Technology

US urges AI firms to ID, then secretly switch, Chinese users to less-capable models.

The United States government has officially escalated its campaign to protect domestic intellectual property in the artificial intelligence sector, naming six prominent Chinese technology firms accused of engaging in industrial-scale data harvesting. In a joint advisory issued on Tuesday, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) leveled formal allegations against DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies contend that these organizations have systematically compromised American frontier AI models to bypass the immense costs and time associated with independent model training.

This development marks a significant turning point in the intensifying AI arms race. For months, US-based laboratories have reported anomalous traffic patterns and sophisticated probing techniques targeting their most powerful systems, including variants of GPT, Claude, Gemini, and Grok. According to the federal advisory, these activities have been ongoing since at least late 2024 and are described as "industrial-scale distillation," a process where a smaller model learns to mimic the outputs and reasoning capabilities of a more powerful, proprietary model.

A Chronology of Escalating Tensions

The friction between US AI developers and Chinese firms is not a recent phenomenon, but the scope of the current accusations suggests a shift from private sector disputes to a high-stakes national security confrontation.

By mid-2025, companies such as OpenAI and Anthropic began publicly documenting instances of what they termed "malicious distillation." In August 2025, reports surfaced indicating that OpenAI had flagged DeepSeek for improper data usage. Shortly thereafter, Google alleged that unknown attackers—later linked to state-adjacent entities—had sent over 100,000 queries to Gemini in a structured attempt to clone its proprietary architecture. By June 2026, Anthropic took the dispute a step further, alleging that Alibaba had defied regulatory warnings to launch a massive cloning operation against Claude.

The April 2026 warning from the US government served as a precursor to the current advisory, signaling that the administration was preparing a multi-agency response. The Tuesday release is the most granular public assessment to date, detailing not just the "what," but the "how" of these operations.

The Anatomy of the Distillation Attacks

The federal agencies outlined several technical methodologies utilized by these firms to extract restricted intelligence. Central to these tactics is the exploitation of AI model inference APIs. By deploying vast networks of fraudulent accounts—often purchased through a "gray market" of proxies—attackers can bypass geographical restrictions and overwhelm service providers with millions of coordinated queries.

Six Chinese AI firms accused of aggressively copying US frontier models

One particularly invasive technique involves "jailbreaking" models through prompt injection. The advisory highlights that firms like DeepSeek have specifically instructed US-based models to articulate their internal, hidden chain-of-thought reasoning. By forcing the models to "think out loud" step-by-step, these actors can reverse-engineer the cognitive pathways and decision-making logic that constitute the core intellectual property of the frontier models.

Furthermore, these firms are accused of using the aggregated outputs to generate synthetic training datasets, effectively using American compute and research efforts to accelerate their own national AI development. The agencies noted that this strategy allows Chinese firms to achieve significant parity with US models while drastically reducing their own financial expenditures and research timelines.

Counter-Measures and the Risk of User Degradation

In response to these systemic threats, the NSA, CISA, and FBI have proposed a series of defensive strategies for US AI companies. These recommendations, however, present a complex dilemma for the companies involved, as they potentially prioritize national security over user experience.

The agencies suggest that firms should increase the intensity of their identity verification processes and monitor for "suspicious subscription-to-usage ratios." They specifically advocate for tracking accounts that immediately hit maximum usage limits, which often indicates automated deployment via pre-engineered templates.

Perhaps the most controversial recommendation is the suggestion that AI firms should "subtly" degrade the quality of responses when they detect suspected distillation activity. By introducing stylistic inconsistencies or intentionally reducing reasoning depth for suspicious accounts, firms could theoretically render the extracted data useless. The agencies go as far as suggesting that firms should "secretly switch" these users to inferior, less-capable models without providing any notice.

This strategy carries significant technical and operational risks. The agencies acknowledged that these defensive measures are not foolproof; sophisticated attackers often employ adaptive discovery tools to identify when they are being served "degraded" data. Furthermore, there is the risk of "false positives," where legitimate users are caught in the dragnet. If an ordinary user is inadvertently switched to a lower-capability model or receives cryptic, less-helpful responses, the resulting loss of trust could damage the reputation of American AI firms.

International Reactions and Diplomatic Friction

The response from Beijing has been characteristically defiant. On Wednesday, Mao Ning, a spokesperson for the Chinese Ministry of Foreign Affairs, dismissed the US allegations as "groundless" and a manifestation of political prejudice. She defended China’s technological advancements as the result of "high-level scientific and technological self-reliance," rather than intellectual property theft.

Six Chinese AI firms accused of aggressively copying US frontier models

This rhetoric follows a pattern established by the Chinese Embassy earlier in the year, which framed the US crackdown as a "smear campaign." Additionally, Chinese officials have countered that US firms frequently utilize Chinese models for their own research and development, suggesting that the flow of information is not as one-sided as the US government claims.

The timing of this advisory is notable, as it precedes a high-level meeting between President Donald Trump and Chinese President Xi Jinping scheduled for September 24. Observers suggest that the accusations may serve as a strategic bargaining chip, aimed at pressuring Beijing to agree to stricter global norms regarding the development and deployment of frontier AI systems.

Implications for the Global AI Ecosystem

The broader implication of this confrontation is a potential bifurcation of the global AI landscape. If US firms are forced to implement aggressive, gatekeeping security measures, it could lead to a more fragmented internet, characterized by increased identity verification requirements and restricted access to powerful models.

For the private sector, the challenge lies in balancing the "triple constraint" of security, accessibility, and economic growth. While the government stresses that the systemic theft of proprietary functionality causes "significant economic losses" and threatens the United States’ lead in the AI race, the implementation of these defensive measures may prove to be a significant logistical burden.

As the AI industry approaches the end of 2026, the mandate from the US government is clear: the era of open-access frontier models may be drawing to a close, replaced by a more defensive, security-conscious operational model. Whether this approach effectively curbs industrial-scale distillation—or merely creates a new, more difficult environment for legitimate global research—remains to be seen. The ultimate success of this strategy will depend on the willingness of major AI developers to collaborate closely with the intelligence community, and on the willingness of the global market to accept the inherent frictions of a more restricted, security-driven technological landscape.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
GIYH News
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.