US Accuses Six Chinese AI Firms of ‘Industrial-Scale’ Theft of America’s Most Powerful Models
Inside the Alleged Industrial-Scale AI Extraction Campaign
Why the US-China AI Race Just Became Far More Hostile
The United States has dramatically escalated its technological confrontation with China by accusing six China-based artificial intelligence companies of conducting systematic, industrial-scale campaigns to extract capabilities from America's most advanced AI models. The extraordinary joint warning from the NSA, FBI and CISA names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI and says their activity has targeted models including GPT, Claude, Gemini and Grok.
The allegation goes far beyond normal technological competition. US agencies claim the companies extracted billions of tokens through millions of exchanges and requests, using American frontier systems to accelerate the development of Chinese models while avoiding some of the enormous research, computing and electricity costs normally required to build frontier AI from scratch.
NSA, FBI and CISA Name Six Chinese AI Companies
The joint cybersecurity advisory describes what US authorities call aggressive and targeted knowledge-distillation campaigns dating back to at least late 2024. It alleges that distillation has become not simply an occasional development technique but a critical part of the strategy used by several leading Chinese AI developers.
US agencies go further by saying the activity occurred “likely with the knowledge of the Chinese government”. That is an allegation rather than proof of direct Chinese government involvement, but its inclusion pushes the dispute firmly into national-security territory.
The six companies named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. Their growing importance reflects the extraordinary speed with which China has narrowed parts of the gap with American frontier laboratories, a shift already reshaping the wider US-China AI and technology rivalry.
Billions of Tokens and Millions of Requests
The scale claimed by American agencies is one of the most striking parts of the warning. The advisory says billions of tokens were extracted across millions of interactions with US frontier models.
Tokens are the units AI systems use to process language. A single conversation may contain hundreds or thousands of them, but billions of deliberately collected tokens can become an enormous synthetic training resource when organised around specific skills such as coding, reasoning, mathematics or tool use.
That distinction matters. The allegation is not simply that employees at Chinese companies occasionally asked American chatbots questions. Washington says organised systems were constructed to obtain useful model outputs repeatedly, at very high volume, and turn those outputs into training material for competing AI systems.
The advisory describes campaigns running for days or months and generating thousands or millions of requests around individual capability areas. US authorities argue that those volumes exceed what would normally be expected from ordinary research or consumer use.
What AI Distillation Actually Means
Model distillation itself is not inherently improper. It is a standard AI technique in which a smaller or less capable model learns from outputs produced by a stronger model.
AI developers can use distillation legitimately to make their own systems faster, cheaper or more efficient. The dispute begins when one company allegedly uses another company's restricted proprietary system as the teacher, particularly when access restrictions, safeguards or contractual terms are intentionally circumvented.
That is the line Washington says the Chinese companies crossed.
The US advisory claims the targeted campaigns sought specific proprietary capabilities rather than simply publicly available knowledge. Those capabilities allegedly included reasoning, software engineering, mathematical performance, agentic behaviour, specialised writing and methods for evaluating the quality of answers.
This makes the confrontation fundamentally different from the older argument over who owns training data scraped from the public internet. The new dispute is increasingly about whether the behaviour of an already trained AI model can itself become a commercially valuable resource that competitors should be prevented from systematically harvesting.
The Alleged Network of Proxies and ‘Transfer Stations’
One of the most revealing parts of the US account concerns how access was allegedly obtained.
American authorities say China-based companies distributed requests across model providers, cloud platforms, third-party aggregators and other infrastructure rather than sending everything through an obvious central account. The advisory describes a grey market of API proxies known as “transfer stations” that can provide access while obscuring where requests originate.
US agencies say these systems allowed users to circumvent geographic restrictions, evade safeguards and make individual campaigns harder to trace.
The advisory also describes bulk premium subscriptions, pools of accounts, automated routing systems and systems designed to remove identifying metadata. According to the agencies, some operations could automatically shift between access routes when one pathway was blocked.
That sophistication is important because it is the foundation for Washington's claim that the activity was organised rather than accidental. The allegation is essentially that an infrastructure existed for collecting American AI capabilities at scale while reducing the chance that any one model provider could see the entire campaign.
DeepSeek Is at the Centre of the Warning
DeepSeek receives particularly detailed attention.
The US government alleges that the company has conducted organised distillation activity against American frontier models since at least late 2024, targeting reasoning capabilities and specialised functions while generating synthetic training material for models including R1 and V3.
The advisory says DeepSeek obtained capabilities from versions of GPT, Claude, Gemini and Grok. It also challenges the significance of DeepSeek's widely discussed low training-cost figure for V3, arguing that such calculations do not capture the economic value of knowledge allegedly obtained through extensive distillation.
That strikes directly at one of the narratives that made DeepSeek such a disruptive force in the global AI industry: the idea that powerful models could be produced far more cheaply than the enormous spending programmes pursued by leading American laboratories.
Washington's argument is that headline training expenditure may tell only part of the story if sophisticated capabilities developed at enormous expense elsewhere can be extracted and converted into synthetic training data.
Moonshot, Alibaba, MiniMax, StepFun and Z.AI Are Also Named
The claims extend well beyond DeepSeek.
