Editorial illustration for US Agencies: Chinese AI Firms Copied US Models With Government Awareness
US Agencies: Chinese Firms Copied American AI Models
Three US government agencies put names to a claim they've been building toward for months: China's AI industry has been systematically siphoning capabilities out of American models, and Beijing probably knew about it. The NSA, CISA, and FBI said in a joint release Tuesday that six firms, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, have run what amounts to an industrial-scale extraction operation against US systems since late 2024.
The targets read like a list of the field's frontier products: Claude, GPT, Gemini, Grok. The method, according to the agencies, isn't subtle. It involves buying up fake accounts in bulk to query US model APIs, then running coordinated, near-identical prompts across those accounts by the thousands or millions. The agencies frame this as a shortcut that lets Chinese firms skip years of costly training and catch up on the cheap, at American companies' expense.
The three agencies are now calling for coordinated action from US AI firms and allied governments to shut down the practice, arguing it threatens the American lead in AI development. Before laying out how the attacks work, the agencies made the case for why this matters now.
“China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model,” agencies said.
Why this matters
For developers and founders building on Claude, GPT, Gemini, or Grok, this advisory is a reminder that API access is a two-way door. If the NSA, CISA, and FBI are right, six Chinese firms turned query access into a shortcut around years of training investment, and did it with Beijing's apparent knowledge. That changes the calculus for anyone licensing frontier models or building products on top of them: the moat you thought you were renting might already have a hole in it.
We're skeptical of the "likely" hedge doing a lot of work here, government attribution claims deserve scrutiny, but the pattern the agencies describe, industrial-scale distillation since late 2024, tracks with how fast DeepSeek and MiniMax have closed capability gaps that shouldn't have closed that quickly. Watch what US labs do next: tighter rate limits, more aggressive output watermarking, or contractual language aimed squarely at distillation. Watch too whether this advisory becomes the opening argument for new export controls on API access itself, not just chips.
That's the fight actually being set up here.
Common Questions Answered
Which Chinese AI firms have been accused of copying US models according to the NSA, CISA, and FBI?
Six Chinese AI companies have been named in the joint advisory: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. According to the three US government agencies, these firms have been conducting industrial-scale distillation operations against US AI systems since late 2024.
What is industrial-scale distillation and how does it benefit Chinese AI companies?
Industrial-scale distillation is the systematic extraction of capabilities from US AI models through query access and API usage. According to the agencies, this practice allows China-based AI companies to achieve significantly shorter AI development timelines and reduced financial expenditures in training frontier models, effectively bypassing years of training investment.
What US frontier AI models have been targeted by this extraction operation?
The targeted models include Claude, GPT, Gemini, and Grok, which represent the leading frontier AI systems from major US developers. These models were accessed through API access, which the agencies describe as a potential security vulnerability that can be exploited for capability extraction.
What does the advisory mean for developers building products on US frontier models?
The advisory serves as a warning that API access to frontier models creates a two-way door where users can extract and replicate model capabilities. Developers and founders licensing these models should reconsider their security assumptions, as the competitive advantage they thought they were renting through model access may already be compromised by foreign competitors with government awareness.
What is the significance of Beijing's apparent knowledge of this AI model copying?
The US agencies' assertion that Beijing probably knew about the extraction operation suggests this is not merely corporate espionage but a state-level strategy to accelerate China's AI development. This implication raises serious concerns about the geopolitical competition in AI and the vulnerability of US technological advantages.
Further Reading
- US accuses Chinese AI firms of 'malicious' copying of AI technology - Reuters
- U.S. agencies say top Chinese AI companies systematically copied American models - NBC News
- White House accuses China of copying American AI models - CNN
- Trump administration vows crackdown on Chinese firms 'exploiting' U.S. AI models - NPR
- Anthropic says Chinese AI labs used Claude to train competing systems - CNN