AI

US Security Agencies Accuse Six Chinese AI Firms of Distillation as Beijing Pushes Back

A joint advisory from the NSA, FBI and CISA names DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI, while China's commerce ministry calls the distillation allegations baseless and threatens countermeasures.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 10, 2026 / Updated September 13, 2026 / 7 min read

The U.S. government on September 8, 2026, accused six Chinese artificial intelligence companies of using a technique known as distillation to copy proprietary capabilities from American AI models, according to a joint statement from U.S. law enforcement and intelligence officials. The companies named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The statement said the firms targeted models from Anthropic, OpenAI, Alphabet's Google and SpaceX.

The allegations landed as the administration of President Donald Trump prepares for Chinese President Xi Jinping's visit to the U.S. in late September, and as the two countries gear up to discuss AI safety risks during a dialogue planned for mid-September. U.S. officials said the Chinese companies copied U.S. AI labs' intellectual property through distillation, which is the process of training smaller AI models using output from larger, more expensive ones to lower training costs. They said the companies did so 'likely with Chinese government awareness'.

China's Ministry of Commerce rejected the claims on September 9, saying the allegations lacked factual basis and legal grounding. It accused the U.S. of double standards and of trying to suppress competition, called distillation a widely used 'neutral technical method in nature', and said some U.S. companies had also 'extensively distilled Chinese models'. A Chinese foreign ministry spokesperson said, 'We hope the U.S. will earnestly implement the important consensus reached by the leaders of both countries and refrain from making false accusations and smearing China.'

The joint advisory was issued by the National Security Agency, the Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency, according to Cybernews. It said the alleged campaign used distillation to help train Chinese models, including DeepSeek R1 and Qwen V3. The advisory urged U.S. AI firms to detect and limit suspicious requests. Distillation is where an AI model is trained to mimic the output of a larger, more capable one. The method is widely used across the industry, but Washington says Chinese firms have deployed it at scale to illicitly copy American systems.

Key Facts

Reuters reported on September 8 that the U.S. government accused Chinese artificial intelligence companies of maliciously copying technology from American AI firms. The Chinese companies copied U.S. AI labs' intellectual property through distillation, according to a statement from U.S. law enforcement and intelligence officials. U.S. officials accused six Chinese companies, including DeepSeek, Moonshot AI and Alibaba (9988.HK), of tapping variants of American-made AI models to train their AI products more quickly. The companies did so 'likely with Chinese government awareness', the statement said, adding that the Chinese firms targeted AI models from Anthropic, OpenAI, Alphabet's Google (GOOGL.O) and SpaceX (SPCX.O). 'China-based AI companies are engaging in aggressive, malicious and targeted distillation activities at an industrial scale,' the officials said.

The Straits Times reported on September 9 that Chinese foreign ministry spokeswoman Mao Ning said China's AI advances were the result of 'achieving high-level science and technological self-reliance'. She said, 'As major powers in artificial intelligence, China and the U.S. should strengthen cooperation.' The Straits Times also noted that the U.S. made a similar accusation in April ahead of Trump's visit to Beijing, and that Reuters reported on July 31 that Chinese military researchers have used outputs from leading U.S. AI models to train domestic Chinese AI systems and advance China's defense capabilities.

AFP reported on September 9 that the advisory said Chinese firms were conducting 'systematic extraction of proprietary functionalities and capabilities of U.S. AI companies' models'. They are doing so 'through industrial-scale knowledge distillation campaigns that form the core, not merely a supplement, of their AI development strategy', it said. The advisory detailed how DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI allegedly used millions of exchanges and requests to steal the capabilities of U.S. models from the likes of OpenAI, Anthropic, Google and xAI. These actions, taken 'likely with Chinese government awareness', have taken place since at least late 2024, it said. AFP contacted the Chinese companies apart from StepFun, which was not immediately reachable. Moonshot AI declined to comment.

Cybernews reported on September 9 that CISA, the NSA and the FBI urge U.S. AI firms to detect and limit suspicious requests. The report said the alleged campaign helped train Chinese models including DeepSeek R1 and Qwen V3, and that China has targeted Claude, Grok, ChatGPT, and Gemini. The U.S. alleges that companies like Alibaba, the creator of Qwen, have turned knowledge distillation into an industrial-sized campaign to fine-tune its family of AI models. This is being called a 'distillation campaign', in which a 'legitimate and useful' AI research technique is turned into an 'aggressive, malicious, and targeted' attack on restricted proprietary information belonging to the U.S. China has allegedly done this by routing distillation requests through multiple pathways to gain unauthorized access to U.S. models.

