{"slug": "us-claims-chinese-ai-companies-core-ai-strategy-is-distilling-american-models", "title": "US claims Chinese AI companies’ core AI strategy is distilling American models", "summary": "The NSA, FBI, and CISA jointly accused Chinese AI companies including DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI of conducting 'industrial-scale' distillation of U.S. frontier AI models, calling it 'the core' of their AI development strategy. The advisory alleges these firms violate terms of use via APIs, cloud providers, and 'transfer stations' to extract proprietary capabilities, and that DeepSeek's claims of low-cost training were false due to synthetic data from distillation.", "body_md": "# US claims Chinese AI companies’ core AI strategy is distilling American models\n\nSource: \n\n[The Register](https://www.theregister.com)\nSpooks and CISA point to ‘industrial-scale distillation’ by DeepSeek, Alibaba, and other Chinese players\n\n Two US intelligence agencies and the nation’s cyber-defense org CISA have accused Chinese AI companies of running “aggressive, malicious, and targeted \n\n[distillation](/glossary/distillation)activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models.” A Tuesday joint advisory from The National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA), alleges that China’s government is “likely” aware of distillation campaigns conducted by[DeepSeek](/compare/llama-4-vs-deepseek-r1), Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies claim that distillation is “the core – not merely a supplement – of their AI development strategy.” Distillation is a process that sees a small model query a larger model to learn how it responds. Over time, the smaller model’s performance improves. Distillation can be a legitimate use of a model if, for example, the organization that creates a model wants to make a smaller version of it without needing to go through the lengthy and expensive process of[training](/glossary/training)a new model. Providers of commercial models, however, generally use their terms and conditions to forbid activity that would allow distillation, to protect the substantial investment in technology and training that goes into creating a model. The three agencies that issued this advisory believe Chinese AI companies flout those terms. “China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use,” the advisory states. “These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection.” The spooks also think China uses “a gray market of proxies known as ‘transfer stations’ to bypass U.S. AI companies’ geographic restrictions, breach terms of use, evade safeguards, and undermine traceability.” Transfer stations apparently “resell access to frontier models at a fraction of the official price [and] create a scalable mechanism for evading provider safeguards and eroding traceability.” The advisory outlines attacks that didn’t just distill models; they also moved markets. For example, the document accuses DeepSeek of using distillation to generate[synthetic data](/glossary/synthetic-data)used to train its models, making its claim of having created them with trivial quantities of computing power false. That’s a notable accusation because DeepSeek’s claims panicked investors who worried that the billions they pumped into infrastructure may not be needed. Another allegation suggests “Alibaba leveraged industrial-scale distillation to improve the company’s Qwen family of AI models.” Some Qwen models are very high quality, and free to download and use – a direct challenge to US-based AI outfits who charge for access to their models but continue to make massive losses. The spooks and CISA recommend AI companies attempt to detect and deflect distillation attacks and suggest immediate maximum usage from new accounts is one indicator of adverse action. “Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns,” is another suggested defense, as is correlating activity across different model providers, cloud platforms, and API aggregators in the hope that doing so reveals distributed distillation campaigns. US government agencies have made many similar accusations in recent months. China has responded with accusations that US companies are the real villains as they distill Chinese models, plus veiled threats that it will respond to any US bans on its tech that flow from distillation allegations. The Register has soughtcomment from Chinese AI companies and will update this story if we receive a substantial response. ®\nGet AI news in your inbox\n\nDaily digest of what matters in AI.", "url": "https://wpnews.pro/news/us-claims-chinese-ai-companies-core-ai-strategy-is-distilling-american-models", "canonical_source": "https://www.machinebrief.com/news/us-claims-chinese-ai-companies-core-ai-strategy-is-distillin-ynxd", "published_at": "2026-09-09 02:59:20+00:00", "updated_at": "2026-09-09 09:06:54.159543+00:00", "lang": "en", "topics": ["ai-policy", "ai-safety", "artificial-intelligence"], "entities": ["NSA", "FBI", "CISA", "DeepSeek", "Alibaba", "Moonshot AI", "MiniMax", "StepFun"], "alternates": {"html": "https://wpnews.pro/news/us-claims-chinese-ai-companies-core-ai-strategy-is-distilling-american-models", "markdown": "https://wpnews.pro/news/us-claims-chinese-ai-companies-core-ai-strategy-is-distilling-american-models.md", "text": "https://wpnews.pro/news/us-claims-chinese-ai-companies-core-ai-strategy-is-distilling-american-models.txt", "jsonld": "https://wpnews.pro/news/us-claims-chinese-ai-companies-core-ai-strategy-is-distilling-american-models.jsonld"}}