The National Security Agency, the Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation have jointly accused a group of Chinese artificial intelligence companies of orchestrating industrial-scale campaigns to copy proprietary American AI models. The agencies specifically named DeepSeek and Moonshot among the firms engaged in what they described as systematic model distillation. The coordinated statement signals a significant escalation in U.S. efforts to protect frontier AI intellectual property from foreign theft.
The Distillation Technique
Model distillation involves training a compact AI system to replicate the responses of a larger frontier model. The process typically starts by sending thousands of queries to the target model, capturing its outputs and then using that data to train a separate model. The result is a system that performs similarly to the original but at a fraction of the development cost.
The technique is widely used in legitimate research and product development. However, when applied to proprietary models without authorization, it becomes a tool for intellectual property theft. The U.S. agencies argue that Chinese AI companies have weaponized distillation on an industrial scale, systematically extracting capabilities from American models.
Government Response
The joint statement from NSA, CISA and the FBI represents a rare public alignment of three major security agencies on a technology theft issue. The agencies did not specify legal actions but indicated they are working with industry partners and international allies to counter the threat. They also urged American AI developers to implement stronger protections against distillation attacks, including output monitoring and access controls.
U.S. officials have long expressed concern about Chinese AI companies rapidly closing the capability gap with American frontier models. The government response, however, has historically focused on export controls for advanced chips rather than on direct countermeasures against model theft. This shift in emphasis suggests a more aggressive posture is taking shape.
Why This Matters
The accusation against DeepSeek and Moonshot could accelerate regulatory moves to restrict the sharing of advanced AI model weights and tighten cross-border data flows. For American AI companies, the risk of losing competitive advantage through distillation may drive changes in how they deploy and monitor their most powerful systems. For Chinese AI firms, the public censure risks further isolation from international research collaborations and access to Western cloud infrastructure. The broader effect is a deepening technological divide between U.S. and Chinese AI ecosystems, with potential consequences for global standards, talent mobility and the pace of innovation.