China's commerce ministry said on September 9 that the allegations lacked factual basis and legal grounding, accused the U.S. of double standards and of trying to suppress competition, and said some U.S. companies had also 'extensively distilled Chinese models'. 'If the U.S. uses cracking down on distillation as a pretext to take actions to contain or suppress Chinese AI companies, China will certainly take resolute measures in response,' it said. The U.S. statement alleged the distillation not only reduces R&D costs for Chinese AI firms but also enhances China's 'military and cyberattack capabilities that could be used against the U.S. and our allies'. The U.S. made a similar accusation in April ahead of Trump's visit to Beijing.

Analysis

The bigger picture here is that the distillation dispute is not merely a technical disagreement about AI research methods. It is the latest flashpoint in a broader struggle for technological supremacy between the world's two largest economies, and it is unfolding against a tightly packed diplomatic calendar. The U.S. accusation arrived on September 8, just days before a planned mid-September U.S.-China dialogue on AI safety risks and weeks before Xi Jinping's expected visit to the White House in late September. The timing suggests that Washington wants to put Beijing on the defensive before those high-stakes conversations, while China's swift rejection on September 9 signals that it will not easily concede ground.

What this really means is that both sides are using the distillation issue as a proxy for a much larger contest over who will set the rules for artificial intelligence. The U.S. statement alleged that the distillation not only reduces R&D costs for Chinese AI firms but also enhances China's 'military and cyberattack capabilities that could be used against the U.S. and our allies'. That framing links commercial AI development to national security, which could justify tougher export controls, sanctions or other restrictive measures. China's commerce ministry, by calling distillation a 'neutral technical method in nature' and accusing the U.S. of double standards, is trying to reframe the debate as one about fair competition rather than theft.

The U.S. position is also complicated by domestic pressures. In July, dozens of startups wrote a letter to the Trump administration urging it to think twice against any outright ban or strict curbs on foreign-made AI models, saying this should only be considered for government use. Many companies prefer Chinese AI models because they are cheaper than the more powerful but pricier U.S. versions from Anthropic or OpenAI. Trump is under pressure to respond to the increasing success of Chinese AI models, but aggressive action could alienate parts of the U.S. tech industry that rely on open access to a global talent pool and affordable AI tools.

The accusations also carry historical echoes. The U.S. made a similar accusation in April ahead of Trump's visit to Beijing, and Reuters reported on July 31 that Chinese military researchers have used outputs from leading U.S. AI models to train domestic systems and advance China's defense capabilities. Beijing turned the tables in July by accusing U.S. AI of using Chinese examples to train their models. This back-and-forth suggests that distillation has become a recurring grievance in U.S.-China tech relations, one that is likely to resurface whenever diplomatic tensions rise.

Why It Matters

The outcome of this dispute could shape the global AI landscape for years to come. If the U.S. follows through with penalties or restrictions, it could accelerate the decoupling of the American and Chinese AI ecosystems, forcing companies to choose sides and fragmenting supply chains, research collaborations and talent flows. The advisory's call for U.S. AI firms to detect and limit suspicious requests already signals a push toward tighter monitoring of API usage and model access, which could raise costs and slow innovation for legitimate developers on both sides.

For China, the accusations are a reputational and strategic challenge. By naming six of its most prominent AI companies, including DeepSeek, Moonshot AI and Alibaba, the U.S. is effectively labeling them as untrustworthy actors in the global AI market. That could hurt their ability to attract international partners, customers and investors. China's response, which frames the allegations as a pretext for suppression, is aimed at rallying domestic support and positioning itself as a defender of fair competition and multilateral cooperation.

The timing also matters for AI safety. The planned mid-September dialogue on AI safety risks offers a rare opportunity for the two countries to find common ground on guardrails for advanced AI systems. But the distillation fight could poison that channel before it even begins. If both sides dig in, the world's leading AI powers may miss a critical chance to cooperate on existential risks, from autonomous weapons to misinformation and cyberattacks.

Next Up

All eyes will be on the mid-September U.S.-China dialogue on AI safety risks and on Xi Jinping's expected visit to Washington in late September. China's commerce ministry has warned that if the U.S. uses cracking down on distillation as a pretext to contain or suppress Chinese AI companies, China will certainly take resolute measures in response. That leaves open the possibility of retaliatory measures, further escalation or a negotiated off-ramp.

Meanwhile, U.S. AI firms are being urged to detect and limit suspicious requests, and the companies named in the advisory have largely stayed silent or declined to comment. Moonshot AI declined to comment, while AFP could not immediately reach StepFun. How these companies respond, and whether the U.S. follows up with concrete policy action, will determine whether this remains a rhetorical battle or becomes a new front in the tech cold war.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.