Three U.S. intelligence and national security agencies have issued a joint advisory accusing prominent Chinese artificial intelligence developers of executing systematic, industrial-scale extraction campaigns against leading American frontier models. According to the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation, Chinese firms extracted billions of tokens across millions of requests since late 2024 to accelerate their own artificial intelligence capabilities.
The public warning names six major Chinese commercial entities—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—and asserts that their actions likely occurred with the knowledge of the Chinese government. The allegations surface weeks before scheduled bilateral talks on artificial intelligence governance and a planned summit in Washington between U.S. President Donald Trump and Chinese President Xi Jinping on September 24.
Industrial-Scale Extraction and Evasion Tactics
According to the joint advisory, Chinese firms targeted advanced systems including variants of Anthropic's Claude, OpenAI's ChatGPT, Alphabet's Google Gemini, and SpaceXAI's Grok. The security agencies detailed how these entities utilized a technique known as distillation, in which a smaller artificial intelligence model systematically queries a larger, more advanced model to learn from its underlying capabilities without incurring the immense computational costs of baseline training.
While model distillation is a standard technique in machine learning research to optimize model size, federal authorities asserted that Chinese developers abused the process to extract proprietary functionalities. The advisory stated that China-based companies route distillation requests through multiple pathways to gain unauthorized access, deliberately violating terms of service. These pathways include native application programming interfaces, remote cloud infrastructure, and third-party aggregators designed to automatically obfuscate user metadata to evade detection.
"China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection," the joint advisory stated. "They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership."
National Security Risks and Military Applications
U.S. intelligence officials warned that the systematic copying of proprietary architecture extends beyond commercial competition, posing direct national security risks. The joint release noted that distillation drastically compresses research and development timelines while enhancing capabilities that could be applied in military operations and cyberattacks against the U.S. and its international allies.
The federal advisory aligns with broader official scrutiny regarding technological transfer. Reporting from late July revealed that Chinese military researchers previously leveraged outputs from top-tier American models to train domestic defense systems. Furthermore, White House Office of Science and Technology Policy Director Michael Kratsios singled out Moonshot AI in July for attempting to extract proprietary capabilities from Anthropic's advanced Fable model, following similar formal claims made by Anthropic earlier in the year.
In response to the persistent threat of intellectual property diversion, industry advocacy groups have increased pressure on the White House to enact stricter controls on advanced hardware exports, including advanced semiconductor chips required to operate commercial AI models.
Economic Rhetoric and Homework Comparison
Addressing the joint allegations on Tuesday, U.S. Treasury Secretary Scott Bessent dismissed the possibility of China surpassing American technological capabilities through distillation. Speaking at Southern Methodist University's Cox School of Business in Dallas, Bessent argued that reliance on copying inherently caps a competitor's potential relative to the industry pioneer.
"The technical word for stealing and copying American AI models is distillation. So, the Chinese distil our models and they can never get ahead of us," Bessent said during the event. "It’s kind of like if you’re looking over someone’s shoulder, copying their homework, you can never get a higher grade than they do."
Bessent also framed the technology gap around structural governance differences, claiming Beijing's reliance on central planning in artificial intelligence would fail due to the state's unwillingness to relinquish strict control over information. He suggested Chinese leaders harbor anxiety that powerful, unrestricted models could eventually challenge regime stability, contrasting that with American efforts focused on safety and serving citizens.
Beijing Rejects Allegations and Cites Progress Containment
The Chinese government pushed back against the federal advisory and executive statements. Chinese Embassy spokesman Liu Chang characterized the U.S. position as a deliberate campaign to block China's legitimate technological advancement, calling on Washington to abandon what Beijing describes as ideological bias.
"We urge the US to respect facts, discard bias, stop its containment on China’s sci-tech development and choose the course of action conducive to sci-tech exchanges and cooperation between China and the US," Liu told reporting outlets, adding that the framing of distillation by the Trump administration was a "deliberate attack on China’s development and progress in the AI industry." Liu warned that American restrictions and allegations "will only stifle global AI advances and serve no one’s interests."
The exchange marks a repeat of diplomatic friction surrounding artificial intelligence intellectual property, following similar U.S. accusations made in April prior to President Trump's visit to Beijing.
Diplomatic Frameworks and Strategic AI Rivalry
The escalating dispute arrives as both nations prepare for bilateral governance discussions ahead of President Xi's visit to Washington on September 24. While President Trump expressed optimism regarding the upcoming summit, noting that artificial intelligence leadership remains firmly with the United States, negotiations face friction over agenda setting. Sources familiar with the planning indicate Beijing favors broader discussions on technology trade, whereas Washington insists on limiting dialogue strictly to artificial intelligence safety risks.
The bilateral tension underscores competing global frameworks designed to anchor artificial intelligence development. The United States is promoting its Pax Silica supply chain initiative, led by Under Secretary of State for Economic Affairs Jacob Helberg, while Beijing advances its World Artificial Intelligence Cooperation Organisation. Helberg noted in July that Washington intends to pursue diplomatic discussions in good faith to clarify positions while establishing boundaries for engagement.
To counter systemic extraction, the NSA, CISA, and FBI advised American commercial AI developers to implement three core mitigation protocols: deploying comprehensive API detection tools, establishing technical response changes to limit high-volume automated querying, and building cross-organizational intelligence sharing channels to track evasion methods across cloud networks.