US agencies accuse DeepSeek, Alibaba and four other Chinese labs of industrial-scale AI distillation
The FBI, NSA and CISA said six firms used transfer-station proxies to mine Claude, ChatGPT, Gemini and Grok. Scott Bessent put sanctions and Entity List designations on the table ahead of Xi Jinping’s late-September visit.

Washington3 min read
Last updated
The FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency accused six Chinese artificial-intelligence companies on 8 September of copying American frontier models “at an industrial scale.” The method named in the joint advisory is distillation: training a cheaper model on the outputs of a larger one until the student reproduces the teacher’s behaviour.
The six firms named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The American models listed as sources are Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini and xAI’s Grok. Officials said the campaign has run since 2024 and was conducted “likely with Chinese government awareness.” They did not claim that Chinese intelligence services ran the work.
Distillation itself is a standard engineering trick. Labs use it to shrink models they already own. The accusation here is that the Chinese companies obtained restricted capabilities by querying American systems through a grey market of proxies that the advisory calls “transfer stations.” Those relays are designed to defeat geographic blocks, terms of use and rate limits that US vendors put on their application programming interfaces.
The agencies said the copied functions included legal specialisation, agent-style tool use and coach or assistant behaviour. Reuters, CNN and NBC, which saw the text, reported that the document goes further than earlier public complaints from OpenAI and Anthropic, which had described suspicious query patterns without naming a full roster of Chinese developers.
Treasury Secretary Scott Bessent answered on X the same day. “When [People’s Republic of China] firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table,” he wrote. The Entity List is the Commerce Department’s roster of foreign parties that US exporters need a licence to supply. A listing would hit chips, cloud contracts and any remaining legal access to American model weights.
The timing is not accidental. President Donald Trump is due to host Xi Jinping in the United States later this month. Officials in Washington have been assembling a file of economic complaints to take into that meeting. Distillation sits next to export-control evasion and semiconductor smuggling on that list. Chinese officials have not issued a detailed reply. State media have treated distillation as ordinary research practice and have pointed to US export bans as the reason Chinese labs must find cheaper training paths.
There is a technical dispute underneath the politics. American vendors argue that high-volume, structured querying of a closed model, followed by training on the transcripts, is theft of trade secrets. Chinese developers argue that publicly exposed chat interfaces produce text that anyone may read, and that training on public text is how the whole industry works. Courts in the United States have not settled that question for generative models. The advisory does not wait for a court. It treats the conduct as hostile and asks companies that host models to tighten access.
What the document does not do is quantify the gap that distillation is said to have closed. It does not say that a named Chinese model now matches Claude or GPT on a named benchmark because of stolen traces. It says the companies ran “high-volume knowledge distillation campaigns” against specific product lines. That is a law-enforcement claim, not a model-evaluation paper.
For buyers of Chinese models the practical effect arrives later, if Bessent follows through. An Entity List hit on DeepSeek or Alibaba’s cloud arm would raise the cost of serving those models outside China and would complicate any remaining joint research. For American labs the effect is immediate: more logging of unusual query patterns, more geographic fencing, more pressure on partners that resell API access.
Xi’s visit will test whether the file stays a talking point or becomes a sanctions package. The three agencies have now put names, methods and a date range on the record. The next move belongs to Commerce, Treasury and the two leaders who are supposed to sit across a table before the month is out.