AI Theft Accusations: US Accuses DeepSeek, Moonshot AI and Other Chinese Firms of Model Distillation
AI Theft Accusations have escalated sharply after US security agencies accused several Chinese artificial intelligence companies of systematically extracting capabilities from leading American AI models through a technique known as knowledge distillation.
The joint cybersecurity advisory, issued by the FBI, National Security Agency and Cybersecurity and Infrastructure Security Agency, named six Chinese AI companies, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. US officials said the activity has been taking place since at least late 2024 and was conducted on an industrial scale.
The allegations add another major point of tension to the rapidly intensifying technology competition between the United States and China.
US Agencies Accuse Chinese AI Firms of Systematic Extraction
According to the US advisory, Chinese AI companies have been using large numbers of requests to American frontier AI models to extract their capabilities and use the resulting outputs to improve their own systems.
The agencies said the activity involved models developed by companies including Anthropic, OpenAI, Google and SpaceX’s AI division. The US government described the operations as aggressive and targeted rather than ordinary experimentation with AI systems.
US officials further alleged that the activity was likely conducted with awareness from the Chinese government.
The accusations represent one of Washington’s strongest public warnings yet about how Chinese AI developers may be acquiring capabilities from US-built frontier models.
What Is AI Distillation?
Knowledge distillation is not inherently an illegal or malicious technology.
In AI development, distillation generally involves using the outputs of a more capable model to help train or improve another model. Developers can ask a powerful AI system questions, collect its responses and use those responses to improve a smaller or newer model.
The technique is widely recognized as a legitimate method in AI research.
The dispute is over how the technique is allegedly being used.
US agencies claim the Chinese companies went far beyond ordinary distillation by systematically sending huge volumes of carefully designed requests to proprietary American models and attempting to extract restricted capabilities.
Billions of Tokens Allegedly Extracted
The US allegations describe a large-scale operation involving potentially billions of tokens and millions of requests.
According to the advisory, the companies allegedly used multiple accounts, proxy services and other methods to access US AI systems while attempting to avoid detection and usage restrictions.
The goal, according to US officials, was to replicate capabilities such as coding, mathematics and advanced reasoning without having to spend the same amount of money and time developing those capabilities independently.
If accurate, such a strategy could significantly reduce the cost of building competitive AI systems.
DeepSeek Among the Companies Named
DeepSeek is among the most prominent companies named in the US advisory.
The Chinese AI company gained international attention after demonstrating models capable of competing with leading American systems while operating with comparatively lower development costs.
Washington’s latest accusations suggest that US officials are now concerned that some Chinese AI companies could use American frontier models as an indirect source of training data and capabilities.
DeepSeek and the other named companies did not immediately respond to requests for comment cited in reports on the allegations.
Moonshot AI Also Faces Allegations
Moonshot AI, the developer of the Kimi family of AI models, was also named.
The company has become one of China’s fastest-growing AI startups, with its Kimi models gaining attention for coding, reasoning and other advanced capabilities.
US agencies allege that Moonshot used outputs from American AI systems, including Claude and GPT, to improve its own models.
Moonshot has previously denied allegations surrounding unauthorized model distillation. The company is also preparing for a potential Hong Kong listing, making the latest accusations particularly significant for its international business and reputation.
Alibaba and Other Chinese AI Firms Named
The allegations extend beyond DeepSeek and Moonshot AI.
US agencies also identified Alibaba, MiniMax, StepFun and Z.AI in the joint advisory.
The inclusion of several major Chinese AI companies indicates that Washington views the issue as broader than the actions of a single startup.
US officials are concerned that the alleged practices could allow Chinese companies to close the technological gap with American AI developers more quickly than would otherwise be possible.
US Says the Activity Violated Terms of Service
One of Washington’s central arguments is that the alleged distillation campaigns did not simply rely on publicly available AI outputs.
The cybersecurity advisory said Chinese AI companies allegedly routed requests through multiple pathways and accounts to obtain unauthorized access to proprietary capabilities, potentially violating the terms of service of US AI providers.
The agencies also alleged that some companies used bulk purchases of premium subscriptions shared among teams of developers to reduce the cost of obtaining large volumes of AI-generated outputs.
That distinction is important because normal model distillation and unauthorized extraction are not necessarily the same activity.
China Rejects the Accusations
Beijing has strongly rejected Washington’s allegations.
Chinese officials described the US claims as unfounded and criticized Washington for attempting to restrict China’s technological development.
China’s Foreign Ministry said AI development should remain open and inclusive and argued that Chinese advances were the result of domestic technological development rather than the systematic theft alleged by US agencies.
The Chinese government has also argued that distillation itself is a neutral and widely used AI-development technique.
The disagreement therefore centers not on whether distillation exists, but on whether particular companies used the technique improperly to extract restricted capabilities from proprietary US systems.
The AI Race Between the US and China
The accusations come as the United States and China compete aggressively for leadership in artificial intelligence.
Both countries are investing heavily in AI models, computing infrastructure, semiconductor technology and data centers.
Washington has imposed restrictions on China’s access to some advanced technologies, particularly high-end AI chips, while Chinese companies have attempted to develop increasingly capable models despite those limitations.
