US spy agencies accused six Chinese AI firms of industrial-scale distillation of American frontier models, threatening sanctions weeks before the Trump-Xi summit.
US spy agencies accused six Chinese AI firms of industrial-scale distillation of American frontier models, threatening sanctions weeks before the Trump-Xi summit.

US spy agencies accused six Chinese AI developers of siphoning frontier American models at industrial scale, a finding that threatens sanctions and export controls on a sector already under heavy short-selling pressure.
"China opposes politicizing and instrumentalizing trade and tech issues. Such actions will only stifle global AI advances and serve no one's interests," Liu Chang, a spokesperson for the Chinese embassy in Washington, said in an emailed statement.
The joint advisory from the National Security Agency, FBI and Cybersecurity and Infrastructure Security Agency, issued Tuesday, names DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun and Z.AI as running "aggressive, malicious, and targeted distillation activities" since at least late 2024. The agencies said the firms extracted billions of tokens across millions of requests from models including Anthropic's Claude, OpenAI's GPT, Google's Gemini and xAI's Grok, routing queries through native application programming interfaces, remote cloud providers and third-party aggregators to obscure their origin.
The finding lands weeks before President Donald Trump is scheduled to host Chinese counterpart Xi Jinping in Washington, and after Treasury Secretary Scott Bessent warned in July of sanctions for any Chinese venture found to engage in intellectual property theft. Hong Kong-listed shares of the accused firms — Alibaba, MiniMax and Z.AI — carried short ratios of 23.3 percent, 5 percent and 7.4 percent respectively as of Sept. 8, exchange data shows.
Distillation lets a smaller model query a larger one to learn its responses, a legitimate technique when a developer shrinks its own model. OpenAI and Anthropic forbid the practice in their terms of service to protect the billions spent on training. The agencies said the Chinese firms treated it as "the core — not merely a supplement — of their AI development strategy," with Beijing "likely" aware of the campaigns.
The advisory details which US systems each firm distilled and why. DeepSeek drew on Anthropic's Claude 3.7, OpenAI's GPT-4o and Google's Gemini 2.5 Pro Preview to train its R1 and V3 models, the agencies said, calling the company's publicly quoted $5.6 million training cost misleading because it excludes data acquired through distillation. Moonshot AI pulled from Claude Fable 5 for its Kimi-K3 model and GPT-4o for its Kimi-K2, while Alibaba used distillation to improve its free-to-download Qwen family — a direct challenge to US rivals that charge for access.
The agencies also described a gray market of proxies called "transfer stations" that resell access to frontier models at a fraction of the official price, creating a scalable way to bypass geographic restrictions and evade safeguards. They advised US developers to flag immediate maximum usage from new accounts as one indicator of adverse action and to subtly alter responses to suspected distillation attempts.
The advisory stops short of naming enforcement actions, but it hands US lawmakers and the Trump administration a formal intelligence finding to accelerate measures already under consideration. Anthropic in June accused Alibaba of accessing its Claude model through thousands of fraudulent accounts, and Bessent's July warning followed Moonshot's release of Kimi K3, a model that stoked concern about Chinese gains in AI.
For investors, the overhang is twofold: the threat of sanctions that would cut Chinese firms off from US chips and cloud access, and the legal exposure of models trained on distilled data. On Tuesday, Alibaba and MiniMax shares rose 0.5 percent and 1.9 percent respectively while Z.AI slipped 0.5 percent, moves that masked the structural risk the advisory poses. The accusation also carries echoes of the market shock DeepSeek triggered when it claimed to have built a frontier model with minimal computing power, a claim that panicked investors who had poured billions into AI infrastructure. The agencies urged US developers to share intelligence on distillation campaigns across providers, a defensive posture that could raise costs for the very Chinese firms accused of undercutting them.
This article is for informational purposes only and does not constitute investment advice.