Six Chinese AI firms accused of aggressively copying US frontier models
Sep 9, 2026, 1:06 PM · Ars Technica

U.S. agencies name six Chinese AI companies for industrial-scale distillation of frontier models—and urge labs to silently downgrade suspected attackers, a fix that could also punish legitimate users.
Why it matters
In a joint statement, the NSA, CISA, and FBI accused DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting capabilities from U.S. frontier models—variants of Claude, GPT, Gemini, and Grok—since at least late 2024, likely with Chinese government awareness.
The agencies say distillation shortens Chinese development timelines and cuts training costs, and that stolen capabilities form the core—not a side channel—of China's AI strategy. They want American labs and allies to treat this as ecosystem defense, not one company's abuse queue.
China's Foreign Ministry called the claims groundless and framed Beijing's progress as self-reliance, while noting U.S. firms have also distilled from Chinese models. The accusation lands ahead of a planned Trump–Xi meeting and amid China's push to expand intelligent computing capacity.
From the desk
We're watching a shift from private lab complaints to a named, multi-agency indictment. OpenAI, Google, and Anthropic had already alleged improper cloning or distillation; Tuesday's release is the administration's most detailed public charge yet, with tactics spelled out: bulk fake accounts, gray-market proxies, coordinated identical prompts by the thousands or millions, and jailbreaks that force models to spill chain-of-thought.
The mitigation menu is where this gets operationally messy. Agencies want better detection of anomalous volume and subscription-to-usage ratios, stronger identity checks, and—most controversially—secret response degradation or silent switches to weaker models for suspected distillers. That can starve attackers of clean training signal. It can also trap legitimate researchers, enterprises, and anyone whose traffic looks "too patterned" in a quieter, dumber model with no notice.
We've seen how badly silent routing lands with users. OpenAI took heat last year when automatic routing defaulted people to less capable variants unless they begged the model to think harder. Asking labs to do that on purpose, without telling the target, trades user trust for contested national-security gain. Chinese attackers, the agencies admit, already run quality checks that spot degradation within a day.
Useful AI still depends on open-enough APIs and predictable quality. If defense means turning inference into a soft honeypot for half the world's traffic, the product gets worse for everyone who isn't a nation-state team. The likelier durable fix is shared threat intel and hard identity for high-volume access—not making ordinary users guess whether they got the real model today.
I'm watching whether U.S. labs adopt silent downgrades in production, how China responds beyond rhetoric before the September 24 meeting, and whether allied governments actually build the information-sharing layer the agencies say is essential.
Context
Distillation attacks have been a live industry worry for more than a year. The April warning that a crackdown was coming preceded this more granular accusation. Agencies recommend flagging campaigns that run days to months at volumes far above normal research use, and balancing security against user experience while keeping safety researchers informed of model changes.
Who feels it
- U.S. frontier labs
- Pressure to harden APIs, identity, and abuse detection—and to consider silent degradation that risks backlash from real customers.
- Enterprise and research users
- Stronger verification and anomalous-traffic policing may mean friction, false positives, or unexplained quality drops.
- Chinese AI firms named
- Public branding as industrial distillers raises export-control, partnership, and reputational heat regardless of Beijing's denial.
- Allied governments
- Asked to share distillation-threat intelligence so labs aren't chasing isolated anomalies alone.
What to watch
- Whether major U.S. labs confirm they will silently switch or degrade suspected distillation accounts.
- Concrete enforcement steps beyond the joint advisory—sanctions, export rules, or criminal referrals.
- How Trump–Xi diplomacy on September 24 treats AI IP and model access.
- Evidence that shared industry–government threat intel actually changes attacker economics.