1. The U.S. government leveled sweeping accusations against China's leading AI developers, claiming they are conducting systematic extraction of proprietary functionalities and capabilities of American-developed models through industrial-scale knowledge distillation campaigns [para. 1]. A joint report from the NSA, FBI and CISA alleged that the Chinese government is "likely" aware of these activities, through which DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI "extracted billions of tokens across millions of exchanges/requests" from U.S. top AI models — including variants of Claude, GPT, Gemini and Grok — since at least late 2024 [para. 2]. The agencies claimed distillation is "the core — not merely a supplement — of their AI development strategy" [para. 3].2. Distillation is the process of training smaller AI models using output from larger ones to lower training costs; it can be a legitimate research technique, but U.S. officials and industry executives have long complained that the volume and targeted manner of Chinese campaigns amount to stealing [para. 4]. The report said China-based AI companies route distillation requests through multiple pathways for unauthorized access, including native APIs, remote cloud providers and third-party aggregators that obfuscate user metadata, as well as gray-market proxies known as "transfer stations" to bypass geographic restrictions and evade safeguards [para. 5][para. 6]. The agencies recommended three remediating steps: comprehensive detection and mitigation, targeted response changes, and cross-organization intelligence sharing [para. 7]. A Chinese IP compliance professional told Caixin that U.S. tech companies chose lobbying over civil litigation because neither U.S. nor Chinese law provides a clear, actionable legal definition of distillation [para. 8].3. The report detailed alleged misconduct by each company [para. 9]. DeepSeek was accused of "conducting an organized distillation campaign" since late 2024 to generate synthetic data for training its R1 model, making its claim of using trivial computing power false [para. 10]. Moonshot AI allegedly "extracted significant Claude Fable 5 data to train its Kimi-K3 model and GPT-4o data to train its Kimi-K2 model" for supervised fine-tuning and reinforcement learning improvements [para. 11]. Alibaba was accused of using "industrial-scale distillation" to improve its Qwen family, distilling Claude-4, Claude Opus, Claude Sonnet and GPT-5 in late 2025 [para. 12]. MiniMax, Z.AI and StepFun faced similar accusations [para. 13].4. The investigation was heavily championed by OpenAI and Anthropic [para. 14]. In February, Anthropic accused DeepSeek, MiniMax and Moonshot AI of generating over 16 million exchanges with Claude through approximately 24,000 fraudulent accounts [para. 15]. Also in February, OpenAI wrote to the House alleging DeepSeek consistently attempted to distill frontier models, noting most adversarial activity originated from China, with occasional traces from Russia [para. 16]. In June, Anthropic escalated to the Senate, accusing Alibaba of using approximately 25,000 fraudulent accounts [para. 17]. On June 5, the White House unveiled a National Security Presidential Memorandum requiring government agencies to develop partnerships with private-sector companies to protect cutting-edge AI technologies from malicious distillation attacks [para. 18].5. However, a powerful coalition of Silicon Valley giants pushed back against the aggressive stance [para. 19]. On July 24, Nvidia CEO Jensen Huang published a joint letter co-signed by Meta, Microsoft, Dell and Hugging Face, urging policymakers not to conflate legitimate model development methodologies with unauthorized data acquisition [para. 20]. The letter argued that distillation is a ubiquitous and essential technique for model evaluation and improvement, representing a continuation of the open-source tradition since the 1980s [para. 21], and that unlawful extraction concerns should be addressed through targeted legal and commercial frameworks rather than sweeping restrictions [para. 22]. Meta underscored this divide on Aug. 10 by releasing its Muse Glimmer model with entirely open-source weights, explicitly highlighting its use of distillation methodologies throughout training [para. 23].AI generated, for reference only
In Depth: AI Distillation in China Leaves U.S. Tech Giants at Odds
OpenAI and Anthropic are urging Washington to act against what they see as copying the capabilities of their models, even as Nvidia, Meta and Microsoft argue that the method is an essential tool for innovation
U.S. alleges Chinese AI companies extracted billions of tokens from American models since late 2024 through industrial-scale distillation as core strategy. Conflict between OpenAI/Anthropic and Meta/Microsoft on distillation legitimacy signals regulatory uncertainty impacting frontier AI IP and positioning.












