The federal cybersecurity advisory from CISA, the NSA and the FBI is a clear shot across the bow. It accuses China‑based AI firms of running “industrial‑scale” knowledge‑distillation campaigns to harvest proprietary capabilities from U.S. frontier models. Beijing answered with the usual denials and a warning of “countermeasures.” This is not petty tech fighting — it’s industrial espionage dressed up as a research shortcut, and it demands a firm American response.
CISA, NSA and FBI: What the advisory says about China AI theft
AA26‑251A spells out the allegations
The joint advisory (AA26‑251A) names firms such as DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI and says they “extracted billions of tokens across millions of exchanges” from U.S. frontier models like Claude, GPT, Gemini and Grok. The agencies describe tactics — fraudulent accounts, proxy transfer stations, bulk subscriptions and metadata scrubbing — that look a lot like organized data theft. Anthropic’s earlier disclosure about millions of exchanges with Claude and 24,000 fake accounts gave industry proof of concept; now the U.S. government has amplified those claims into a national‑security advisory.
Why mass distillation is not innocent research
It behaves like industrial espionage, and it risks safety
Knowledge distillation is a normal machine‑learning tool when used openly and ethically. But when it’s done covertly at scale to copy a competitor’s capabilities without paying or following rules, it’s theft. Worse, copied models may lack the safety guardrails built into the originals. That increases the chance of misuse — from cyber‑attacks to weaponized code or disinformation — and turns a commercial quarrel into a security crisis. The advisory even warns this was “likely with Chinese government awareness,” which elevates the problem from corporate bad behavior to state‑sponsored strategy.
Beijing’s predictable pushback — denial and bluster
“Groundless” claims and threats of countermeasures
As expected, China’s Ministry of Commerce called the allegations “groundless” and accused the U.S. of trying to monopolize AI. Foreign Ministry spokeswoman Mao Ning urged cooperation and rejected “unfounded accusations.” Translation? China’s playbook is denial, then retaliation if pressed. That posture risks turning a technical fight over code into a diplomatic showdown — and could complicate upcoming talks about AI governance between President Donald Trump’s administration and President Xi Jinping’s government.
What Washington should do next
Move from warnings to hard countermeasures and smarter defenses
The advisory includes sensible mitigation steps — detect abnormal query patterns, covertly degrade outputs to frustrate extractors, and share telemetry across providers. Those are useful, but not enough. The U.S. must pair tougher cyber defenses with real consequences: tighter export controls, targeted sanctions or entity listings for firms that act as conduits for theft, and legal tools to go after bad actors. Treasury Secretary Scott Bessent’s insistence that China cannot outrun the U.S. in AI is a morale booster, but words mean little without coordinated action. If we want AI to be an engine for American prosperity and security, we must treat theft like theft — and stop pretending a stolen shortcut is innovation.
