Six Chinese AI firms accused of aggressively copying US frontier models

The advisory marks a significant escalation in the ongoing geopolitical struggle for technological supremacy. According to the federal assessment, these companies have been aggressively harvesting the capabilities of high-end US models—including advanced iterations of OpenAI’s GPT, Google’s Gemini, Anthropic’s Claude, and xAI’s Grok—since at least late 2024. By using these models as a foundation, the accused firms are alleged to have bypassed years of expensive research and development, effectively cloning sophisticated reasoning and logic chains to accelerate their own internal AI progress.
The Mechanics of Industrial-Scale Distillation
The US government’s report details a sophisticated playbook employed by the Chinese firms, characterized by the deployment of massive, automated infrastructure. The primary method involves "exploiting AI model inference APIs" through the bulk procurement of thousands of fraudulent or non-legitimate user accounts. These accounts are then utilized to launch "highly coordinated queries" that span across days or even months. By bombarding US APIs with millions of prompts on identical topics, these actors can map out the internal logic, weights, and decision-making processes of the target models.
One particularly concerning technique identified by the agencies is the use of "jailbreak" prompts designed to bypass safety guardrails and force the models to expose their hidden Chain-of-Thought (CoT) reasoning. The report notes that DeepSeek, in particular, was observed utilizing specialized prompts that instructed models to articulate the step-by-step internal reasoning behind their responses. Once the model outputs this "thought process," the data is harvested to train smaller, more efficient domestic Chinese models, a process that significantly lowers the financial and temporal barrier to achieving "frontier-level" performance.
A Timeline of Escalation
The friction surrounding AI model theft has been building for over a year. The timeline of this conflict highlights a rapid transition from industry-level complaints to formal government intervention:

- Late 2024: US AI labs begin reporting anomalous traffic patterns and evidence of automated "distillation" attacks targeting their proprietary APIs.
- August 2025: OpenAI and other industry leaders publicly raise concerns regarding the improper use of their data, with widespread reports of model cloning attempts.
- April 2026: The US government issues a formal warning to China, signaling that a crackdown on industrial-scale AI theft is imminent.
- June 2026: Anthropic publicly alleges that Alibaba engaged in a massive cloning attack against Claude, calling for potential criminal consequences.
- September 2026: The joint NSA/CISA/FBI advisory provides the most comprehensive public evidence to date, naming the six specific Chinese firms and detailing the technical methods of the attacks.
Proposed Mitigations and the User Experience Dilemma
The federal agencies have urged US AI companies to adopt a proactive, defensive posture that could fundamentally alter the user experience for legitimate customers. The core recommendation is for firms to implement a "secret" routing system. When an account is flagged by the system as being part of a suspicious, high-volume, or automated cluster, the AI provider should, without notice, route that user’s requests to an inferior or "dumbed-down" model.
This strategy aims to starve the attackers of high-quality training data. By providing responses that contain "stylistic inconsistencies" or reduced reasoning depth, the AI providers can ensure that any data captured by the attackers is useless for training purposes. However, this proposal has drawn concern from industry analysts regarding the potential for collateral damage.
If a legitimate enterprise user or a researcher happens to trigger the automated detection system—perhaps through a large, legitimate batch-processing task—they may find their service suddenly degraded without explanation. The agencies acknowledge this risk but maintain that the cost of inaction is too high. They suggest that firms must "balance security with user experience," essentially signaling that a certain level of performance degradation for some users is a necessary trade-off to prevent the theft of national technological assets.
Official Responses and Geopolitical Tensions
The Chinese government has vehemently denied the allegations, characterizing the US advisory as a "smear campaign" intended to stifle China’s technological rise. During a briefing on Wednesday, Chinese Ministry of Foreign Affairs spokesperson Mao Ning labeled the accusations "groundless," asserting that China’s rapid progress in artificial intelligence is the result of indigenous innovation and scientific self-reliance.
Furthermore, Beijing has pointed out that the flow of AI research is not unidirectional. Official reports in Chinese state media, including the People’s Daily, have noted that many US-based startups and researchers have utilized Chinese AI models for their own development, citing their cost-effectiveness and high performance in specific tasks. The Chinese government has warned that it is prepared to take "all necessary measures" if its legitimate business interests continue to be targeted by US-imposed restrictions or public accusations.

Economic and Security Implications
The stakes for the United States are largely economic and strategic. The "frontier model" is the crown jewel of the modern tech economy; whoever controls the most advanced AI holds a decisive advantage in fields ranging from drug discovery and material science to military logistics and cybersecurity. The US agencies argue that if these capabilities are effectively stolen, the US loses the "economic lead" it has worked to build over the past decade.
The potential economic losses are estimated to be in the billions of dollars. When a firm like DeepSeek or Moonshot AI can bypass the massive capital expenditure required to train a foundation model by distilling it from an existing one, they essentially gain a free ride on the back of American innovation. This shifts the playing field in a way that the US government believes is fundamentally unfair and a threat to national security.
Moving Toward Collaborative Defense
The joint advisory emphasizes that isolated efforts by single companies are insufficient to stop these campaigns. The government is pushing for a more integrated defense strategy where AI firms share threat intelligence in real-time. This includes sharing data on "gray market" proxy networks and the specific prompt templates used in distillation attacks.
The strategy also calls for stricter "identity verification" for enterprise subscriptions. By tracking the usage patterns of individual accounts more closely, providers hope to identify the point where an account shifts from a "human user" pattern to an "automated harvester" pattern. While this will undoubtedly improve security, it raises long-standing questions about user privacy and the extent to which major tech platforms should monitor the specific queries of their users.
As the September 24 meeting between President Donald Trump and President Xi Jinping approaches, the issue of AI theft is expected to be a central topic of discussion. The tension between the need for an open, collaborative global research environment and the imperative to protect proprietary technological advancements has reached a critical inflection point. Whether these proposed mitigations can be implemented without alienating the global user base of US-based AI services remains an open question, and one that will likely dictate the next phase of the AI arms race.







