US accuses Chinese AI firms of distilling frontier models
TECH

US accuses Chinese AI firms of distilling frontier models

37+
Signals

Strategic Overview

  • 01.
    On September 8, 2026, the NSA, CISA, and FBI released a joint cybersecurity advisory (AA26-251A) accusing six China-based AI companies of running industrial-scale knowledge-distillation campaigns against U.S. frontier AI models since at least late 2024.
  • 02.
    The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as having extracted proprietary capabilities from Claude, GPT, Gemini, and Grok.
  • 03.
    Anthropic's own investigation found DeepSeek, Moonshot AI, and MiniMax generated more than 16 million exchanges with Claude through roughly 24,000 fraudulent accounts organized into 'hydra cluster' proxy networks.
  • 04.
    China's Ministry of Commerce rejected the allegations as baseless and politically motivated, called distillation a neutral practice used globally including by American firms, and warned of retaliatory countermeasures.

Deep Analysis

Inside the Extraction Playbook

On September 8, 2026, the NSA, CISA, and FBI released joint advisory AA26-251A warning that 'China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities' [1]. The advisory and Anthropic's parallel investigation describe a common playbook: gray-market proxy 'transfer stations,' native APIs, cloud platforms, and third-party aggregators used to funnel prompts to frontier models, paired with automated failover when one access route is blocked [4]. Anthropic's own telemetry ties DeepSeek, Moonshot AI, and MiniMax to more than 16 million exchanges with Claude routed through roughly 24,000 fraudulent accounts organized into what the company calls 'hydra cluster architectures,' with one proxy network alone running more than 20,000 fraudulent accounts [2][3].

MiniMax's traffic pattern illustrates the speed of the operation: 'When we released a new model during MiniMax's active campaign, they pivoted within 24 hours, redirecting nearly half their traffic to capture capabilities from our latest system,' Anthropic said, adding that MiniMax also used prompt injection against Claude Code [2]. That same tool has its own complication: in July 2026 Anthropic shipped Claude Code 2.1.197, which removed a proxy-fingerprint detection mechanism covering 147 Chinese domains, and the company has since promised a fix [9].

A Contested Verdict

Security professionals largely back Washington's framing. Ismael Valenzuela of Arctic Wolf called the campaign 'abuse of legitimate access by sophisticated, well-resourced adversaries' [6], while Databricks CEO Ali Ghodsi pointed to the underlying economics: the extracted capability is 'just so extremely powerful and so extremely cheap, and it's just available to anyone' [3].

But the verdict is not unanimous. Commentary on X reframed the advisory as a shift from hardware export controls to a cognitive-extraction lens - 'copying the brain, not the chip' - and noted that skepticism echoed even among some US AI researchers, including some at OpenAI, who see distillation as a normal industry practice rather than a uniquely Chinese offense. China's Ministry of Commerce rejected the accusations outright, calling distillation 'a neutral and widely used industry practice employed by companies around the world, including American firms' [7].

Six Companies, One Playbook, Different Scales

The six named companies show a wide range of technique and scale. DeepSeek is accused of distilling four versions of Claude, two versions of Gemini, five versions of ChatGPT, and Grok 4, generating more than 150,000 exchanges with Claude alone [1][2]. Moonshot AI's campaign was larger still - 18 different U.S. models distilled to build its Kimi-K2/K3 line, with more than 3.4 million Claude exchanges logged [1][2]. MiniMax is accused of chain-of-thought and reinforcement-learning (RL) data extraction, generating more than 13 million Claude exchanges [2][3].

Alibaba's activity was described as industrial-scale distillation aimed at improving its Qwen model family [4]; StepFun was flagged for extracting reasoning and coding capability across late 2025 and early 2026, and Z.AI for pulling billions of tokens out of GPT-5.5 and Claude Opus [4]. Even framed at this range of scale, all six cases rely on the same underlying mechanics detailed in the advisory - fraudulent accounts and proxy infrastructure built to look like ordinary usage.

Beijing's Countercharge

China's response has moved beyond rhetoric. Its Commerce Ministry warned that 'if the US takes action to contain or suppress Chinese AI companies in the name of combating distillation, China will certainly take resolute measures in response' [7], a threat landing just ahead of planned Trump-Xi talks [8].

Some outlets have already reframed the dispute as a cybersecurity matter rather than a trade one [5], and the advisory itself steers U.S. companies toward defensive measures - subscription-to-usage monitoring, deliberate response degradation for suspected scraping traffic, and closer intelligence sharing - rather than purely legal remedies [1]. With both governments talking past each other on whether large-scale model querying is theft or ordinary practice, how - or whether - that gap closes could shape the negotiating posture on AI policy well beyond this single advisory.

