In an unprecedented joint advisory released Tuesday, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) publicly accused six Chinese artificial intelligence companies of conducting 'industrial-scale' attacks aimed at stealing the core capabilities of US frontier AI models. The firms named—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—allegedly extracted proprietary knowledge from models such as Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok.

The advisory marks a significant escalation in the US-China technology rivalry, moving from export controls and sanctions to direct accusations of systematic intellectual property theft. According to the agencies, the Chinese companies have been targeting US models since at least late 2024, using a technique called 'model distillation' to compress the outputs and decision-making patterns of frontier models into their own systems. This process, while not a direct copy of code, effectively transfers the 'reasoning' capabilities developed at enormous cost by US labs into cheaper, faster-to-market Chinese imitations.

Industrial-scale distillation

Model distillation is a well-known machine-learning technique, but the US agencies describe a far more aggressive variant. 'China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model,' the advisory noted. By repeatedly querying US models and using the responses to train their own, Chinese firms can bypass years of research and billions of dollars in compute and data costs.

The agencies said the activity was 'likely conducted with Chinese government awareness,' suggesting a state-sponsored or state-encouraged effort to close the AI gap. The accusation goes beyond individual corporate misconduct, framing the practice as a national security threat. The advisory did not specify exactly which model outputs were stolen or how the attacks were detected, but it urged US AI developers to harden their systems against such distillation attempts, including monitoring for suspicious query patterns and implementing behavioral output filters.

The accused firms

The six named companies represent a broad cross-section of China's AI sector, from startups to tech giants:

  • DeepSeek – The Hangzhou-based startup whose R1 reasoning model stunned the industry in early 2025 with performance rivaling OpenAI's o1 at a fraction of the training cost.
  • Alibaba – The e-commerce and cloud giant, which has released open-source models like Qwen and invested heavily in generative AI.
  • Moonshot AI – Creator of the Kimi chatbot, known for its long-context processing capabilities.
  • MiniMax – A startup specializing in multimodal models and the Hailuo video generator.
  • StepFun – A Shanghai-based firm behind the Step series of models.
  • Z.AI – A newer entrant founded by former Moonshot executives, focused on large language models.

The inclusion of Alibaba, a publicly traded company with global operations, adds a commercial dimension. Alibaba has not yet responded to the allegations, but its stock saw a dip in early trading following the announcement. The other firms either declined to comment or issued brief statements denying any wrongdoing.

China responds

Beijing reacted swiftly, rejecting the US claims as baseless and politically motivated. A spokesman for China's Ministry of Foreign Affairs called the allegations 'groundless smears' and accused Washington of trying to 'suppress Chinese technological development under the pretext of national security.' State media echoed the sentiment, framing the advisory as part of a broader US campaign to maintain its AI dominance by any means necessary.

'China's AI development is open, innovative, and law-abiding. The US claims are a typical act of bullying and technological protectionism,' the spokesman said in a press briefing.

Chinese experts also pointed out that distillation is a widely used research practice in the global AI community, and that US companies have similarly trained models on outputs from other systems. 'If using public model outputs to train your own model is theft, then almost every AI lab in the world is guilty,' said a researcher at Beijing's Tsinghua University, who requested anonymity.

Broader implications

The advisory lands at a delicate moment in US-China relations. Earlier this year, DeepSeek's R1 model sent shockwaves through Silicon Valley, prompting questions about whether US export controls on advanced chips were working. The new accusation suggests that despite those controls, Chinese firms have found ways to leverage US intellectual capital to advance their own capabilities. It also raises concerns about the security of commercially available AI models, as opposed to open-source ones.

Some commentators note that the US government is walking a tightrope. On one hand, it wants to keep cutting-edge AI out of Chinese hands. On the other, American labs like OpenAI and Anthropic are eager to sell their models globally, including to clients who might misuse them. The advisory may push these labs to restrict access more tightly, potentially affecting legitimate users worldwide.

For the broader industry, the episode highlights the fragility of intellectual property in the age of generative AI. Once a model is accessible via an API, its knowledge can be distilled—often without any traceable breach of cybersecurity. Legal remedies are limited: trade secret laws are difficult to apply to machine-learned weights, and international enforcement is nearly impossible. The US advisory is therefore as much a warning to domestic firms as an accusation against foreign competitors.

The six companies now face potential sanctions, inclusion on the US Entity List, or restrictions on doing business with American partners. Whether such measures can halt distillation remains uncertain. As one AI policy expert said, 'You can stop chip shipments, but you cannot stop a determined adversary from asking a chatbot questions.'

The global AI race is entering a new phase, one where the battlefield extends beyond silicon and into the very outputs of the models themselves. Tuesday's advisory is a clear signal that Washington views this battle as critical to its technological and national security interests—and that it is willing to name and shame those it considers the aggressors.