Skip to content
Tech News
← Back to articles

Six Chinese AI firms accused of aggressively copying US frontier models

read original get The Coming Wave" by Mustafa Suleyman (hardcover) → more articles
Why This Matters

US intelligence and security agencies have publicly named six major Chinese AI companies, including DeepSeek and Alibaba, as allegedly running industrial-scale distillation attacks against US frontier models like Claude, GPT, Gemini, and Grok. The accusation escalates the US-China AI rivalry from commercial competition into a national security matter, and the proposed defenses could change how everyone accesses AI APIs.

Key Takeaways
Worth a Look

The Coming Wave" by Mustafa Suleyman (hardcover) — If headlines about frontier-model theft and the US-China AI race have you wanting the bigger picture, this book from the DeepMind co-founder digs into how fast AI capabilities spread and why containing them is so hard. It's a readable way to understand the stakes behind distillation, national security worries, and the scramble for AI leadership.

See The Coming Wave" by Mustafa Suleyman (hardcover) on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

The United States has now named six Chinese AI firms accused of waging industrial-scale attacks distilling US frontier AI model capabilities and perhaps sparing billions in Chinese development costs.

In a joint release Tuesday, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) alleged that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been attacking US models since at least late 2024. The firms “likely” acted with “Chinese government awareness” when extracting capabilities from US models, including variants of Claude, GPT, Gemini, and Grok, agencies said.

“China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model,” agencies said.

All American AI firms must work with the government and US allies to end the alleged theft threatening the US lead in the AI race, the agencies said. That will require coordinated action across the AI ecosystem to combat the “aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of US frontier AI models.”

Attack methods include “exploiting AI model inference APIs” by bulk-buying fake accounts, agencies said. Not registered to legitimate users, these swarms of fraudulent accounts execute “highly coordinated queries featuring identical or similar prompt texts,” which range “from thousands to millions on similar topics.”

Another common method is using prompt injection techniques to jailbreak models, including crafting “prompts forcing models to reveal their hidden [chain-of-thought] reasoning,” agencies said. For example, “DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step.”

Fixes may frustrate AI users in US

To encourage firms to work together, agencies recommended mitigations that would supposedly make it harder for Chinese firms to steal from US models.

First, AI firms must improve detection of sophisticated campaigns that allegedly use tens of thousands of accounts relying on “a gray market of proxies” to evade geographical restrictions and “route distillation requests through multiple pathways to gain unauthorized access.”