Three American security agencies have put their names to a detailed accusation against six Chinese artificial intelligence companies, and the specifics of the accusation, more than its headline, are what make it consequential.

The FBI, the NSA, and CISA issued a joint advisory on September 8 alleging that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Zhipu AI have been systematically extracting capabilities from American frontier AI models through a technique called knowledge distillation, as reported by AIN. Distillation is a recognized training method in which a smaller model learns to imitate a larger one. What the advisory alleges is not ordinary research: it describes an "industrial-scale" effort, running since at least late 2024, that pulled billions of tokens from American models through millions of interactions.

What the advisory claims

The advisory names specific targets and specific methods. The models allegedly tapped include Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok. The extracted capabilities, according to the agencies, span reasoning, coding, reinforcement learning, fine-tuning techniques, agentic workflows, mathematics, and software engineering.

The methods described are designed around access control. The advisory alleges the firms used native APIs, remote cloud services, third-party aggregation platforms, and API proxy services referred to as transfer stations, purchased premium accounts shared across development teams, and switched automatically between access channels to hide metadata and bypass geographic restrictions. The agencies say the activity may have been conducted with the knowledge of the Chinese government, and that distillation at this scale reduces research costs and potentially undermines American technological, military, and cybersecurity advantages.

The advisory is a claim, not a finding. No charges have been filed, no court has reviewed the evidence, and the agencies' conclusions carry the weight of their authority, which is substantial but not judicial. The document's second half is practical: it urges American AI developers to monitor for anomalous accounts and prompt patterns, to alter model responses when suspicious distillation queries are detected, and to share threat information among model providers, cloud companies, and API aggregators.

Beijing's answer, stated plainly

China's Ministry of Commerce responded on September 9, calling the accusations groundless and without legal basis. Its counterargument has two parts. First, it says distillation is a normal commercial technical practice, and that American companies have also distilled Chinese models at scale. Second, it frames the advisory as economic policy wearing a security label: an attempt to use the "crackdown on distillation" as a pretext for industrial monopoly and for stifling Chinese competition. Beijing warned it would resolutely take countermeasures if Washington continues to suppress Chinese AI firms.

The Foreign Ministry's spokesperson, Mao Ning, struck a different register, saying both countries are major AI powers and should strengthen cooperation rather than escalate. The two responses, commercial confrontation and diplomatic openness, capture the dual track Beijing is running.

The advisory itself anticipates the dispute's politics without resolving them. American officials have described the alleged activity in national-security terms, as a threat to an advantage the United States spent heavily to build. Chinese officials describe the same activity as a trade dispute dressed up for a domestic audience. Both framings are assertions about motive, and motive is exactly what a cybersecurity advisory cannot prove.

Why the timing matters

The advisory landed at a delicate moment. A Trump-Xi meeting is planned for late September, and an AI-related security dialogue between the two governments is scheduled for mid-September. An accusation of this specificity, issued weeks before the two leaders sit down, functions as an agenda item whether or not it was intended as one. The sequencing also mirrors a familiar pattern in the technology rivalry: allegations, counter-accusations, and then a negotiation in which both sides bring their versions of the facts to the table.

For the American AI industry, the advisory's operational guidance is the part with immediate consequences. Model providers already watch for API abuse; the advisory's list of evasion methods gives them specific signatures to look for, and its call for information sharing formalizes a response that had been ad hoc. For the six named companies, the accusation adds a compliance burden beyond any legal one, since customers and partners will now ask about the allegations whether or not any are ever proven.

The dispute over who copied what, and whether copying at that scale is a crime or a market practice, will not be resolved by an advisory or a press conference. It will be resolved, if it is resolved at all, by whatever evidence the agencies eventually make public, and by the negotiations now scheduled for the weeks ahead.

Primary sources

  1. FBI, NSA, and CISA joint advisory, as reported by AIN and MarketScreener.
  2. China's Ministry of Commerce response, as reported by Le Figaro.
  3. The Associated Press wire reporting on the advisory and its timing.