US security agencies have accused China's top AI companies including DeepSeek and Kimi maker Moonshot AI of systematically extracting proprietary knowledge from American firms and warned Silicon Valley developers to protect their work.
The Chinese firms have used a technique known as distillation since at least 2024 to gain access to and draw information out of US AI models "at an industrial scale" to train their own systems, according to a joint statement issued Tuesday by the National Security Agency, FBI and Cybersecurity and Infrastructure Security Agency. The agencies specifically accused DeepSeek, Moonshot, Alibaba Group Holding Ltd., MiniMax, StepFun and Z.AI Co. of the practice.
Trump administration officials and American AI developers alike have accused Chinese firms of distilling from US AI models in the past to build their own products. The practice, which can be legitimately deployed by an AI developer that uses its state-of-the-art model to effectively teach a more power-efficient version, is seen as an improper shortcut when done without approval. The security alert issued Tuesday takes the accusations one step further, detailing which US systems were distilled by each of the Chinese companies and for what reasons, including to improve their own models' abilities to solve math problems and review code.
The security agencies went as far as to say the companies are likely siphoning information from American models "with knowledge of the Chinese government" and accused the firms of intentionally skirting US companies' use restrictions to access their systems.
"China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies' terms of use," they said in the notice.
A spokesperson for the Chinese embassy didn't respond to a request for comment. China's government has previously rejected US claims of unfair use of distillation. Representatives for DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.ai did not immediately respond to requests for comment.
The agencies advised US AI developers to take "immediate action," including altering responses to suspected malicious distillation attempts and sharing their intelligence on distillation campaigns with one another.
OpenAI and Anthropic PBC have increasingly complained that their Chinese rivals are gaining unauthorized access to their models to develop their own chatbots at a fraction of the cost.
In June, Anthropic accused Alibaba of waging a large-scale effort to "illicitly" access its Claude model using thousands of fraudulent accounts, Bloomberg News reported previously.
The Trump administration vowed in April to take further steps to address the practice. US lawmakers are also considering measures aimed at penalizing Chinese companies found to be copying unfairly from their American counterparts. Tuesday's security advisory may serve as a means of accelerating those efforts.
Issued just weeks before President Donald Trump is scheduled to welcome his Chinese counterpart Xi Jinping to Washington for a high-stakes summit, the agencies' accusations threaten to intensify friction between the world's two largest economies. AI has increasingly moved to the center of the US-China rivalry, with each side seeking to dominate the market for the technology.
US Treasury Secretary Scott Bessent warned in July of the prospect of sanctions for any Chinese venture found to engage in intellectual property theft. Bessent spoke days after Moonshot released Kimi K3, a model that ignited widespread concerns about Chinese firms gaining ground against the US on AI.

