AI-Generated · tencent/hy3-preview

U.S. agencies allege industrial-scale distillation of frontier AI models by six Chinese firms

U.S. federal agencies accuse six Chinese AI firms of industrial-scale distillation of American frontier models, with sanctions threatened and Beijing denying the claims.

U.S. agencies allege industrial-scale distillation of frontier AI models by six Chinese firms
A common visualization of an artificial neural network alongside a computing chip — illustrative of the AI models and hardware behind the allegations (file photo, 2018).
Photo: mikemacmarketing / photo on flickr, CC BY 2.0

On Tuesday, Sept 8, 2026, the FBI, NSA and CISA alleged in a joint advisory that major Chinese AI companies are carrying out industrial-scale theft of trade secrets by using ‘distillation’ to ‘extract restricted proprietary functionalities and capabilities of U.S. frontier AI models’, singling out DeepSeek and Alibaba among others. Treasury Secretary Bessent threatened sanctions in response, and China’s embassy rejected the claims.

In an alert published Tuesday, Sept 8, 2026, the same agencies said top Chinese AI companies have systematically mined cutting-edge US models (Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini, xAI’s Grok) since 2024. The report named six companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — and assessed the activity as coming “likely with Chinese government awareness.” China dismissed the accusations as groundless.

DeepSeek and Alibaba appear in both the advisory’s singled-out examples and the fuller six-company list, which anchors the agencies’ narrative that the extraction effort spans prominent labs rather than fringe actors. The inclusion of Moonshot AI, MiniMax, StepFun and Z.AI extends the scope across consumer chat assistants and enterprise model builders alike, suggesting a coordinated squeeze on the entire frontier of U.S. model capability.

The U.S. response paired the publication with a financial threat. Bessent’s sanctions warning, issued after the advisory, signals an intent to convert the intelligence finding into punitive action rather than mere public attribution. China’s embassy rejecting the claims outright mirrors the broader dismissal from Beijing, leaving the two governments on a familiar collision course over technological sovereignty.

The distillation label describes a technique of pulling restricted proprietary functionalities out of an already-built target model, rather than training from raw data. Applied across Claude, ChatGPT, Gemini and Grok since 2024 as the agencies contend, the method would let a recipient lab reproduce advanced behavior without absorbing the full cost of frontier research — the precise trade-secret harm the advisory accuses the six firms of inflicting.

What distinguishes this advisory from prior intellectual-property complaints is the explicit attribution of likely government awareness, which reframes the six firms’ work as a tolerated national project. That framing is the diplomatic precondition for the sanctions authority Bessent invoked, and it narrows the space for the routine corporate-espionage deniability both sides have relied on in earlier semiconductor and telecom disputes.

Sources