On Tuesday, U.S. security agencies, including the National Security Agency and the Federal Bureau of Investigation, publicly accused six Chinese artificial intelligence companies of systematically exploiting American AI models. The agencies claimed that these companies have engaged in aggressive and targeted distillation activities on an industrial scale to train their own AI systems. This allegation raises significant concerns regarding the integrity of U.S. technological advancements and the potential implications for national security.
In July, an Anthropic executive said distillation had helped China narrow the gap with the U.S. from 12 to 18 months down to roughly six to nine months.
The U.S. security agencies said the Chinese companies have engaged in millions of exchanges with frontier U.S. models including Claude, ChatGPT, Gemini and Grok. The U.S. agencies said the scale of the Chinese campaigns showed distillation was “the critical core” of China’s AI development, not just a supplement. The accused companies haven’t directly denied distillation, but an executive at Beijing-based Moonshot AI told local media in July after releasing Kimi K3 that the model’s “breakthrough performance” relied on fundamental innovations, not distillation or copying. An official at China’s foreign ministry said in July that foreign countries were hyping the concept of distillation from malicious motives. By itself, this distillation probably falls short of theft, according to some legal specialists. But the U.S. says Chinese methods of distillation are illicit. Anthropic in February said Chinese companies used “fraudulent accounts and proxy services to access Claude at scale while evading detection.
Start with the basics of building an AI model. Developers such as Anthropic and OpenAI gather all the materials they can find from the internet and books , throw it into a big blender with fancy math, and build a neural network modeled on the human brain. This network links words through connections of various weights. A model trained this way can produce natural-sounding sentences by stringing one word after another. China sees it differently. When AI developers distill closed models such as Claude, it is a tougher question. They say the output of AI models is unlikely to be considered intellectual property akin to a book or a movie. Even if it were, distillers aren’t directly copying that output, just using it to learn, like an aspiring writer reading books. Anthropic’s terms of service prohibit Chinese companies from using Claude, with other U.S. companies setting similar rules. Some companies say in their user policies that distillation for developing competing models isn’t allowed.

