Security

U.S. Accuses Chinese AI Firms of Industrial-Scale Model Theft

Federal agencies say companies like DeepSeek and Moonshot AI systematically distilled American frontier models using billions of queries to train their own systems.

Omega Editorial· September 8, 2026· 3 min read

The U.S. government has issued a stark warning about what it describes as a coordinated campaign by Chinese artificial intelligence companies to illegally extract capabilities from American frontier AI models through a technique called distillation.

According to a joint cybersecurity advisory released by the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI, the scale of these efforts suggests distillation has become central to China's AI development strategy rather than a supplementary tactic. The advisory, first reported by CyberScoop, names six Chinese companies and details their alleged activities since late 2024.

The Accused Companies and Their Methods

The advisory specifically identifies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as conducting what federal agencies characterize as systematic extraction campaigns. These companies allegedly spent billions of tokens across millions of interactions with leading U.S. models including Anthropic's Claude, OpenAI's ChatGPT, Google Gemini, and xAI's Grok.

DeepSeek reportedly distilled multiple versions of these frontier models to generate synthetic training data for its R1 and R3 systems, targeting capabilities in agentic functioning, question-and-answer optimization, and creative writing. Moonshot AI allegedly distilled 18 different U.S. models—including Claude Opus 4, Anthropic's most advanced commercial offering—to enhance its Kimi-K2 and Kimi K3 models in areas like coding, data analysis, and visual processing.

Sophisticated Evasion Tactics

Chinese AI companies employ elaborate systems to avoid detection, according to the advisory. These include distributing requests across multiple accounts, models, and platforms; using native APIs, remote cloud providers, and third-party aggregators to mask user metadata; and leveraging proxies and gray-market technologies to circumvent geographic restrictions and usage terms.

The agencies state these tactics allow companies to extract proprietary functionalities while evading safeguards built into frontier models.

Why it matters

This accusation arrives at a complex moment for AI intellectual property. While U.S. agencies frame Chinese distillation as theft threatening national competitiveness, American AI companies face their own legal challenges from artists, authors, and media organizations over training data practices. The advisory acknowledges that distillation is common in legitimate AI research and development, but argues Chinese efforts differ in their aggressive scale and intent. The claim that distillation forms the "core" of China's AI strategy—tacitly encouraged by Beijing—suggests U.S. officials view this as industrial policy rather than isolated corporate behavior.

A Familiar Pattern

The charges echo decades of U.S. accusations that China uses cyberattacks, insider threats, and economic espionage to acquire American technology. In June, Michael Kratsios, head of the White House Office of Science and Technology Policy, made similar claims about Moonshot AI's distillation of Claude Opus 4.

The agencies call for coordinated response across government, private industry, and allied nations, emphasizing information-sharing as critical to addressing what they characterize as industrial-scale distillation.

Details of the advisory were first reported by CyberScoop.

#ai model distillation#chinese ai companies#deepseek#national security#intellectual property#cybersecurity

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Hackers Backed by China, Russia, Iran Deploy AI Agents in Attacks

Google researchers document nation-state threat actors moving from basic chatbots to autonomous AI systems that execute complex cyberattacks without human oversight.

Via AI Watch · Sep 8, 2026
Security· 3 min read

Hidden Prompt Injections Threaten AI Agents With Invisible Attacks

Malicious instructions embedded in documents can hijack autonomous systems without triggering traditional security tools.

Via AI Watch · Sep 8, 2026
Security· 3 min read

CIS and OpenAI Launch AI Pilot for State Cybersecurity Defense

The program will test whether artificial intelligence can help under-resourced government security teams identify vulnerabilities and prioritize threats.

Via AI Watch · Sep 8, 2026