The latest allegations suggest that the AI competition is increasingly extending beyond hardware and chips into the protection of proprietary model capabilities.
Anthropic and OpenAI Have Raised Similar Concerns
The latest US government advisory follows earlier warnings from American AI companies.
Anthropic and OpenAI have previously raised concerns about Chinese companies using their models to develop competing AI systems.
The new government report gives those concerns a national-security dimension by alleging that the activity could potentially support China’s broader technological, military and cyber capabilities.
That could increase pressure on Washington to introduce additional safeguards around access to advanced AI models.
Why Distillation Matters in the AI Industry
AI models require enormous amounts of computing power, engineering expertise and financial investment.
If a company can obtain large quantities of high-quality outputs from an already powerful model, it may be able to accelerate the development of its own system.
This does not necessarily mean that the second model is simply a copy. Distillation can produce a different model with its own architecture and behavior.
However, Washington argues that using proprietary model outputs at massive scale can allow competitors to reproduce valuable capabilities without bearing the full cost of developing them independently.
Potential Impact on US AI Companies
The allegations could encourage American AI companies to strengthen restrictions on access to their most advanced models.
Providers may increase monitoring of unusual account activity, impose tighter limits on automated requests and introduce additional methods to identify coordinated attempts to extract model capabilities.
This could also affect legitimate developers and researchers if restrictions become too broad.
The industry therefore faces a difficult balance between protecting intellectual property and keeping AI systems accessible enough for innovation.
Could the Dispute Lead to New Restrictions?
The latest accusations could increase calls for additional US measures against Chinese AI companies.
Potential responses could include tighter export controls, restrictions on access to American AI services or efforts to prevent specific companies from obtaining advanced computing resources.
However, broad restrictions could also have unintended consequences.
AI researchers have noted that distillation itself is a legitimate and important technique, meaning policymakers would need to distinguish between normal research practices and alleged unauthorized extraction of proprietary capabilities.
AI Tensions Could Affect US-China Talks
The timing of the accusations is also significant.
The United States and China are preparing for discussions on AI safety, while President Donald Trump and Chinese President Xi Jinping are expected to address broader bilateral issues later this month.
AI governance, cybersecurity and technological competition are likely to remain important parts of the relationship.
The latest allegations could make those discussions more difficult, but they could also increase the urgency of establishing clearer international rules around AI model access and technology protection.
The Bigger Question: Who Controls AI Capabilities?
The dispute highlights a fundamental question for the global AI industry: How should valuable AI capabilities be protected in an environment where models can be queried and their outputs can be used to train other systems?
Traditional intellectual-property protections were not designed specifically for modern generative AI systems.
Companies can protect their source code, model weights and infrastructure, but preventing outsiders from learning from model outputs can be considerably more complicated.
As AI becomes more capable, this distinction is likely to become increasingly important.
What Happens Next?
The immediate focus will be on whether the US government takes additional action against the companies named in the advisory.
American AI firms are also likely to strengthen their security and monitoring systems to prevent large-scale automated extraction.
Meanwhile, Chinese AI companies are expected to continue developing their own models while rejecting accusations that their progress depends on unauthorized copying.
The outcome could influence not only US-China technology relations but also the broader rules governing AI development around the world.
Key Takeaway
The latest AI Theft Accusations mark a major escalation in the US-China artificial intelligence rivalry.
The FBI, NSA and CISA have accused six Chinese AI companies, including DeepSeek, Moonshot AI and Alibaba, of conducting industrial-scale knowledge-distillation campaigns designed to extract capabilities from American AI models. The agencies allege that the activity involved millions of requests, multiple accounts and proxy services and may have occurred with Chinese government awareness.
China has rejected the allegations as unfounded and defended distillation as a legitimate AI-development technique.
The dispute could now become an important part of the wider US-China technology relationship as both countries compete for leadership in artificial intelligence.
FAQs
1. What are the latest AI Theft Accusations?
US security agencies have accused several Chinese AI companies of systematically extracting capabilities from US frontier AI models through large-scale knowledge distillation.
2. Which Chinese AI companies were named?
The US advisory named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.
3. What is AI distillation?
AI distillation is a technique in which outputs from a more capable model are used to train or improve another AI model.
4. Is AI distillation illegal?
Not inherently. Distillation is a legitimate AI research technique. The US allegations concern the alleged unauthorized, large-scale extraction of capabilities from proprietary models.
5. Which US AI models were allegedly targeted?
US agencies said the activity involved models from companies including Anthropic, OpenAI, Google and SpaceX’s AI division.
6. How did the companies allegedly obtain the AI outputs?
US officials said the companies allegedly used millions of requests, multiple accounts and proxy services to access American AI systems and avoid usage restrictions.
7. Did China admit to the allegations?
No. Chinese officials rejected the accusations and described them as unfounded.
8. Why is the issue important?
Large-scale distillation could potentially allow AI companies to reproduce advanced capabilities more quickly and at lower development costs, according to US officials.
9. Could the US impose new restrictions?
The allegations could lead to stronger safeguards, access restrictions or other policy measures, although no specific new punishment automatically follows from the advisory.
10. What does this mean for the US-China AI race?
The dispute highlights how competition is expanding from AI chips and computing infrastructure to model capabilities, intellectual property and access to advanced AI systems.