U.S. Accuses Chinese AI Firms of Industrial-Scale Model Theft
Federal agencies say companies like DeepSeek and Moonshot AI systematically distilled American frontier models using billions of queries to train their own systems.

The U.S. government has issued a stark warning about what it describes as a coordinated campaign by Chinese artificial intelligence companies to illegally extract capabilities from American frontier AI models through a technique called distillation.
According to a joint cybersecurity advisory released by the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI, the scale of these efforts suggests distillation has become central to China's AI development strategy rather than a supplementary tactic. The advisory, first reported by CyberScoop, names six Chinese companies and details their alleged activities since late 2024.
The Accused Companies and Their Methods
The advisory specifically identifies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as conducting what federal agencies characterize as systematic extraction campaigns. These companies allegedly spent billions of tokens across millions of interactions with leading U.S. models including Anthropic's Claude, OpenAI's ChatGPT, Google Gemini, and xAI's Grok.
DeepSeek reportedly distilled multiple versions of these frontier models to generate synthetic training data for its R1 and R3 systems, targeting capabilities in agentic functioning, question-and-answer optimization, and creative writing. Moonshot AI allegedly distilled 18 different U.S. models—including Claude Opus 4, Anthropic's most advanced commercial offering—to enhance its Kimi-K2 and Kimi K3 models in areas like coding, data analysis, and visual processing.
Sophisticated Evasion Tactics
Chinese AI companies employ elaborate systems to avoid detection, according to the advisory. These include distributing requests across multiple accounts, models, and platforms; using native APIs, remote cloud providers, and third-party aggregators to mask user metadata; and leveraging proxies and gray-market technologies to circumvent geographic restrictions and usage terms.
The agencies state these tactics allow companies to extract proprietary functionalities while evading safeguards built into frontier models.
Why it matters
This accusation arrives at a complex moment for AI intellectual property. While U.S. agencies frame Chinese distillation as theft threatening national competitiveness, American AI companies face their own legal challenges from artists, authors, and media organizations over training data practices. The advisory acknowledges that distillation is common in legitimate AI research and development, but argues Chinese efforts differ in their aggressive scale and intent. The claim that distillation forms the "core" of China's AI strategy—tacitly encouraged by Beijing—suggests U.S. officials view this as industrial policy rather than isolated corporate behavior.
A Familiar Pattern
The charges echo decades of U.S. accusations that China uses cyberattacks, insider threats, and economic espionage to acquire American technology. In June, Michael Kratsios, head of the White House Office of Science and Technology Policy, made similar claims about Moonshot AI's distillation of Claude Opus 4.
The agencies call for coordinated response across government, private industry, and allied nations, emphasizing information-sharing as critical to addressing what they characterize as industrial-scale distillation.
Details of the advisory were first reported by CyberScoop.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call

