Six Chinese AI firms accused of aggressively copying US frontier models
US security agencies have accused six China-based AI companies of systematically extracting capabilities from US frontier models, potentially accelerating Chinese AI development and reducing costs. The NSA, CISA and FBI say the firms used techniques such as large-scale API exploitation and prompt injection against models including variants of Claude, GPT, Gemini and Grok since at least late 2024.

Why It Matters
If true, the alleged industrial-scale distillation could shorten Chinese development timelines and erode US leadership in frontier AI, prompting government-directed countermeasures that may affect user experience and privacy. The agencies are urging coordinated action across industry and allied governments to blunt the activity.
Key Facts
- Agencies: National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI)
- Accused firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI
- Alleged timeframe: Since at least late 2024
- Targeted US models: Variants of Claude, GPT, Gemini, Grok
- Primary techniques cited: Bulk-buying fake accounts to exploit inference APIs; coordinated identical prompts; prompt-injection/jailbreaking to extract chain-of-thought
US cybersecurity and intelligence agencies say six China-based AI companies have been engaged in large-scale campaigns to extract capabilities from leading US models, a practice the agencies contend can materially shorten rival development timelines and save training costs. In a joint statement, the NSA, CISA and FBI named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI and said the activity has been ongoing since at least late 2024. The agencies added the operations “likely” occurred with Chinese government awareness and targeted variants of Claude, GPT, Gemini and Grok.
According to the agencies, the campaigns use multiple tactics to siphon functionality from inference APIs. One described approach involves bulk purchasing of accounts and routing them through proxy services so large numbers of near-identical queries can be issued across days or months. Another common method is prompt injection that attempts to jailbreak models and coax out hidden reasoning; the agencies specifically said DeepSeek used prompts instructing models to write out step-by-step internal reasoning for completed responses.
To blunt these efforts, the US agencies recommended that American AI firms strengthen detection of anomalous accounts, networks and prompt patterns and tighten identity verification and monitoring of enterprise subscriptions. They also urged firms to adopt defensive response changes: subtly degrading or altering outputs—for example by changing reasoning style, reducing reasoning depth, adding stylistic noise—or quietly routing suspected distillation actors to less-capable model variants without notifying users. The agencies argued such moves would lower the value of extracted outputs to adversaries.
The agencies acknowledged those mitigations pose technical and user-experience trade-offs. Adversaries may use adaptive discovery and automated quality checks to detect defensive downgrades, and poorly targeted measures risk affecting legitimate users who could see shorter or lower-precision responses without warning. The agencies recommended balancing security and user experience, informing safety researchers and third-party evaluators of changes, and pursuing coordinated action across industry and allied governments as part of a longer-term defense strategy.
Keep Reading

Automattic CEO Matt Mullenweg placed on leave

AI advocacy group launches state-level policy push

The incomplete history of Duo devices

The black iPhone Pro returns
Original source: Ars Technica AI