Six Chinese AI firms accused of aggressively copying US frontier models

According to the joint advisory released this past Tuesday, these entities have been systematically harvesting the capabilities of high-end American models—including variants of OpenAI’s GPT, Google’s Gemini, Anthropic’s Claude, and xAI’s Grok—since at least late 2024. By distilling the internal reasoning, chain-of-thought processes, and specialized training data of these frontier systems, the accused firms have allegedly bypassed years of research and development, saving themselves billions of dollars in compute and engineering costs while accelerating their own competitive standing in the global AI race.
A Chronology of Escalating Tensions
The accusation represents the most significant escalation in the ongoing digital cold war between Washington and Beijing regarding the future of generative AI. The tension has been building steadily over the past eighteen months. As early as the spring of 2025, leading American AI labs began reporting anomalous traffic patterns and evidence of "model cloning."
In April 2026, the US government signaled that a formal crackdown was imminent, warning Beijing that the systematic exploitation of American intellectual property would no longer be tolerated. Despite these warnings, the scale of the alleged theft has continued to grow. OpenAI, Google, and Anthropic have each documented instances of unauthorized access, with Anthropic taking the bold step of suggesting that Alibaba should face criminal charges for what it characterized as the largest-ever cloning attack on the Claude architecture.
The current federal advisory formalizes these individual corporate grievances into a unified national security strategy. The document asserts that these activities are not merely the work of independent rogue actors but are being conducted with "Chinese government awareness," suggesting a state-sponsored or state-sanctioned initiative to close the gap between Chinese and American technological dominance.

The Anatomy of Industrial-Scale Distillation
The methodology employed by these Chinese firms is described by US intelligence as a sophisticated, high-volume operation. Rather than traditional hacking—which involves breaching a network—the attackers are "exploiting AI model inference APIs." By utilizing thousands of fraudulent accounts, the actors create a "gray market" of proxies that allows them to bypass geographical restrictions and overwhelm servers with coordinated, massive-scale queries.
These queries are designed to trick the models into revealing their internal decision-making frameworks. For instance, the report notes that DeepSeek has frequently utilized "chain-of-thought" prompts, which explicitly instruct the model to articulate its internal logic step-by-step. By capturing these outputs, Chinese firms can reverse-engineer the "reasoning" that makes US models superior, subsequently using that data to train their own, smaller, and more efficient domestic models.
Defensive Countermeasures: The "Secret Switch" Strategy
In response to these findings, the US government has outlined a series of technical mitigations that place the burden of defense squarely on American tech firms. The most controversial of these recommendations is the implementation of "degraded responses" or the "secret switching" of users suspected of malicious activity to less-capable, inferior models.
The strategy involves a multi-layered approach to detection:
- Behavioral Analysis: Firms are advised to monitor for anomalous patterns, such as bulk account procurement, usage that hits maximum API limits immediately upon account creation, and subscription-to-usage ratios that deviate from standard enterprise or research patterns.
- Identity Verification: Agencies are pushing for more rigorous "know-your-customer" (KYC) requirements for API access, though this risks infringing upon the privacy of legitimate researchers and developers.
- Strategic Degradation: When a user is identified as part of a suspected distillation campaign, the model should—without warning—provide a response that is logically sound but lacks the depth or nuance of the original. This "noise" is intended to render the distillation useless, effectively poisoning the data that the Chinese firms are trying to steal.
However, the efficacy of this strategy is debated. The intelligence report admits that Chinese firms have become "adaptive," employing automated quality assurance systems that can detect when an AI output is being intentionally degraded. If the model is not providing high-quality logic, these firms simply move on to a different target, potentially rendering the "secret switch" a cat-and-mouse game that could ultimately alienate legitimate users who might be incorrectly flagged by these automated defenses.

Broader Economic and Geopolitical Implications
The implications of this conflict extend far beyond technical troubleshooting. The US government warns that if the American private sector cannot coordinate with the government to protect its IP, the United States faces significant, long-term economic damage. The systematic extraction of proprietary functionality essentially turns the American AI ecosystem into a free training ground for foreign competitors.
The Chinese government has reacted with predictable indignation. Mao Ning, a spokesperson for the Chinese Ministry of Foreign Affairs, dismissed the allegations as "groundless" during a press briefing on Wednesday. She characterized the success of China’s AI sector as the product of "high-level scientific and technological self-reliance" and argued that the US is merely attempting to smear Chinese achievements due to geopolitical insecurity. Furthermore, Chinese officials have countered that many American startups have themselves utilized Chinese models for distillation, arguing that the flow of AI research has historically been global and collaborative.
As the September 24 meeting between President Donald Trump and President Xi Jinping approaches, this issue is expected to be a focal point of the diplomatic agenda. The US push to "dumb down" models for suspicious actors represents a fundamental shift in how the internet and AI services are governed: from open, universal access to a gated, defensive posture defined by national security boundaries.
The Path Forward
The path forward remains fraught with technical and ethical hurdles. The requirement for AI firms to share data on these attacks with the government and one another is essential to building a cohesive defense, but it also necessitates a delicate balance between public safety and user privacy. As the US moves toward a more restrictive, surveillance-heavy approach to model access, the AI industry must grapple with the potential for "false positives"—legitimate researchers or developers who might find themselves suddenly cut off from the tools they need because their usage patterns appeared "anomalous" to an automated, paranoid defense system.
Ultimately, the directive serves as a stark reminder that the frontier of artificial intelligence is no longer just a site for innovation, but a critical theater of national power. With Beijing aggressively targeting a fourfold increase in its computing capacity by 2030, the US government has signaled that it is prepared to sacrifice the seamlessness of the user experience to ensure that the secrets of its most advanced models remain protected. Whether these defensive maneuvers will actually stem the tide of distillation, or merely force attackers to evolve even more sophisticated, harder-to-detect methods, remains the central question of the next phase of the global AI competition.






