Full Breakdown
U.S.–China AI Distillation Dispute Escalates Ahead of Bilateral Talks
By Drooid · · How we work
Core Event: Allegations of Large-Scale Model Distillation by Chinese Firms
U.S. security agencies—the FBI, NSA and CISA—issued a joint advisory accusing six Chinese AI companies (DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI) of “industrial-scale knowledge distillation” that extracted billions of tokens from models such as Claude, ChatGPT, Google Gemini and Grok. The advisory urges U.S. developers to “poison” responses to suspected distillation requests. Anthropic’s 145-page threat report corroborates massive “illicit distillation” attacks that routed user queries to its Claude models and returned the outputs as if generated by the Chinese firms.
Background & Context
Knowledge distillation trains a smaller “student” model to imitate a larger “teacher” model, lowering computational cost. U.S. officials contend that systematic, large-scale extraction of proprietary behavior amounts to IP theft and a national-security risk. Export controls on advanced chips since late 2022 have limited Chinese access to cutting-edge hardware, prompting some developers to rely on distillation.
Data & Statistics
- Six firms named in the advisory.
- Alleged extraction of billions of tokens since late 2024.
- Anthropic reports 151 million Claude exchanges by Alibaba (May-July 2026).
- Moonshot AI diverted ?300,000 requests using 5,380 fraudulent accounts.
- Activity peaked at ?3 million requests per day.
- DeepSeek conducted ?12 million attacks over two weeks in July.
Official Statements & Responses
- The advisory recommends U.S. firms “modify or restrict the responses” to suspected distillation accounts and avoid informing them of any downgrade.
- White House science adviser Michael Kratsios said Moonshot AI had distilled Anthropic’s Fable model using detection-evasion methods.
- Bessent, leading the U.S. delegation, warned that “there is no day after tomorrow if China wins at this” and stressed the U.S. cannot pause AI development while rivals advance.
- Chinese Foreign Ministry spokesperson Mao Ning called the accusations “false allegations” and urged Washington to honor understandings reached between former presidents.
- A Ministry of Commerce spokesperson labeled the U.S. approach a “double standard,” noting American firms also draw on Chinese open-source models.
- The Commerce Ministry later said there is “no factual or legal basis” for the accusations and warned of “countermeasures” if the U.S. moves to contain Chinese AI firms.
Criticism & Opposition
Chinese officials argue distillation is a neutral, industry-wide practice and that the U.S. is using security rhetoric to protect its dominance. Liu Dian, a research fellow at Fudan University, emphasized that “model distillation itself is a technical method widely used across the global AI industry, and not all capability transfer… can simply be equated with a national security threat.”
Conflicting Reports & Gaps
- Exchange counts differ: Anthropic cites 151 million Claude exchanges by Alibaba, while Bloomberg mentions “large-scale” activity without a precise figure.
- Account numbers vary: the New York Post cites 3,500 distinct accounts for Alibaba, whereas other sources note 5,380 fraudulent accounts for Moonshot.
- No independent technical audit has verified the extent of the alleged distillation, leaving the precise scope of IP loss uncertain.
What’s Next
U.S. and Chinese delegations will meet for AI safety talks in Washington, with the broader U.S.–China summit slated for September 24. Discussions are expected to focus on preventing AI-related security incidents and addressing the disputed distillation practices.
Verbatim Quotes
- “There is no day after tomorrow if China wins at this,” — Bessent
- “Model distillation itself is a technical method widely used across the global AI industry, and not all capability transfer or model learning can simply be equated with a national security threat,” — Liu Dian, Fudan University.
