{"slug": "us-security-agencies-accuse-chinese-ai-firms-of-intellectual-property-theft", "title": "US security agencies accuse Chinese AI firms of intellectual property theft", "summary": "The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) jointly accused six Chinese AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—of conducting an industrial-scale knowledge distillation campaign since late 2024, extracting billions of tokens from Anthropic's Claude, OpenAI's GPT series, Google's Gemini, and xAI's Grok. The advisory claims the firms used proxies and shared accounts to circumvent terms of service, and suggests the operations were likely conducted with Chinese government knowledge. US Treasury Secretary Scott Bessent indicated sanctions or Entity List designations could follow.", "body_md": "Photo: toter yau / Pexels\n\n# US security agencies accuse Chinese AI firms of intellectual property theft\n\nCISA, NSA, and FBI allege six Chinese companies extracted billions of tokens from leading American AI models in coordinated distillation campaign\n\nThree of America’s most powerful security agencies just pointed a very large finger at six Chinese AI companies, accusing them of systematically siphoning knowledge from the country’s most advanced AI models. The joint advisory from CISA, the NSA, and the FBI describes what officials are calling an industrial-scale extraction campaign that has been running since late 2024.\n\nThe targets: Anthropic’s Claude, OpenAI’s GPT series, [Google](https://cryptobriefing.com/markets/alphabet/)’s Gemini, and xAI’s Grok. The accused: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The method: knowledge distillation, a machine learning technique that’s perfectly legal on its own but allegedly weaponized here to copy the outputs of frontier AI systems at a staggering scale.\n\n## How distillation becomes espionage\n\nKnowledge distillation is a well-known technique in machine learning. A smaller “student” model learns to mimic the behavior of a larger “teacher” model by studying its outputs. The technique itself isn’t controversial. Researchers use it all the time to build lighter, faster models.\n\nWhat makes this case different, according to US officials, is the sheer scale and the alleged coordination behind it. The advisory describes millions of requests made against American AI systems, resulting in the extraction of billions of tokens worth of output data.\n\nThe accused firms allegedly used proxies, shared accounts, and various evasion tactics to circumvent the terms of service that govern access to these models.\n\nUS officials went further, suggesting these weren’t rogue corporate operations. The advisory states that the extraction efforts were likely conducted with the knowledge of the Chinese government, framing the activity as part of Beijing’s broader strategy to close the AI gap with the United States.\n\n## Escalation from earlier warnings\n\nThis advisory didn’t arrive out of nowhere. It builds on accusations first made by the White House back in April 2026, which flagged similar industrial-scale distillation campaigns and noted the use of advanced circumvention measures to avoid detection. The September advisory essentially upgrades those warnings from “we’ve noticed something” to “here are the names.”\n\nUS Treasury Secretary Scott Bessent has already indicated that sanctions or Entity List designations could be on the table. Being placed on the Entity List would restrict American companies from doing business with the named firms, cutting off access to US technology, cloud services, and potentially even hardware.\n\nChina’s response has been predictable. Officials in Beijing dismissed the allegations as baseless.\n\n## What’s actually at stake\n\nAmerican AI companies whose models were targeted, including Anthropic, OpenAI, Google, and xAI, will face pressure to demonstrate that their systems can detect and prevent large-scale extraction attempts. The advisory explicitly encourages US AI providers to adopt detection and mitigation measures.\n\nThe advisory also raises a thorny technical question: how do you actually prevent distillation at scale? Unlike stealing source code or hardware designs, distillation works by interacting with a model through its normal interface. Every API call returns useful data. Drawing the line between legitimate heavy usage and systematic extraction isn’t straightforward, and any detection system risks flagging legitimate researchers alongside bad actors.\n\nAmerican AI companies have built their businesses partly on broad API access. Locking that down too aggressively could undermine adoption and revenue. Not locking it down enough, according to three federal agencies, means handing your most valuable intellectual property to competitors backed by a rival government.\n\n**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our\n\n[Editorial Policy](https://cryptobriefing.com/editorial-policy/).", "url": "https://wpnews.pro/news/us-security-agencies-accuse-chinese-ai-firms-of-intellectual-property-theft", "canonical_source": "https://cryptobriefing.com/us-agencies-accuse-chinese-ai-firms-ip-theft/", "published_at": "2026-09-09 20:40:01+00:00", "updated_at": "2026-09-09 20:44:16.966566+00:00", "lang": "en", "topics": ["ai-policy", "ai-safety", "artificial-intelligence"], "entities": ["CISA", "NSA", "FBI", "DeepSeek", "Moonshot AI", "Alibaba", "MiniMax", "StepFun"], "alternates": {"html": "https://wpnews.pro/news/us-security-agencies-accuse-chinese-ai-firms-of-intellectual-property-theft", "markdown": "https://wpnews.pro/news/us-security-agencies-accuse-chinese-ai-firms-of-intellectual-property-theft.md", "text": "https://wpnews.pro/news/us-security-agencies-accuse-chinese-ai-firms-of-intellectual-property-theft.txt", "jsonld": "https://wpnews.pro/news/us-security-agencies-accuse-chinese-ai-firms-of-intellectual-property-theft.jsonld"}}