Journalism begins where hype ends

,,

I do not fear computers. I fear the lack of them."

—Isaac Asimov

China Slams US Accusations of ‘Systematic’ Copying of Frontier AI Models

US security agencies accuse China-based AI companies - DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI - of systematically extracting capabilities from US frontier AI models through industrial-scale distillation, with malicious activities dating back to at least late 2024.
A futuristic AI data center with multiple computer monitors displaying artificial intelligence and network visualizations, overlaid with U.S. and China graphics representing competition in AI technology.
September 9, 2026 05:25 PM IST | Written by Neelam Sharma | Edited by Pratima O Pareek

Rejecting accusations by US security agencies that Chinese AI companies were conducting “distillation campaigns” against US AI firms, Chinese Foreign Ministry spokesperson Mao Ning on Wednesday urged Washington to refrain from making “unfounded accusations” against China and smearing its reputation.

Mao called on Washington to “earnestly implement the important consensus reached by the heads of state of the two countries” and urged greater cooperation in artificial intelligence. “Both China and the US are major countries in the field of artificial intelligence and they should strengthen cooperation,” she said.

The US National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have warned that China-based AI firms are systematically extracting proprietary capabilities from US frontier AI models through “industrial-scale” distillation campaigns.

“China-based AI companies are engaging in aggressive, malicious, and targeted malicious distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models,” it said.

According to the US cybersecurity advisory, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens across millions of exchanges and requests from US models, including variants of Claude, GPT, Gemini and Grok, since at least late 2024.

The advisory said DeepSeek conducted organized campaigns targeting reasoning capabilities, specialized optimizations and domain-specific functions to train its R1 and V3 models, while Alibaba leveraged industrial-scale distillation to improve its Qwen family of AI models.

The allegations come months after a dispute between Alibaba and Anthropic over Claude Code.

In July, AI FrontPage Editor Pratima O Pareek reported, citing sources familiar with the matter, that Alibaba Group Holding had implemented a ban on employees using Anthropic’s Claude Code for work, effective July 10. The company asked employees to use its own AI coding assistant, Qoder, instead.

In late 2025, MiniMax distilled chain-of-thought (CoT) reasoning, RL, SFT and software engineering capabilities to improve its M2 model from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro and Gemini 3 Pro.

According to the advisory, the companies routed distillation requests through multiple pathways, including APIs (application programming interfaces), remote cloud providers, third-party aggregators and a gray market of API proxies known as “transfer stations.” The agencies said these methods were used to bypass US AI companies’ geographic restrictions, safeguards and other access controls.

The advisory identifies tactics including prompt injection, attempts to extract hidden chain-of-thought reasoning, automated failover between providers and the use of fraudulent or shared accounts.

The agencies said some campaigns involved query volumes ranging from thousands to millions per domain to generate synthetic training data.

The agencies recommended that US AI companies take three immediate steps: strengthen detection and mitigation of anomalous or malicious prompts, accounts, networks and behaviors; deploy targeted changes to responses from suspected distillation attempts to reduce the benefits to companies conducting such campaigns; and establish cross-organization intelligence sharing among model providers, cloud platforms and API aggregators to identify distributed campaigns.

According to the advisory, industrial-scale distillation can significantly shorten AI development timelines and reduce financial expenditures for companies seeking to train frontier models.

They also warned that China-based AI companies deliberately distribute operations across multiple providers and pathways to evade detection, enabling the systematic extraction of proprietary capabilities. The agencies said the activity threatens US technological leadership and called for a coordinated response across the US government, private industry and allied nations.

Also Read: China Accuses US of “AI Hegemonism” as Distillation Row Deepens

Authors

  • Neelam Sharma, reporter at AI FrontPage

    Neelam Sharma is a passionate storyteller, and journalist with over a decade of experience across leading Indian media houses.
    Known for her calm presence on screen and powerful storytelling off it, Neelam brings a rare blend of credibility, creativity, and empathy to journalism. Her strength lies in ground reporting and research-driven narratives that connect with the heart of the audience. Whether covering social issues, human-interest features, or breaking news, she combines factual depth with a human touch—making every story not just informative.

    LinkedIn

  • Pratima Pareek, Editor and Co-founder of AI FrontPage

    Pratima O Pareek is an Editor and Co-Founder of AI FrontPage. A gold medalist in Mass Communication and Journalism, she's worked across national and international newsrooms, bringing sharp editorial instincts and a commitment to clarity. She believes in cutting through the noise to deliver stories that actually matter.
    Off the clock, she watches offbeat cinema, follows tennis, and explores new places like a traveler, not a tourist.

    LinkedIn