US Accuses 6 Chinese AI Firms of "Industrial Scale" Model Theft
Serge Bulaev
U.S. officials say six Chinese AI companies may be copying U.S. AI models on a large scale using knowledge distillation. The agencies warn this could be a security risk and might help Chinese cyber and military research. Reports suggest these firms use automation and many fake accounts to collect data from American AI systems. U.S. authorities are considering actions like financial sanctions, blocking technology sales, and new laws to stop this. Industry groups are also working together to spot and limit suspicious activity.

U.S. intelligence agencies accuse six Chinese AI firms of industrial-scale model theft, alleging they use knowledge distillation to harvest proprietary capabilities from American frontier models. A joint advisory from the NSA, FBI, and CISA named DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun, and Z.ai, urging U.S. AI providers to monitor for massive, coordinated querying patterns. The agencies frame the practice as a major national security and intellectual property threat.
The public accusation
U.S. agencies allege that several Chinese companies are systematically stealing capabilities from American AI models. This is reportedly done using an automated process called 'knowledge distillation' at an industrial scale, involving millions of queries from thousands of fake accounts to replicate the performance of proprietary U.S. systems.
The public accusations escalated throughout 2026. According to a Nextgov memo, the White House warned in April of "deliberate, industrial scale campaigns to distill U.S. frontier AI systems." By August, Treasury Secretary Scott Bessent confirmed that sanctions were a possible response. According to industry reports, Chinese firms are alleged to have engaged in systematic extraction campaigns using millions of API calls hidden behind proxy infrastructure. Security officials characterize these campaigns as highly aggressive, automating prompt acquisition, high-volume querying, and data filtering to rapidly build training sets. For instance, Anthropic reported detecting one effort that involved 24,000 fraudulent accounts and generated 16 million request-response pairs.
How large scale distillation works
Knowledge distillation is a common technique for compressing large models, but the agencies focus on a variant that scrapes teacher outputs at industrial volume. Public technical writeups outline several methods:
| Method | Core idea | Reported advantage |
|---|---|---|
| Response distillation | Train student on teacher's final answers | Simple to automate over huge prompt sets |
| Soft label distillation | Copy probability distributions | Transfers richer signal with fewer examples |
| Reasoning trajectory distillation | Capture chain of thought traces | Improves math and logic benchmarks |
At an industrial scale, this activity generates distinct technical signatures. Security teams look for red flags like synchronized query bursts from many accounts, the use of repetitive prompt templates, and traffic routed through proxy relays to obscure its origin. To counter this, CISA's advisory recommends that providers implement robust cross-account linkage analysis and aggressive rate limiting to disrupt these patterns.
Policy options now on the table
The U.S. government is considering a multi-pronged response, although no final decisions have been made. Key policy levers being discussed include:
- Technology Restrictions: Placing the accused firms on the Commerce Department's Entity List, which would block them from purchasing U.S. cloud services or advanced chips.
- Financial Sanctions: The Treasury Department is exploring targeted financial penalties. According to CNBC, Secretary Bessent stated this option "remains available if overseas models are stealing from our great companies."
- New Legislation: The proposed Deterring American AI Model Theft Act would mandate formal assessments of model extraction threats and authorize new penalties.
In parallel, the private sector is organizing its own defenses. U.S. AI labs have begun sharing telemetry on suspected scraping campaigns, and industry experts are pushing for a standardized reporting format to flag malicious traffic more effectively. This emerging focus suggests that model access policies are becoming as critical as hardware export controls in the strategic U.S. - China AI competition.
What companies are accused of industrial-scale AI model theft?
The joint statement from the NSA, FBI, and CISA names six China-based AI firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.ai. These companies are alleged to have engaged in systematic extraction of proprietary functionalities from American frontier AI models through what officials describe as "deliberate, industrial-scale campaigns" of model distillation.
How does "large-scale distillation" work as an alleged theft method?
Distillation itself is a legitimate research technique where a smaller "student" model learns from a larger "teacher" model's outputs. However, U.S. agencies allege these Chinese firms deployed it maliciously at industrial scale - using techniques like:
- Response distillation: Training student models on millions of teacher-generated answers
- Chain-of-thought elicitation: Extracting full reasoning traces, not just final outputs
- Coordinated infrastructure: Employing proxy services and tens of thousands of fraudulent accounts to disguise massive API querying
According to technical reports, detection systems flag high-volume repetitive querying, coordinated prompt patterns, and cross-account linkage through IP correlation as key indicators of these campaigns.
What specific evidence has been made public about Moonshot AI?
Moonshot AI is among the companies named in the allegations, though specific technical details about their methods remain largely unverified. Despite these accusations, Moonshot's models have gained market attention, demonstrating how distillation - whether authorized or not - can rapidly elevate a competitor's market position.
What policy responses is the U.S. government considering?
The Biden administration has escalated from public warnings toward concrete enforcement mechanisms:
- April 2026: White House memo directed agencies to improve coordination with U.S. AI firms and explore accountability measures
- July 2026: Treasury Secretary Scott Bessent stated the U.S. could impose financial sanctions or Entity List designations on Chinese AI firms found to be stealing American IP
- Legislative action: The Deterring American AI Model Theft Act of 2026 would authorize sanctions and Entity List actions against identified entities
The administration has also faced calls to halt exports of advanced AI chips to China, with experts arguing such hardware enables Chinese firms to develop comparable capabilities even when facing model-access restrictions.
Why does this matter beyond intellectual property?
The allegations carry national security dimensions that extend far beyond commercial competition. U.S. officials have linked these activities to military and cyber capability development - Reuters reported that Chinese military researchers used outputs from OpenAI and Anthropic models to train domestic defense systems, based on a review of more than 80 papers and patents.
The dispute reflects a broader strategic vulnerability: if frontier-model outputs can be systematically harvested at scale, the United States' multi-billion dollar lead in AI development could erode faster than hardware restrictions alone would predict, potentially "locking in gains" for the Chinese AI ecosystem at a critical competitive moment.