Washington has accused six Chinese artificial intelligence companies of conducting large scale efforts to extract capabilities from leading American AI models, opening another difficult chapter in the competition over advanced technology. The allegations, announced by US national security and law enforcement agencies earlier this month, center on a technique known as distillation and have raised fresh questions about intellectual property, cybersecurity, national security, and the future balance of AI power.
US Agencies Raise New Allegations Over AI Model Distillation
On September 8, 2026, the National Security Agency, Federal Bureau of Investigation, and Cybersecurity and Infrastructure Security Agency issued a joint advisory alleging that China based AI companies had carried out industrial scale distillation campaigns against US frontier AI systems. The agencies named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
US officials said the activity had been taking place since at least late 2024 and involved efforts to extract capabilities from advanced models associated with American companies including Anthropic, OpenAI, Google, and SpaceX. The agencies said the alleged activity could allow companies to shorten development timelines and reduce the enormous computing, electricity, research, and engineering costs normally required to develop highly capable AI systems.
The advisory is available through the Federal Bureau of Investigation, while cybersecurity guidance and related information are also published by the Cybersecurity and Infrastructure Security Agency.
What AI Distillation Actually Means
The controversy is partly rooted in a technical process that is not inherently illegal or malicious. AI distillation can involve training a smaller model by using the outputs generated by a larger model. Researchers and companies can use the method for legitimate purposes such as improving efficiency, reducing computing requirements, and creating systems that require fewer resources to operate.
The dispute concerns how the technique is allegedly being used and how access to powerful proprietary models is obtained. US agencies said the companies identified in their advisory were not simply using publicly available information. Instead, officials alleged that they were systematically querying protected AI services at very large scale in an effort to reproduce specific capabilities.
That distinction is central to the dispute. A company learning from a publicly released model is different from a company allegedly using fraudulent accounts, automated queries, or other methods to obtain restricted outputs from a proprietary system.
Millions of Queries Can Become a Powerful Training Resource
According to the US advisory, some alleged campaigns involved large numbers of accounts and coordinated prompts directed toward American AI services. Investigators said certain activity involved repeated or closely related questions designed to gather substantial amounts of model output.
At ordinary consumer scale, asking an AI system questions produces only a small amount of information. At industrial scale, however, millions of interactions can create a substantial dataset. That dataset can potentially reveal patterns in reasoning, coding, mathematics, software engineering, response behavior, and other capabilities.
The US agencies alleged that some of the activity involved fraudulent accounts and techniques intended to bypass restrictions placed on access to advanced models. They also described attempts to extract information through carefully designed prompts and other technical methods.
Why the Allegations Matter to the Global AI Industry
The dispute reaches far beyond individual companies. Frontier AI development requires enormous investments in computer chips, data centers, electricity, research teams, training datasets, and specialized engineering. Companies spending billions of dollars to develop advanced models have strong incentives to protect the resulting technology.
If a competitor can reproduce important capabilities by repeatedly querying an existing model rather than building an equivalent system from the beginning, the economics of AI development could change significantly. The original developer carries the cost of training and maintaining the model, while another company could potentially use its outputs as a shortcut.
That is why the US government has described the alleged activity as a strategic concern rather than simply a commercial dispute. American agencies argue that large scale extraction could help Chinese companies narrow technological gaps while avoiding some of the research and infrastructure expenses associated with frontier AI development.
China Rejects the US Characterization
Chinese officials have rejected the US allegations and described the accusations as unfounded. Chinese authorities have also argued that AI development in China reflects domestic scientific and technological progress rather than simply the copying of American systems.
The disagreement illustrates the difficulty of separating legitimate AI research from improper use of another company’s technology. Distillation itself is a recognized machine learning technique. The disputed question is whether specific companies used restricted models and access methods in ways that violated terms of service, intellectual property protections, cybersecurity rules, or other applicable restrictions.
