
The FBI, National Security Agency and Cybersecurity and Infrastructure Security Agency have accused six Chinese artificial intelligence companies of conducting large-scale campaigns to extract proprietary capabilities from leading American AI models, escalating a dispute over how the next generation of AI systems is developed.
The joint advisory, released Tuesday, names DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.ai. U.S. officials allege the companies used outputs from models including OpenAI’s GPT, Anthropic’s Claude, Google’s Gemini and Grok to accelerate development of their own systems. The agencies say the activity has occurred since at least late 2024 and likely took place with Chinese government awareness. China rejected the accusations Wednesday, describing its AI progress as the result of domestic innovation and urging the United States to avoid unfounded allegations.
What Is AI Distillation?
Distillation is a legitimate machine-learning technique in which a smaller model learns from the responses of a larger, more capable model. A developer might use a powerful AI system to generate examples, then train a less expensive model to produce similar results. The approach can reduce the computing resources, electricity and research costs required to build an AI product. The dispute arises when companies allegedly use another developer’s restricted model capabilities without authorization, particularly through large numbers of automated requests designed to reproduce proprietary behavior.
According to the advisory, the Chinese companies used multiple access pathways, including third-party API services and shared premium subscriptions, to gather large volumes of model responses while avoiding detection. The agencies allege that the campaigns involved billions of tokens across millions of exchanges and violated U.S. AI companies’ terms of service. They also warn that faster development of advanced Chinese models could have implications for military and cyber capabilities. The allegations do not establish that the accused companies obtained the underlying model weights or source code, and they should not be confused with a breach of ordinary users’ ChatGPT, Claude or Gemini conversations.
The Readovia Lens
The dispute highlights the growing economic value of AI model capabilities and the difficulty of protecting them once powerful systems are made available through online services. Distillation can support legitimate innovation, but unauthorized extraction could allow competitors to benefit from expensive research without bearing the same development costs. For U.S. AI companies, the challenge is to protect proprietary technology while preserving access for customers, researchers and developers who use these systems legitimately.

























































