Security
US Security Agencies Accuse Chinese AI Firms of Systematic IP Theft
Three of America’s most powerful security agencies have accused six Chinese AI companies of systematically siphoning knowledge from the country’s advanced AI models. The joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) describes what officials term an industrial-scale extraction campaign that has been ongoing since late 2024.
The targeted AI models include Anthropic’s Claude, OpenAI’s GPT series, Google’s Gemini, and xAI’s Grok. The accused firms are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The method employed for this alleged theft is known as knowledge distillation, a legal machine learning technique that has reportedly been weaponized to copy the outputs of advanced AI systems at an unprecedented scale.
Knowledge distillation involves a smaller “student” model mimicking the behavior of a larger “teacher” model by analyzing its outputs. Although this technique is commonly used in research, US officials claim that the scale and coordination of these efforts are what set this case apart. The advisory details millions of requests made against American AI systems, leading to the extraction of billions of tokens worth of output data. The accused firms allegedly used proxies, shared accounts, and various evasion tactics to bypass terms of service governing access to these models.
US officials suggest that these operations were likely conducted with the knowledge of the Chinese government, framing the activity as part of Beijing’s broader strategy to close the AI gap with the United States. This advisory builds on earlier accusations made by the White House in April 2026, which highlighted similar industrial-scale distillation campaigns.
US Treasury Secretary Scott Bessent has indicated that sanctions or Entity List designations could be considered, which would restrict American companies from engaging with the named firms, cutting off access to US technology and services.
In response, Chinese officials have dismissed the allegations as baseless. The situation raises significant concerns for American AI companies, which will now face pressure to demonstrate their systems' ability to detect and prevent large-scale extraction attempts. The advisory encourages US AI providers to adopt detection and mitigation measures, while also posing a complex technical challenge: how to prevent distillation at scale without hindering legitimate usage.
FAQ
What are the main allegations against the six Chinese AI companies?
The US security agencies accuse the six Chinese AI companies of systematically siphoning knowledge from advanced American AI models through an industrial-scale extraction campaign using a technique called knowledge distillation.
What is knowledge distillation and how is it being misused?
Knowledge distillation is a machine learning technique where a smaller 'student' model mimics the behavior of a larger 'teacher' model by analyzing its outputs. It is being misused by the accused firms to copy outputs of advanced AI systems at an unprecedented scale.
Which American AI models are mentioned as targets of this alleged theft?
The targeted AI models include Anthropic’s Claude, OpenAI’s GPT series, Google’s Gemini, and xAI’s Grok.
What actions might the US government take in response to these allegations?
US Treasury Secretary Scott Bessent has indicated that sanctions or Entity List designations could be considered, which would restrict American companies from engaging with the named firms and cut off their access to US technology and services.
How are the accused firms allegedly bypassing access restrictions to American AI systems?
The accused firms reportedly used proxies, shared accounts, and various evasion tactics to bypass terms of service governing access to these AI models.