Key Points
- US security agencies accuse six Chinese companies of industrial-scale distillation targeting leading American AI models.
- The technique uses a teacher model’s answers and reasoning to improve a cheaper student system.
- Potential sanctions, lawsuits and access restrictions could reshape competition ahead of the Trump-Xi meeting.
The latest
US security agencies, including the National Security Agency and Federal Bureau of Investigation, accused six Chinese artificial-intelligence companies of systematically exploiting American models to train their own systems. They described the activity as “aggressive, malicious and targeted distillation” at industrial scale and said the companies conducted millions of exchanges with frontier systems including Claude, ChatGPT, Gemini and Grok. The allegations elevate a widely used AI training technique into a US-China policy dispute.
Details
- How it works: Distillation follows a model’s initial training on large text collections. Engineers prompt a more capable “teacher model” to answer questions and explain its reasoning, then use those exchanges to fine-tune a “student model” by adjusting its weights. The process supplements work by human experts, reduces costs and helps the student produce more natural, useful responses.
- Competitive impact: An Anthropic executive said in July that distillation had helped China narrow its AI gap with the United States from 12 to 18 months to roughly six to nine months. The agencies called distillation the “critical core” of Chinese AI development rather than a supplementary tool. Some US researchers argue it is not the main driver of China’s latest advances.
- China responds: The accused companies have not directly denied distillation. After Moonshot AI released Kimi K3 in July, an executive said its “breakthrough performance” resulted from fundamental innovations, not distillation or copying. A Chinese Foreign Ministry spokeswoman called on Washington to stop making false accusations and smearing China.
- Legal dividing line: Companies commonly distill their own models to create smaller versions, while distillation of downloadable, modifiable open-weight systems is widely accepted. Closed models such as Claude present a harder legal question. Some specialists say their outputs are unlikely to receive intellectual-property treatment comparable to books or films, and distillers use those outputs to learn rather than copy them directly.
- Possible US action: Anthropic said in February that Chinese companies used fraudulent accounts and proxy services to reach Claude at scale while evading detection. Treasury Secretary Scott Bessent raised sanctions and Entity List designations for covert operations crossing into intellectual-property theft. Lawsuits over service terms are another option, although overseas intermediaries could complicate evidence gathering and prolong litigation.
Background
A July open letter backed by Nvidia and Microsoft warned against sweeping restrictions on techniques important to AI innovation. It urged authorities to address unlawful distillation through targeted legal and commercial frameworks. Anthropic bars Chinese companies from using Claude, while other US developers prohibit distillation intended to build competing models.
What’s next
President Donald Trump is scheduled to meet Chinese leader Xi Jinping in Washington in late September, when artificial intelligence may enter the discussions. The policy indicator will be whether Bessent moves ahead with blacklisting Chinese AI companies, potentially restricting access to their models and exposing developers to wider US sanctions.