U.S. Accuses Chinese AI Firms of Industrial-Scale Model Extraction
U.S. agencies accuse Chinese AI firms of using industrial-scale distillation to steal proprietary capabilities from top American frontier models.
By Muhamed Porić
September 15, 2026 at 1:26 PM

U.S. federal agencies have formally accused several major Chinese AI companies of conducting industrial-scale model distillation to illicitly extract proprietary capabilities from American frontier models. Authorities claim this campaign has been underway since late 2024. It targets the intellectual property of U.S. leaders to bypass the R&D costs associated with training state-of-the-art systems.
The joint advisory issued by the FBI, NSA, and CISA identifies several Chinese firms, including DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI, as participants in these efforts. These companies are alleged to have targeted U.S. models, including Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini, and xAI’s Grok.
"When [People’s Republic of China] firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table," said Treasury Secretary Scott Bessent in a statement regarding the advisory.
The Mechanism of Model Distillation
Distillation is a technical practice in machine learning where a smaller, more efficient student model is trained to mimic the outputs and behaviors of a larger, more powerful teacher model. In standard research contexts, developers use this to create lightweight versions of models that can run on consumer hardware.
However, the U.S. government argues that this process has been weaponized as a strategy to strip American models of their underlying reasoning capabilities and security safeguards. By querying these models millions of times, attackers can effectively clone the performance characteristics of proprietary systems without the multi-billion dollar investment required to develop them from scratch.
Anthropic has provided evidence of the scale of these operations. The company alleges that three Chinese labs utilized approximately 24,000 fraudulent accounts to generate more than 16 million distinct exchanges with its Claude model as part of a coordinated extraction campaign.
Diplomatic and Economic Tensions
The Chinese government has denied the allegations. They characterize the U.S. advisory as a politically motivated attempt to stifle competition.
"The U.S. side’s hyping of the so-called ‘distillation’ concept is deliberate attack on China’s development and progress in the AI industry. China firmly rejects it," said Chinese Foreign Ministry spokesperson Mao Ning.
This confrontation represents an escalation in the geopolitical struggle over AI dominance. Beyond the threat of intellectual property theft, the U.S. government is concerned that the extraction of these capabilities undermines the competitive advantage of American technology firms and could compromise the safety guardrails designed to prevent the misuse of advanced artificial intelligence.
Muhamed Porić
Founder and Editor of Embers.
Newsletter
Get Embers in your inbox
The stories that actually moved something, delivered when there's something worth sending, not daily filler.