Those legal questions are likely to become increasingly important as AI companies attempt to protect their models while researchers seek more efficient methods for training and improving systems.
The Intellectual Property Question Is More Complicated Than Traditional Software Copying
Traditional software piracy can sometimes be easier to identify because the original source code, files, or protected assets can be directly copied. AI models create a more complicated situation.
A modern AI model contains learned numerical representations rather than a conventional collection of source files that another company can simply duplicate. A competing developer may instead attempt to reproduce behavior by collecting model responses and using those responses to train another system.
This creates a difficult legal and technical boundary. The output of an AI system may be protected in different ways depending on the circumstances, while the process used to collect and reuse that output can raise separate questions involving contracts, computer access, trade secrets, copyright, and unfair competition.
For companies developing advanced models, protecting application programming interfaces and monitoring unusual usage patterns has therefore become an important part of AI security.
American AI Companies Face a New Security Challenge
The allegations also highlight a growing problem for AI providers. A company can invest heavily in creating a powerful model, but customers need access to that model for it to generate commercial value. The same access can potentially become a pathway for large scale extraction.
AI companies therefore have to balance accessibility with security. They can monitor account behavior, identify unusual request patterns, restrict automated access, limit high volume activity, and investigate suspicious networks. At the same time, excessive restrictions can make legitimate research and commercial use more difficult.
The challenge becomes especially complicated when advanced AI models are offered globally. A model can be hosted in one country while its users, infrastructure, developers, and commercial customers operate across many jurisdictions.
The AI Race Is Becoming a Broader Technology Competition
The dispute comes at a moment when China and the United States are competing intensely across artificial intelligence, semiconductors, cloud computing, robotics, and advanced computing infrastructure.
Chinese companies have produced increasingly capable AI systems, while American companies continue to invest heavily in frontier models and the infrastructure needed to train them. The narrowing technological gap has made questions about access to computing hardware, model capabilities, research talent, and proprietary technology increasingly sensitive.
Recent reporting from the Associated Press has described Chinese AI developers as rapidly closing parts of the technological gap with the United States, while also noting that American companies remain leaders in several areas of advanced AI research and model development.
What Could Happen Next
The September allegations could lead to stronger technical safeguards and additional restrictions on access to advanced AI systems. US agencies have urged AI companies to improve cooperation with government authorities and international partners to detect and prevent large scale extraction attempts.
Several developments will be worth watching closely:
- Whether the US government introduces sanctions or other restrictions against the named companies
- Whether American AI providers impose tighter controls on access to their most capable models
- Whether China takes reciprocal measures against American technology companies
- Whether governments establish clearer international rules for AI model extraction and intellectual property
- Whether AI companies develop stronger methods for detecting automated and coordinated model queries
Any new restrictions could also have consequences for legitimate AI research. Open research communities, smaller companies, universities, and international developers rely on access to powerful models for experimentation and product development. Policymakers therefore face a difficult balance between protecting proprietary technology and preserving an environment where useful AI research can continue.
A Defining Issue for the Next Phase of Artificial Intelligence
The dispute over model distillation reflects a deeper change in artificial intelligence. The competitive advantage of an AI company is no longer limited to the physical computers used to train a model. It can also include the behavior, capabilities, training methods, engineering techniques, safety systems, and specialized knowledge embedded within that model.
That makes model security an increasingly important part of national technology policy. Companies must protect valuable systems without making them inaccessible, while governments must respond to alleged misuse without creating rules that unnecessarily restrict legitimate innovation.
For consumers and businesses, the immediate effects may appear distant from everyday AI use. Yet decisions made now about model access, intellectual property, cybersecurity, and international technology controls could influence which AI systems are available, how much they cost, and how quickly new capabilities reach the public.
As the United States and China continue competing over artificial intelligence, the central question is no longer simply who can build the most capable model. It is also how those capabilities are protected, shared, reproduced, regulated, and used across borders. The September allegations place that question at the center of an increasingly consequential global technology debate.