Historical Context

since 2024-12
China-based distillation campaigns against U.S. frontier models began at least as early as late 2024, according to the joint advisory.
2026-02-23
Anthropic first publicly accused DeepSeek, MiniMax, and Moonshot AI of distilling Claude models to build competing systems, ahead of a separate U.S. debate over AI chip export controls.
2026-07-01
Anthropic shipped Claude Code version 2.1.197, which removed a proxy-fingerprint detection mechanism covering 147 Chinese domains, and has since promised a fix.
2026-09-08
The three agencies released joint advisory AA26-251A, naming six China-based AI companies over industrial-scale distillation activity.
2026-09-09
China's Ministry of Commerce publicly rejected the U.S. allegations and warned of retaliatory countermeasures, with the dispute surfacing ahead of planned Trump-Xi talks.

Power Map

Key Players
Subject

US accuses Chinese AI firms of distilling frontier models

NS

NSA, CISA, and FBI

Joint authors of advisory AA26-251A, warning that China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale, and naming six companies as responsible.

DE

DeepSeek

Accused of distilling four versions of Claude, two versions of Gemini, five versions of ChatGPT, and Grok 4, generating more than 150,000 exchanges with Claude.

MO

Moonshot AI

Accused of distilling 18 different U.S. models to build its Kimi-K2/K3 line, generating more than 3.4 million exchanges with Claude.

AL

Alibaba

Accused of running industrial-scale distillation activity aimed at improving its Qwen model family.

MI

MiniMax

Accused of chain-of-thought and reinforcement-learning (RL) data extraction, generating more than 13 million exchanges with Claude through roughly 24,000 fraudulent accounts, pivoting nearly half its traffic to new Claude releases within 24 hours, and using prompt injection against Claude Code.

ST

StepFun

Accused of extracting reasoning and coding capability from U.S. frontier models across late 2025 and early 2026.

Z.

Z.AI

Accused of extracting billions of tokens from GPT-5.5 and Claude Opus.

AN

Anthropic

Targeted company that conducted its own investigation and published detailed findings on the fraudulent-account networks and hydra-cluster proxy architecture used against Claude.

CH

China's Ministry of Commerce

Rejected the U.S. allegations as baseless and politically motivated, called distillation a neutral and widely used industry practice, and warned of resolute retaliatory measures if the U.S. uses the claims to justify containment of Chinese AI firms.

CH

China's Ministry of Foreign Affairs

Separately urged Washington to refrain from unfounded accusations against Chinese companies.

Fact Check

9 cited
  1. [1] AA26-251A: China-Based AI Companies' Distillation of US AI Models
  2. [2] Detecting and Preventing Distillation Attacks
  3. [3] Anthropic Says DeepSeek, Moonshot, and MiniMax Used 24,000 Fake Accounts
  4. [4] US Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models
  5. [5] China's Malicious AI Knowledge Distillation Against US Companies
  6. [6] US Agencies Accuse China AI Firms of Industrial-Scale Distillation
  7. [7] China Rejects US Claims of Industrial-Scale AI Model Distillation, Warns of Retaliation
  8. [8] China Hitting Back at US Claims of Malicious AI Distillation Ahead of Planned Talks
  9. [9] Claude Code Hid Proxy Fingerprints in System Prompts, Anthropic Promises Fix

Source Articles

Top 5

THE SIGNAL.

Analysts

Frames the distillation campaigns as abuse of legitimate access by sophisticated, well-resourced adversaries deliberately distributing operations to evade detection, comparable to credential-stuffing tactics.

Ismael Valenzuela, Arctic Wolf
Cybersecurity industry analyst

Describes distillation as an extremely powerful, extremely cheap technique broadly available to anyone, underscoring why it is attractive regardless of legality concerns.

Ali Ghodsi, CEO of Databricks
Industry executive commenting on distillation broadly
The Crowd

This is crazy! The US is gearing up for a serious crackdown on Chinese AI labs. And distillation is right at the center of it. What used to just be OpenAI and Anthropic complaining about Chinese labs distilling their models is now an issue the FBI, NSA and CISA are treating as a national security matter.

@@zhodonx70

CHINA MAY BE COPYING THE BRAIN, NOT THE CHIP America has focused heavily on preventing China from acquiring the most advanced computer chips. But the next phase of the AI competition may involve extracting the capabilities of American models after those chips have already done the work.

@@DecodeConflict59

The US accuses Chinese AI companies of carrying out aggressive distillation on an industrial scale. China rejects the accusation, saying it is unsupported by evidence and has no legal basis. Even some American researchers question the US narrative. Researchers including OpenAI staff have noted distillation is a common industry practice.

@@MediaUnlock23
Broadcast
Behind China's rapid AI ascent

Behind China's rapid AI ascent

Why Anthropic is right to fear Chinese AI distillation

Why Anthropic is right to fear Chinese AI distillation

USA Fighting Chinese AI Distillation Attacks - America Losing to China

USA Fighting Chinese AI Distillation Attacks - America Losing to China