Feds accuse China of ‘systematic’ distillation of U.S. AI models
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
The U.S. government is accusing Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities.
According to a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI, the sheer scale of these efforts since 2024 indicate that distillation is a critical part of China’s AI industrial policy.
“China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy,” the agencies wrote.
The advisory names Chinese companies like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, saying they spent billions of tokens across millions of exchanges and requests with frontier U.S. AI models like Anthropic’s Claude, OpenAI’s ChatGPT, Google Gemini, and xAI’s Grok, since at least late 2024.
The U.S. agencies said the companies used data culled from these interactions to strengthen their own domestic models, a practice that is tacitly encouraged but not directed by political leaders in Beijing.
DeepSeek, for example, distilled frontier U.S. models to generate synthetic training data for its R1 and R3 models, including four different versions of Claude, two versions of Gemini, five versions of ChatGPT and Grok 4. Those models helped train DeepSeek’s capabilities in areas like agentic functioning, question and answer optimization, creative and occupational writing and others.
Another Chinese company, Moonshot AI, allegedly distilled 18 different U.S. models – including Fable 5, Anthropic’s current, most advanced commercially available model – to train its Kimi-K2 and Kimi K3 models. The company used millions of queries meant to extract enhanced capabilities in areas like agentic reasoning, coding and data analysis, computer vision, larger logical frameworks, visual processing and others.
Chinese AI companies manage a sophisticated set of tools and systems that route requests and prompts through multiple pathways to avoid detection.
The advisory lists common tactics observed by Chinese companies, including spreading requests across different accounts, models and platforms, using native APIs, remote cloud providers, and third-party aggregators to obfuscate user metadata, and leveraging proxies and gray tech markets to get around geographic restrictions, terms of use and safeguards built into frontier models.
“Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the advisory stated.
For decades, U.S. national security officials and western business leaders have accused China of leveraging cyberattacks, insider threats and other forms of economic espionage to pilfer proprietary or sensitive technologies from U.S. businesses.
In June, Michael Kratsios, White House head of Office of Science and Technology Policy, made a similar accusation about MoonshotAI of distilling Fable 5 to train its own models, and described a similar “sophisticated” system for evading guardrails and restrictions on usage.
The warning Tuesday levies similar charges about Chinese theft of American tech, but for frontier AI companies that are facing lawsuits themselves from artists, authors, media organizations and other parties who say AI companies illegally trained their models on copyrighted or trademarked work.
Even within the competitive AI industry, companies and open-source organizations commonly share weights and measures for AI systems, or distill other AI systems in the course of legitimate work or research.
The agencies acknowledge this reality, but claim that Chinese companies are engaged in “aggressive, malicious, and targeted distillation activities at an industrial scale.”
Latest Podcasts
Government
FTC rescinds policy requiring health apps to notify customers after a breach
Lawmakers call on Commerce to sanction hackers-for-hire
FBI cyber chief worries private sector not sharing enough cyber threat information
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Technology
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
Threats
Conti ransomware crew member sentenced to four years in prison
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Wyden seeks upgraded NSA security guidance on commercial VPN use
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Reproduced in full under licence from CyberScoop. © CyberScoop. Written by djohnson.
Coverage
One outlet has carried this so far.
2026-09-08 20:47 UTC
Related stories
- Cisco warns of max severity ISE zero-day exploited in attacks
BleepingComputer · 2026-09-17
- Windows 11 KB5124008 update breaks domain trust for some users
BleepingComputer · 2026-09-16
- CISA decides weekly vulnerability bulletin isn't necessary anymore
The Register · 2026-09-16
- Malware bypasses browser checks to force install Chrome, Edge extensions
BleepingComputer · 2026-09-16
- Google Pixel phones pwned in zero-click attacks
The Register · 2026-09-16