TL;DR — Key Takeaways
- U.S. security agencies accused six Chinese AI companies, including DeepSeek and Alibaba, of using American frontier models to accelerate development of their own systems.
- The agencies allege the companies extracted billions of tokens through millions of interactions with U.S. models and used knowledge distillation to improve reasoning, coding and agent capabilities.
- Officials said some companies used fraudulent accounts, API proxies and other methods to bypass geographic and usage restrictions.
U.S. security agencies have accused six major Chinese AI companies of using American frontier models to accelerate development of their own AI systems, and have also alleged that this work was likely done “with the knowledge of the Chinese government.”
The National Security Agency, FBI and Cybersecurity and Infrastructure Security Agency issued an advisory that named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI in a joint security alert. The agencies said the companies have extracted billions of tokens through millions of interactions with U.S. models since at least late 2024.
The alleged targets include models from Anthropic, OpenAI, Google and xAI. The agencies said the Chinese developers used the resulting data to improve capabilities ranging from software engineering and mathematical reasoning to AI agents and customer service.
The U.S. agencies claim that Chinese companies used knowledge distillation, a machine learning technique in which a smaller model learns from the output of a more capable model. AI developers can use distillation legitimately to create smaller, more efficient systems. The U.S. agencies allege that the Chinese companies crossed that line by circumventing access controls and violating the terms governing American AI services.
According to the advisory, the companies used methods that included fraudulent accounts, API proxies and other routes designed to evade geographic and usage restrictions. U.S. officials said the scale of the activity indicates that distillation plays a central role in the Chinese companies’ AI development rather than serving as an occasional training method.
Allegations About the Economics of Chinese AI Development
The U.S. government provided specific claims about individual vendors. DeepSeek allegedly drew on GPT and Claude models to improve its R1 and V3 systems, including their reasoning and agent capabilities.
Moonshot AI was accused of using Anthropic technology to help develop its Kimi K3 model. The advisory also linked Alibaba, MiniMax, StepFun and Z.AI to distillation efforts involving coding and software engineering.
The allegations also raise questions about the economics of Chinese AI development. DeepSeek drew global attention partly because it reported a remarkably low training cost of $5.6 million for its V3 model. U.S. agencies contend that such figures do not account for the value of training data obtained through distillation.
The advisory offers recommendations to U.S. AI companies to help protect their work. The agencies recommended stronger verification of users, behavioral monitoring for suspicious activity and greater sharing of threat intelligence among AI developers. They also suggested that companies alter or reduce the quality of model responses when they detect suspected distillation attempts.
The accusations could carry costs beyond tighter technical defenses. Treasury Secretary Scott Bessent warned in July that Chinese AI companies found to have engaged in IP theft could face sanctions. U.S. lawmakers are also considering measures intended to penalize Chinese companies accused of improperly copying American AI technology.
China has rejected the broader U.S. claims. Foreign Ministry spokesperson Mao Ning said the country’s AI advances stem from its own scientific and technological development and called for greater cooperation between the two nations. A Chinese Embassy spokesperson characterized the accusations as an attack on China’s progress in AI.

