Development
Six Chinese AI firms accused of aggressively copying US frontier models
September 10, 2026 Development Source: Ars Technica
Share this article
Flagging this activity should be somewhat easy, agencies suggested, since “campaigns span days to months with query volumes in the thousands to millions per domain, far exceeding legitimate research or development use cases.”
Generally, they’ve recommended stepping up monitoring for “anomalous and malicious prompts, accounts, networks, and behaviors.” Because Chinese firms rely on “bulk procurement of the US AI companies’ premium subscriptions shared across teams of developers,” that effort should also include flagging accounts with suspicious subscription-to-usage ratios, as well as any new accounts immediately hitting maximum usage, agencies said. Both indicate “bulk deployment with pre-engineered templates,” agencies said. US firms should also be strengthening “identity verification” of users and more closely tracking individuals using enterprise subscriptions (both of which potentially raise privacy red flags for legitimate users).
Next, agencies asked firms to start dumbing down model responses when suspected distillation attacks are flagged. By “subtly” altering responses—such as by “presenting correct information with different reasoning,” adding stylistic inconsistencies, or reducing reasoning depth—firms can decrease the payoff for Chinese firms. US firms could also secretly switch malicious accounts to an inferior model, and they should do so without providing any notice, agencies suggested.
Still, agencies think it’s best practice to “avoid informing China-based AI company users suspected of distillation campaigns of a switch to a downgraded model.”
Acknowledging that such steps could frustrate users, agencies said that firms should try to “balance security with user experience” while accepting that some trade-offs, like “lower prediction precision and business usefulness,” may be inevitable to keep China from copying US capabilities. However, US firms should strive to ensure that “AI safety researchers and third-party evaluators” are “informed of model changes,” agencies suggested.
Finally, and seemingly most critical to the defense strategy long-term, agencies want AI firms and allied governments to share information to help leading firms track how distillation attacks evolve and avoid wasting time researching isolated anomalies.
Cooperation is critical, the US thinks. If everyone cannot work together, then the US will face ongoing financial harm “through systematic extraction of proprietary functionality and capabilities, causing significant economic losses,” agencies warned.
AI firms have been warning about distillation attacks since last year. OpenAI accused DeepSeek of using data improperly, Google claimed attackers tried to clone Gemini, and Anthropic suggested that Alibaba should be criminally punished for allegedly launching the largest-ever cloning attack on Claude. Very quickly, the government got behind them, in April warning China that a crackdown was coming.
The joint statement released on Tuesday, though, was the Trump administration’s “most detailed accusation yet,” NBC News noted. In it, agencies claimed that stolen AI model capabilities “form the core—not merely a supplement”—of China’s AI development strategy.
DeepSeek was accused of “extensive malicious distillation” on Claude, Gemini, GPT, and Grok models in efforts to “reduce its compute and research costs.” The Chinese firm allegedly took specialized training data and a range of capabilities, including agentic functions, assistant capabilities, writing optimization, question-and-answer optimization, and chain-of-thought reasoning.
Moonshot AI took a similar approach, switching between models from leading US firms to distill fine-tuning techniques, reinforcement learning, software engineering, and math capabilities.
Other firms, including Alibaba, MiniMax, StepFun, and Z.AI, seemed focused on copying particular models from Anthropic and OpenAI, agencies said.
Ars reached out to all AI firms whose models were allegedly targeted by Chinese firms, but no company immediately responded. So, it’s hard to say if the recommended mitigations are practical.