US agencies accuse six Chinese AI firms of large‑scale model theft
U.S. intelligence agencies — the NSA, CISA and the FBI — released a joint statement alleging that six Chinese artificial‑intelligence companies have been systematically extracting capabilities from leading American models such as Claude, GPT, Gemini and Grok. The firms named — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — are said to have run industrial‑scale distillation campaigns…
Key points
- NSA, CISA, and FBI allege six Chinese AI firms have been industrial‑scale distilling US frontier models since late 2024.
- Targeted models include Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini and Grok, with attackers using fake accounts and prompt‑injection jailbreaks.
- US agencies urge AI companies to improve detection of coordinated query swarms and proxy networks to curb the alleged theft.
The agencies claim these activities dramatically shorten development timelines and cut billions of dollars in training costs for the Chinese firms, potentially eroding the United States’ lead in the AI race. They urge all U.S. AI providers to coordinate on defenses, including better detection of coordinated query swarms, proxy‑network evasion, and stricter API safeguards, to prevent further unauthorized extraction of proprietary model functionalities.
If unchecked, such large‑scale theft could reshape competitive dynamics, prompting tighter regulations and a push for more robust model protection across the global AI ecosystem.
The story so far
32 episodes →- US agencies accuse six Chinese AI firms of large‑scale model theft this story
Six Chinese AI firms accused of aggressively copying US frontier models
Ars Technica AI · 9 September 2026
The United States has now named six Chinese AI firms accused of waging industrial-scale attacks distilling US frontier AI model capabilities and perhaps sparing billions in Chinese development costs.
In a joint release Tuesday, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) alleged that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been attacking US models since at least late 2024. The firms “likely” acted with “Chinese government awareness” when extracting capabilities from US models, including variants of Claude, GPT, Gemini, and Grok, agencies said.
“China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model,” agencies said.
All American AI firms must work with the government and US allies to end the alleged theft threatening the US lead in the AI race, the agencies said. That will require coordinated action across the AI ecosystem to combat the “aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of US frontier AI models.”
Attack methods include “exploiting AI model inference APIs” by bulk-buying fake accounts, agencies said. Not registered to legitimate users, these swarms of fraudulent accounts execute “highly coordinated queries featuring identical or similar prompt texts,” which range “from thousands to millions on similar topics.”
Another common method is using prompt injection techniques to jailbreak models, including crafting “prompts forcing models to reveal their hidden [chain-of-thought] reasoning,” agencies said. For example, “DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step.”
Fixes may frustrate AI users in US
To encourage firms to work together, agencies recommended mitigations that would supposedly make it harder for Chinese firms to steal from US models.
First, AI firms must improve detection of sophisticated campaigns that allegedly use tens of thousands of accounts relying on “a gray market of proxies” to evade geographical restrictions and “route distillation requests through multiple pathways to gain unauthorized access.”
This text was published by Ars Technica AI and written by Ashley Belanger. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
Coverage and discussion
1 source- Hacker News discussion · 8 points news.ycombinator.com
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
Comments
via GitHub Discussions