The FBI, National Security Agency, and Cybersecurity and Infrastructure Security Agency have jointly accused six Chinese artificial intelligence developers of systematically using a technique known as distillation to copy capabilities from American frontier AI models "at an industrial scale." The advisory, released Tuesday, named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as the firms allegedly involved.
According to the agencies, the activity has been ongoing since late 2024 and likely occurred with Chinese government awareness, although they stopped short of claiming Chinese intelligence services were directly involved. The statement says the companies copied capabilities from models developed by Anthropic, OpenAI, Google and xAI, including Claude, ChatGPT, Gemini and Grok.
Distillation is a standard AI research method in which a smaller model is trained on outputs from a larger model. US officials argue the issue is the scale and intent: "The sheer scale of these campaigns and their sophistication indicate that distillation is not a supplement to these companies’ AI model development, but the critical core of it." The advisory also described a gray market of proxies called "transfer stations" used to bypass geographic limits, safeguards and terms of service, as well as bulk purchases of premium subscriptions for shared access.
The accusations come weeks before President Donald Trump is scheduled to host Chinese President Xi Jinping in Washington on September 24. Beijing rejected the claims through Foreign Ministry spokesperson Mao Ning, who said China's AI progress is the result of its own scientific work and called the advisory a smear campaign. A Chinese embassy spokesperson in Washington called the statement a deliberate attack on China’s AI industry.
US agencies have advised American AI developers to adjust system responses to suspected distillation attempts and share intelligence. The Trump administration had previously vowed to address the issue, and Treasury Secretary Scott Bessent warned in July that sanctions could follow for Chinese firms found to be stealing intellectual property. Anthropic has separately accused Alibaba of using thousands of fake accounts to access Claude, generating more than 16 million interactions.