WEDNESDAY 9 SEPTEMBER 2026 latent·wire 70 PIECES ON FILE
← AI NewsAI News

US agencies name six Chinese AI firms in industrial-scale model theft claims

The National Security Agency, Cybersecurity and Infrastructure Security Agency, and FBI jointly accused six Chinese AI firms on Tuesday of waging industrial-scale campaigns to distill capabilities from US frontier models, naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. In a joint release, the agencies alleged the companies have been attacking US models since at least late 2024 and "likely" acted with "Chinese government awareness" when extracting capabilities from variants of Claude, GPT, Gemini, and Grok.

The accusation centers on distillation, a technique in which a model's outputs are used to train a cheaper, smaller model that mimics its behavior. "China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model," the agencies said, arguing the practice could spare Chinese firms billions in development costs.

The agencies described several attack methods. One involves exploiting AI model inference APIs by bulk-buying fake accounts, which are not registered to legitimate users. These swarms of fraudulent accounts execute "highly coordinated queries featuring identical or similar prompt texts," ranging "from thousands to millions on similar topics." Another common method is prompt injection to jailbreak models, including prompts that force models to reveal their hidden chain-of-thought reasoning. The agencies cited DeepSeek as an example, saying it employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step.

The agencies called on all American AI firms to work with the government and US allies to end the alleged theft, which they said threatens the US lead in the AI race. They framed the response as requiring coordinated action across the AI ecosystem to combat "aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of US frontier AI models."

To encourage cooperation, the agencies recommended mitigations meant to make theft harder. The first is improved detection of sophisticated campaigns that allegedly use tens of thousands of accounts relying on "a gray market of proxies" to evade geographical restrictions and route distillation requests through multiple pathways to gain unauthorized access. The article's account of the recommended fixes was cut off mid-sentence in the available text, and the full set of proposed mitigations was not detailed.

The naming of specific companies escalates a long-running US concern about Chinese AI development. The firms named include some of China's most prominent AI labs, among them DeepSeek, whose low-cost models drew global attention, and Alibaba, whose Qwen models are widely used in open-source development. None of the six companies had publicly responded to the allegations in the available reporting.

What remains unclear is how the recommended mitigations would be implemented and whether they would affect legitimate users. The article's headline notes that the fixes "may frustrate AI users in US," suggesting the detection measures could impose friction on ordinary customers as well as on the fraudulent account networks they target. The agencies have not yet detailed enforcement steps or timelines for the coordinated action they are urging.

Why it matters

The US government's naming of six major Chinese AI firms marks an escalation in the AI race, alleging that industrial-scale model distillation is eroding America's frontier-model lead and prompting calls for coordinated industry action.