In a rare joint statement, US security and cybersecurity agencies named six Chinese AI companies accused of aggressively extracting proprietary functionalities from leading American AI models, underscoring escalating tensions in global AI technology competition.

  • Six Chinese AI firms accused of large-scale IP theft from US AI models.
  • Attack methods include fake account swarms and prompt injections.
  • US agencies demand enhanced detection, user verification, and response downgrading.

What happened

The US government, through a coordinated effort by the NSA, Cybersecurity and Infrastructure Security Agency (CISA), and the FBI, publicly accused six Chinese AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—of launching extensive industrial-scale attacks designed to harvest capabilities from frontier American AI models. These attempts have been active since late 2024 and focused on advanced models like variants of Claude, GPT, Gemini, and Grok.

Why it matters

This disclosure highlights a significant cybersecurity and intellectual property challenge at the heart of the global AI race, raising concerns over the loss of American technological advantage. The aggressive distillation of AI models can undermine innovation incentives and threaten US economic and national security interests by enabling adversaries or competitors to leapfrog costly development efforts.

Moreover, the implicated Chinese firms’ use of large-scale proxy networks and gray-market accounts to evade detection shows a heightened level of operational sophistication in industrial IP theft. For US AI companies and policymakers, these activities necessitate new defensive measures that balance robust countermeasures against privacy and legitimate user access.

What to watch next

US agencies have urged the AI sector to improve detection of anomalous query behaviors, strengthen identity verification processes, and monitor subscription usage patterns for signs of bulk exploitation. Additionally, they recommend that companies subtly degrade the value of model outputs—altering response reasoning or switching suspected accounts to less capable models covertly—to reduce the payoff of these distillation attacks.

The effectiveness of these mitigations and the degree of international cooperation to protect AI intellectual property will be critical to monitor. The ongoing escalation highlights a growing intersection between AI technology development, cybersecurity policy, and geopolitical rivalry that could shape the future competitive landscape.

Source assisted: This briefing began from a discovered source item from Ars Technica Tech Policy. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings