Skip to content
Menu
Menu

U.S. Agencies Accuse Six Chinese AI Companies of Systematically Copying American Models

The agencies said the companies collected billions of pieces of model output through millions of requests, likely with the Chinese government’s awareness.

 

Three U.S. security agencies accused six China-based AI companies of systematically extracting capabilities from leading American AI models to accelerate development of their own products.

The National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI in a joint cybersecurity advisory.

The agencies said the companies had collected billions of units of AI-generated text and code through millions of exchanges with Claude, GPT, Gemini, and Grok models since at least late 2024. This process is called ” distillation,” a method in which developers train a smaller or less advanced model on the outputs of a more capable system.

They assessed that the activity occurred “likely with Chinese government awareness.” The advisory did not detail the evidence supporting that assessment or allege that the Chinese government directed the individual operations. This isn’t the first time the US government has accused Chinese companies of distillation activities. In April, the U.S. State Department launched a global diplomatic effort to warn allied governments about alleged intellectual property (IP) theft by Chinese AI companies.

Companies allegedly concealed millions of requests

While some distillation practices are legitimate, the agencies said this activity was improper because the companies allegedly conducted it secretly on an industrial scale, bypassed access restrictions, and violated U.S. providers’ terms of use.

Rather than obtaining the underlying American models, the companies allegedly sent large numbers of carefully coordinated questions designed to draw out valuable capabilities. The resulting answers could then be assembled into datasets used to train Chinese models to perform similar tasks.

Some requests allegedly attempted to make the American models reveal the step-by-step processes they used to reach an answer. That information could help another model learn how to complete complex tasks, rather than merely copying individual answers.

The companies reportedly spread the requests across ordinary subscriptions, cloud services, and businesses that resell access to multiple AI models. The agencies said some of these intermediary services concealed where requests originated, allowing users to evade geographic restrictions and making the activity harder to trace.

The companies also allegedly bought premium subscriptions in bulk, shared accounts among teams of developers, and automatically moved requests to another service when one access route was blocked.

DeepSeek allegedly used four U.S. model families

The advisory said DeepSeek conducted an organized operation beginning in late 2024 to generate training material for its R1 and V3 models.

DeepSeek allegedly collected answers and capabilities from versions of Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini, and xAI’s Grok.

The agencies also challenged DeepSeek’s widely cited claim that training its V3 model cost $5.6 million. They said that figure excluded the cost and value of training material obtained through the alleged distillation activity. The advisory did not provide its own estimate of that value.

The agencies said Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI also used outputs from U.S. models to improve their own AI systems.

According to the advisory, this approach allowed the companies to reduce the time and expense required to develop advanced AI models while reproducing capabilities that had required substantial investment by U.S. companies.

Agencies recommend quietly reducing the value of answers

After describing the alleged activity, the agencies urged U.S. AI companies to look for accounts that begin using the maximum available capacity immediately, operate continuously without normal breaks, or generate unusually large numbers of similar requests.

When a company has strong evidence that an account is being used for improper distillation, the advisory recommends quietly making its answers less useful for training another model. That could include providing less detailed explanations or directing the requests to a less capable model.

The agencies said suspected operators should not be told when such changes are made because that information could help them adjust their methods. Legitimate AI safety researchers and outside evaluators, however, should be informed when they receive results from a different model.

The advisory also called on AI developers, cloud companies, and services that provide access to multiple models to share information. Activity that appears unremarkable to one provider could reveal a coordinated operation when compared with similar requests seen by other companies.

China rejects the allegations

China’s Commerce Ministry rejected the U.S. allegations, saying they lacked factual and legal support.

The ministry described distillation as a commonly used technical method and accused the United States of applying a double standard. It also claimed that American companies have used Chinese models in their own distillation work.

The ministry said China would respond if the United States used the allegations to impose restrictions on Chinese AI companies.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!