Global

Six Chinese AI Labs Accused of ‘Industrial-Scale’ Model Theft — Washington Says It Has the Numbers

5 min read

The US government has moved from informal complaints to a formal, multi-agency accusation: on September 8, the National Security Agency, the FBI, and the Cybersecurity and Infrastructure Security Agency jointly published an advisory accusing six China-based AI developers of extracting proprietary capabilities from American frontier models at what the agencies described as an industrial scale.

The companies named are DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun, and Z.AI — a list that covers most of China’s best-known large language model developers, not a single rogue actor. The models allegedly targeted include Claude, GPT, Gemini, and Grok variants, with the advisory stating the extraction campaigns date back to late 2024 and have continued essentially uninterrupted since.

Distillation, Weaponized

The technique at the center of the advisory is knowledge distillation: training a smaller or cheaper model on the outputs of a more advanced one, so the smaller model inherits reasoning patterns, coding ability, or other specialized capabilities without the cost of training them from scratch. Distillation itself is not inherently improper — it is a standard, widely published research method used by labs everywhere, including in the United States. What the advisory alleges is scale and intent: coordinated, high-volume querying designed specifically to reverse-engineer capabilities rather than to build on public research.

Anthropic’s own disclosure, cited in the advisory, is the most concrete data point so far. The company says three China-based labs ran what it called an “industrial-scale campaign” against Claude, generating more than 16 million exchanges through roughly 24,000 fraudulent accounts. Investigators also describe the use of “transfer stations” — API proxy layers that route requests through intermediary services to mask origin and dodge regional access restrictions — as a recurring piece of the infrastructure behind these campaigns. By the agencies’ account, the pattern was not a handful of researchers testing a model; it was infrastructure built to harvest at volume.

The advisory also puts a number on one specific case: by mid-2026, Z.AI is alleged to have extracted billions of tokens’ worth of output from GPT-5.5 and Claude Opus 4.8, using that harvested data to build up its own model’s reasoning capability rather than developing it independently. Investigators separately challenged DeepSeek’s long-repeated claim that its earlier flagship model cost only around $5.6 million to train, arguing that figure omits the cost of the distillation infrastructure that made such a cheap headline number possible in the first place — reopening a dispute over Chinese AI cost claims that has simmered since early 2025.

CISA’s acting director, Nick Andersen, framed the advisory as a call to action rather than a closed case: “We strongly urge AI companies to take immediate steps to safeguard their platforms” against these campaigns, according to the agency’s statement. The recommendations that follow read like a hardening checklist for any company running a commercial model API: stronger account and identity verification, active monitoring for enterprise-scale usage patterns from suspicious accounts, deliberately varying model responses and limiting exposed reasoning depth, deploying differential privacy with hard rate limits, sharing threat indicators across platforms, and training models to resist the kind of systematic prompting used to extract internal reasoning traces.

None of the six named companies had issued a substantive public rebuttal as of this writing, and Chinese officials have not offered a formal government response to the specific advisory. That silence is itself notable — after more than a year of Western AI labs privately grumbling about suspicious usage patterns from Chinese IP ranges and shell accounts, this is the first time the claim has been elevated to a joint, named, agency-level accusation rather than a single company’s complaint.

What changes now is less the underlying behavior — which multiple labs say has been happening since late 2024 — than its formal status. A joint NSA-FBI-CISA advisory functions differently than a corporate blog post: it becomes the reference point for future export-control tightening, for enterprise procurement risk assessments, and potentially for legal action against companies or resellers found facilitating the “transfer station” infrastructure the advisory describes. Expect every major US model provider to point to this advisory the next time they justify a stricter API rate limit or a new identity-verification requirement.

What This Means for Philippine Founders

Two concrete effects are worth planning around rather than just reading about. First, Philippine startups building products on top of Claude, GPT, or Gemini APIs should expect tighter enterprise verification, lower default rate limits, and more aggressive anomaly detection in the coming months — a direct, foreseeable response to this advisory’s own recommendations. A local AI-wrapper startup running genuinely high but legitimate query volume (a customer-support bot serving thousands of Filipino users, for instance) may get caught in broader anti-abuse tightening and should be ready to document usage patterns proactively rather than get blindsided by a sudden account review.

Second, and more strategically: a meaningful share of Philippine startups — particularly in content, customer service, and low-margin fintech tooling — have leaned on cheaper Chinese-model APIs precisely because they undercut US pricing. If that pricing gap is partly explained by extracted rather than independently developed capability, as this advisory alleges, it raises real dependency risk. A sudden platform ban, a fresh export-control response, or a geopolitical flashpoint could disrupt access to those models with far less warning than a normal vendor price change — worth factoring into any build decision that currently assumes a specific low-cost Chinese model stays available and unchanged.

AI distillation Alibaba Anthropic China DeepSeek export controls

Share this article

Share on X Share on LinkedIn Share on Facebook

Related Articles

Newsletter

By subscribing, you agree to our Privacy Policy.