cd /news/ai-policy/six-chinese-ai-firms-accused-of-aggr… · home topics ai-policy article
[ARTICLE · art-125031] src=arstechnica.com ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

Six Chinese AI firms accused of aggressively copying US frontier models

The NSA, CISA, and FBI jointly accused six Chinese AI firms—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—of conducting industrial-scale distillation of US frontier AI models since late 2024, allegedly with Chinese government awareness. The agencies said the firms extracted capabilities from models including Claude, GPT, Gemini, and Grok, shortening their development timelines and reducing costs, and urged US AI firms to coordinate with government and allies to counter the theft.

by read2 min views5 publishedSep 9, 2026
Six Chinese AI firms accused of aggressively copying US frontier models
Image: Arstechnica (auto-discovered)

The United States has now named six Chinese AI firms accused of waging industrial-scale attacks distilling US frontier AI model capabilities and perhaps sparing billions in Chinese development costs.

In a joint release Tuesday, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) alleged that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been attacking US models since at least late 2024. The firms “likely” acted with “Chinese government awareness” when extracting capabilities from US models, including variants of Claude, GPT, Gemini, and Grok, agencies said.

“China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model,” agencies said.

All American AI firms must work with the government and US allies to end the alleged theft threatening the US lead in the AI race, the agencies said. That will require coordinated action across the AI ecosystem to combat the “aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of US frontier AI models.”

Attack methods include “exploiting AI model inference APIs” by bulk-buying fake accounts, agencies said. Not registered to legitimate users, these swarms of fraudulent accounts execute “highly coordinated queries featuring identical or similar prompt texts,” which range “from thousands to millions on similar topics.”

Another common method is using prompt injection techniques to jailbreak models, including crafting “prompts forcing models to reveal their hidden [chain-of-thought] reasoning,” agencies said. For example, “DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step.”

Fixes may frustrate AI users in US #

To encourage firms to work together, agencies recommended mitigations that would supposedly make it harder for Chinese firms to steal from US models.

First, AI firms must improve detection of sophisticated campaigns that allegedly use tens of thousands of accounts relying on “a gray market of proxies” to evade geographical restrictions and “route distillation requests through multiple pathways to gain unauthorized access.”

── more in #ai-policy 4 stories · sorted by recency
── more on @nsa 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/six-chinese-ai-firms…] indexed:0 read:2min 2026-09-09 ·