US security agencies have formally accused six Chinese artificial intelligence companies of systematically exploiting American AI models to train their own systems, a practice known as model distillation. The allegations, detailed in a joint advisory from the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Cybersecurity and Infrastructure Security Agency (CISA), highlight a growing concern over intellectual property theft and national security.

The companies named include DeepSeek, Moonshot AI, Alibaba Group Holding, MiniMax, StepFun, and Z.AI. According to the advisory, these firms have engaged in what the agencies describe as “aggressive, malicious, and targeted distillation activities at an industrial scale” since at least 2024, extracting proprietary functionalities from US frontier AI models to develop their own systems.

Read also
Markets
Dow futures slide 300+ points as Brent tops $100, inflation worries resurface
US stock futures fell as Brent crude topped $100 for the first time since July, reviving inflation concerns. Dow futures dropped over 300 points ahead of key data.

What is AI model distillation?

Distillation is a well-established technique in artificial intelligence that transfers capabilities from a large, complex “teacher” model to a smaller, more efficient “student” model. Instead of training from scratch, developers use the outputs of the larger model as training data for the smaller one. This process, formalized by Geoffrey Hinton and his Google colleagues in 2015, allows for significant reductions in computing costs while retaining much of the original model's performance.

In practice, a developer can query a powerful AI model with thousands or millions of prompts, then use those responses to train a new model. The student model learns patterns from the teacher's responses and can eventually replicate many of its capabilities without needing the same level of computational resources. This makes distillation a valuable tool for creating efficient, specialized AI systems.

When does distillation become controversial?

Distillation becomes problematic when it is used to replicate another company's proprietary model without authorization. Competitors can use interactions with a frontier model to generate training data, effectively shortcutting years of research and development. The US security agencies allege that Chinese firms have used multiple pathways to gain unauthorized access to American AI systems, violating terms of service.

OpenAI and Anthropic have separately reported such activities. Anthropic disclosed in February that it had uncovered campaigns involving DeepSeek, Moonshot AI, and MiniMax, which attempted to extract capabilities from its Claude chatbot. These campaigns reportedly involved approximately 16 million exchanges and 24,000 fake accounts, with MiniMax alone accounting for over 13 million exchanges. OpenAI made similar allegations in January.

The emergence of DeepSeek's low-cost AI model last year, which demonstrated capabilities competitive with leading US systems, has intensified scrutiny. The model's performance challenged assumptions about US dominance in frontier AI and raised questions about how Chinese companies achieve comparable results with significantly lower costs.

National security implications

The latest US advisory goes beyond commercial competition, emphasizing potential military and cyber threats. The agencies stated that industrial-scale distillation could reduce research and development costs for Chinese AI companies while enhancing China's “military and cyberattack capabilities that could be used against the US and our allies.” A Reuters report from July 31 noted that Chinese military researchers had used outputs from leading US AI models to train domestic systems and advance defense capabilities.

Anthropic has also warned that illicitly distilled models may lack the safety safeguards built into American frontier models. These safeguards are designed to prevent AI from assisting in activities such as developing biological weapons or conducting malicious cyber operations. If those protections are not transferred, the resulting models could pose significant national security risks.

The allegations come amid broader tensions over AI technology and trade. For investors, the situation underscores the importance of monitoring regulatory developments and geopolitical risks in the AI sector. The outcome of these accusations could influence market dynamics, particularly for companies involved in AI development and cybersecurity. As the debate over intellectual property and competition intensifies, the industry may see increased scrutiny and potential policy changes.

This article is for informational purposes only and does not constitute financial advice.