The advisory alleges that Moonshot AI extracted material from multiple American systems to develop capabilities used by its Kimi models, including reasoning, software engineering and mathematics. It also alleges that Alibaba used large-scale distillation to strengthen its Qwen family.
MiniMax is accused of targeting reasoning and software-development capabilities, while StepFun is alleged to have extracted coding and agentic functions. Z.AI is accused of using billions of tokens from American models to help develop reasoning capabilities.
These remain US government allegations. The distinction matters because model distillation is technically complicated, and proving precisely how much of a finished model's capability came from particular external outputs can be difficult.
China's Ministry of Commerce previously rejected similar American accusations, describing US claims surrounding Chinese AI companies as baseless and objecting to the use of technology disputes as justification for possible sanctions. Moonshot has also denied allegations that improper distillation was behind its model development.
The Real Battle Is Over the Cost of Intelligence
The economic stakes are enormous.
Frontier AI models can require huge investment in chips, data centres, electricity, researchers, data processing and experimentation. American companies are committing tens of billions of dollars to infrastructure because pushing performance forward becomes increasingly expensive.
If a competitor can observe millions of high-quality responses from those systems and train another model to reproduce valuable parts of their behaviour, the economics change.
That is why Washington increasingly regards model capability as something closer to strategic intellectual property than an ordinary online service.
The issue sits alongside America's attempts to restrict China's access to high-end semiconductors. Washington has already spent years trying to limit access to the hardware required to train the most sophisticated systems, helping create the conditions for a wider black market in advanced AI chips.
Distillation creates a different vulnerability. A country may restrict physical processors, manufacturing equipment and other infrastructure while still exposing valuable model capabilities through online services accessible from around the world.
China’s Rapid Progress Makes the Dispute More Urgent
The warning arrives as Chinese AI developers are becoming increasingly competitive.
China has built a huge research and development system around artificial intelligence, semiconductors, robotics and advanced manufacturing. Its domestic models are becoming cheaper, more capable and more widely available, while companies such as Alibaba, DeepSeek and Moonshot increasingly compete for developers far outside China.
That progress is part of a much larger Chinese push to deploy AI across the economy, making the question of where underlying capabilities originated strategically important to Washington.
The fear is not simply commercial.
The NSA says advances in Chinese AI could increase military and cyber capabilities that may eventually be deployed against the United States and its allies. Frontier AI therefore sits at the intersection of economic competition, cybersecurity and military power.
America Wants AI Companies to Fight Back
The advisory is not simply an accusation. It is also an instruction manual for defending American models.
US agencies want AI companies to detect unusual patterns involving accounts, networks, prompts and usage. Signals could include newly created accounts immediately generating enormous volumes of traffic, around-the-clock activity with little normal human variation or large groups of accounts behaving in coordinated ways.
Providers are also being encouraged to share information with one another. That matters because a campaign distributed across several companies may look ordinary when each provider sees only a fraction of it.
The agencies even suggest altering responses to suspected malicious distillation attempts so the information being collected becomes less valuable.
That points towards a new technological arms race. AI companies will try to identify automated harvesting systems; harvesting systems will become better at imitating legitimate users; providers will introduce new detection methods; and developers attempting extraction will adapt again.
The US-China AI War Has Entered a New Phase
The confrontation between Washington and Beijing was once dominated by telecommunications equipment, semiconductor manufacturing and export controls.
Now the models themselves have become strategic assets.
That creates a far harder problem. A chip can be stopped at a border. Manufacturing equipment can require an export licence. An AI model accessed through the internet can potentially be queried millions of times from a distributed network of accounts spanning numerous countries and cloud services.
The United States is effectively signalling that it increasingly views systematic extraction of frontier-model capabilities as a national-security threat rather than simply aggressive competition between technology companies.
What comes next could matter far beyond the six companies named in the advisory. Washington has already raised the possibility of sanctions and Entity List restrictions against Chinese companies accused of crossing the line into intellectual-property theft, while Beijing has warned against using such claims to suppress Chinese technology businesses.
The unresolved question is therefore much bigger than whether one model learned from another. The world's two most powerful technological ecosystems are beginning to fight over who owns machine intelligence itself — and whether the capabilities produced inside a frontier AI system can ever truly be kept inside it.
Research Verification
The central allegation comes directly from the joint September 8 cybersecurity advisory issued by the NSA, FBI and CISA. It names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, alleges extraction of billions of tokens across millions of requests, and says the activity occurred “likely with” Chinese government knowledge. The advisory also explicitly distinguishes legitimate distillation from what it characterises as aggressive and malicious industrial-scale extraction.
The advisory details alleged use of proxy “transfer stations”, fraudulent accounts, distributed request routing, metadata sanitisation, automated failover and targeted extraction of reasoning, coding and agentic capabilities. It separately sets out allegations involving DeepSeek and Moonshot and identifies American model families including Claude, GPT, Gemini and Grok.
Anthropic independently disclosed in February that it had identified campaigns involving DeepSeek, Moonshot and MiniMax generating more than 16 million exchanges through roughly 24,000 fraudulent accounts.
China's Ministry of Commerce rejected earlier US allegations concerning model distillation in July, opposing what it described as baseless accusations and potential sanctions against Chinese companies.
The attached Taylor Tailored prompt requires the article itself to remain one continuous Squarespace-ready block, with supporting SEO, metadata and image material kept outside it.

