Three Major U.S. Security Agencies Accuse Six Chinese AI Firms of Industrial-Scale Distillation Attacks
nashnova research
The FBI, NSA, and CISA jointly accused DeepSeek, Alibaba, and four other Chinese AI firms of industrial-scale distillation attacks on America's frontier models. Treasury Secretary Bessent immediately put sanctions and the Entity List on the table — the U.S.-China AI contest is escalating from a technical dispute into a security confrontation.
What exactly are the three agencies alleging?
The FBI, NSA, and CISA issued a joint statement naming DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI. Since at least late 2024, the six firms extracted billions of tokens through millions of requests against U.S. models.
Targets included Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok — covering virtually every leading closed-source U.S. model.
The agencies concluded this was carried out "most likely with the knowledge of the Chinese government." This means → Washington has framed the distillation as a state-coordinated campaign, not isolated corporate behavior.
What is distillation, and why is it controversial?
Distillation — using a powerful "teacher model" to generate Q&A data, then training a smaller "student model" on that data — is a standard, legal technique. Apple distills its own models into lightweight phone versions the same way.
The dispute is about method: Anthropic disclosed in February that Chinese firms used fraudulent accounts and proxy services to access Claude at scale while evading detection. In plain terms = the technique itself is legal, but covertly mass-extracting a closed-source model's knowledge under fake identities changes the nature of the act.
Some legal experts argue AI model outputs are hard to classify as traditional intellectual property, making distillation closer to "learning from a book" than "copying." This reflects a legal framework that has not yet caught up with AI technology.
How much has distillation narrowed the U.S.-China AI gap?
An Anthropic executive said in July that distillation helped China shrink its gap with the U.S. from 12–18 months to roughly 6–9 months.
U.S. security agencies went further, calling the sheer scale of distillation a "core pillar" of China's AI development — not a supplementary tool.
Not everyone in Washington agrees. OpenAI executive Dean Ball and other researchers argue distillation may have helped Chinese firms early on, but is not the main driver of their recent progress.
How has China responded?
China's Ministry of Foreign Affairs said in July that foreign parties were hyping the distillation concept with "malicious intent."
A Moonshot AI executive, after launching the Kimi K3 model, told Chinese media its breakthrough performance relied on foundational innovation, not distillation or copying.
This means → the two sides' narratives on distillation's actual contribution are diametrically opposed — Washington calls it a "core pillar"; Beijing calls it "hype."
Will sanctions actually land? What to watch next?
Treasury Secretary Scott Bessent stated plainly: when Chinese firms cross the IP-theft red line, sanctions and the Entity List are on the table. This is the most direct sanctions threat any U.S. official has made over Chinese AI distillation.
On the civil side, Anthropic and others already bar Chinese firms from using their models under their terms of service. Some lawyers believe lawsuits are viable, but the odds of prevailing remain uncertain.
Reuters reports the U.S. and China are preparing to hold AI-safety talks in mid-September, just ahead of President Xi's planned visit to Washington to meet President Trump. In plain terms = whether the sanctions threat materializes first or becomes a bargaining chip, the window is the weeks around the September summit.
市场有风险,内容仅供研究参考,不构成投资建议。