U.S. officials and American AI developers are accusing major Chinese artificial-intelligence companies of using industrial-scale “distillation” campaigns to extract valuable capabilities from leading U.S. models, potentially allowing Chinese competitors to reproduce sophisticated reasoning, coding and agentic functions without bearing the enormous cost of developing them independently. The allegations center on DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, which are accused of routing millions of queries through proxy services, fraudulent accounts and intermediary “transfer stations” to reach American models despite access restrictions. The controversy raises concerns extending beyond intellectual-property theft to national security and user privacy, particularly because some intermediaries allegedly combined ordinary customer queries with model-extraction traffic. China rejects the accusations, calling them groundless and arguing that distillation is a standard AI-development practice.
Key Takeaways
- U.S. authorities allege Chinese AI developers extracted billions of tokens through millions of exchanges with American frontier systems, using distillation to accelerate development while reducing the enormous computing and research costs associated with building comparable capabilities independently.
- Investigators say proxy networks, fraudulent accounts, shared premium subscriptions and third-party intermediaries were used to circumvent access restrictions and make coordinated extraction traffic more difficult for American companies to identify and block.
- The dispute has become a strategic U.S.-China technology issue: Washington sees industrial-scale extraction as a threat to American intellectual property and technological leadership, while Beijing argues the accusations politicize a legitimate and widely used AI-training technique.
In-Depth
U.S. security agencies are escalating warnings that Chinese artificial-intelligence developers have harvested capabilities from American frontier models, turning a legitimate training technique known as distillation into industrial-scale extraction. The allegations name DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, with investigators saying the firms generated millions of coordinated requests and billions of tokens from systems including Claude, GPT, Gemini and Grok.
The concern extends beyond technological competition. Investigators say operators used proxy networks, fraudulent accounts, shared subscriptions and third-party intermediaries to evade geographic restrictions and detection. Such methods could allow competitors to reproduce valuable reasoning, coding and agentic capabilities while avoiding research, computing and development costs. Anthropic reported detecting more than 16 million exchanges associated with three Chinese laboratories, illustrating the scale of the challenge.
The episode also exposes a troubling data-security dimension. When intermediary services mix legitimate customer traffic with extraction campaigns, user prompts may travel through infrastructure customers never selected. Sensitive business, personal or proprietary information could therefore become entangled in an organized effort to train competing systems.
Beijing rejects the accusations as groundless and argues that distillation is common throughout the global AI industry. That defense, however, does not resolve the central American allegation: that access restrictions and service terms were deliberately circumvented at massive scale. Washington now faces a strategic choice between preserving commercial access and protecting intellectual property that required vast American investment. Stronger identity verification, coordinated threat sharing and targeted access controls appear necessary if the United States intends to preserve its model advantage.

