US claims Chinese AI firms are carrying out ‘industrial-scale’ theft of trade secrets

13 hours ago  ·  4 min read
By James Lopez - sandego.net
gettyimages-2195797164

US Claims Chinese AI Firms Stole Trade Secrets

Sandego.net – US claims Chinese AI firms are conducting what three federal agencies call an “industrial-scale” operation to siphon proprietary capabilities from American rivals. The FBI, the National Security Agency, and the Cybersecurity and Infrastructure Security Agency released a joint advisory on Tuesday laying out the allegation in formal government language — a step that elevates months of private executive complaints into an official record at precisely the moment Washington and Beijing are clashing over control of next-generation computing intelligence.

How Distillation Became a National-Security Issue

Knowledge distillation is a standard machine-learning technique: a smaller model learns by imitating the outputs of a larger, more capable one, compressing the teacher’s behavior into a cheaper student. Used inside a single lab or across academic collaborations, the practice is unremarkable. What the advisory targets is the covert infrastructure and sheer volume behind Chinese operators’ use of the method against specific American frontier models.

The agencies wrote that Chinese companies are leveraging distillation to “extract restricted proprietary functionalities and capabilities of U.S. frontier AI models,” and that the operational scale indicates the technique functions as the central engine of their model-development pipeline rather than a peripheral research exercise.

“The sheer scale of these campaigns and their sophistication indicate that distillation is not a supplement to these companies’ AI model development, but the critical core of it.”

To dodge geographic restrictions, usage terms, and the technical safeguards embedded in American APIs, the advisory says Chinese operators route queries through a network of intermediaries it labels “transfer stations” — a gray-market proxy layer that obscures the originating IP address and corporate identity behind each request.

Named Targets and the Sanctions Lever

The advisory singled out DeepSeek and Alibaba Group as having carried out “high-volume knowledge distillation campaigns” aimed at US-based AI companies. Treasury Secretary Scott Bessent went a step further, signaling that punitive measures are already being prepared for firms he views as having crossed from aggressive benchmarking into outright intellectual-property theft.

“When [People’s Republic of China] firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.”

An Entity List designation, administered by the Department of Commerce, can cut off a company’s access to American semiconductors, software, and components. For any firm dependent on Nvidia GPUs or US cloud infrastructure, that constraint carries practical weight well beyond the rhetorical force of the announcement.

Anthropic’s Figures: 16 Million Exchanges Across 24,000 Accounts

Separately, Anthropic — the company behind the Claude model family — alleged that three Chinese AI laboratories mounted an “industrial-scale campaign” to pull capabilities out of Claude. The company stated those labs generated more than 16 million conversational exchanges through roughly 24,000 accounts it characterized as fraudulent. If accurate, the figure implies sustained, automated querying at a scale far beyond what a casual researcher or a single competitor’s evaluation team would produce.

US claims Chinese AI firms are stealing model capabilities gain additional force when a corporate whistleblower’s numbers sit alongside a government-verified advisory. The pairing makes dismissal by Beijing considerably harder than either allegation standing alone.

Open-Weight Models and the Broader Competitive Picture

Chinese open-weight models — released with publicly downloadable parameters rather than locked behind a proprietary API — have been climbing in global adoption. Developers can fine-tune them locally, run them on-premises without shipping data to a foreign cloud, and often pay less per inference than they would for a closed American system. If those models are, in part, built on distilled knowledge extracted from US frontier systems, the competitive advantage they offer downstream users rests on a foundation that Washington now says was taken without authorization.

The distillation story also sits within a wider pattern of AI assets being treated as espionage targets. Google’s Threat Intelligence Group has published findings on parallel covert-collection efforts, reinforcing the view that model weights, training data, and inference outputs are now contested strategic resources on par with semiconductors and rare-earth minerals.

Frequently Asked Questions

What exactly did the three agencies accuse Chinese firms of doing? The FBI, NSA, and CISA alleged that major Chinese AI companies used knowledge distillation at industrial scale to extract proprietary capabilities from American frontier models, routing queries through hidden intermediary infrastructure to avoid detection.

Which companies were named in the advisory? DeepSeek and Alibaba Group were specifically identified as having carried out high-volume distillation campaigns against US-based AI companies.

What penalties could follow? Treasury Secretary Scott Bessent indicated that sanctions and Entity List designations are under consideration. An Entity List designation can restrict access to US semiconductors, software, and components.

How does Anthropic’s claim relate to the government advisory? Anthropic reported that three Chinese labs generated over 16 million exchanges with Claude through approximately 24,000 fraudulent accounts. Its corporate allegation complements the agencies’ formal finding, giving the accusation both a private-sector and a government-verification dimension.

Does this mean Chinese open-weight models are invalid? The advisory does not invalidate any released model. It asserts that some of the underlying knowledge may have been acquired without authorization, which could affect future licensing, procurement, and sanctions decisions.

More from this category