bessent said. "You can't, because the Chinese won't pause".
The Treasury Secretary also criticized technology companies for failing to engage adequately with communities affected by new data-center construction, giving data-center developers, hyperscalers, and major AI companies a "D-minus" for community outreach. This suggests that maintaining American AI leadership requires not just technological innovation but also addressing public concerns about infrastructure expansion.
The advisory urges American AI companies and infrastructure providers to improve detection of suspicious activity and strengthen coordination across model developers, cloud providers, and API providers to counter large-scale distillation campaigns. As the competition between U.S. and Chinese AI labs intensifies, the ability to protect proprietary models and detect unauthorized access will likely become a critical factor in determining which nation maintains technological leadership in artificial intelligence.