Three US agencies have named six Chinese AI firms in a joint advisory that accuses them of industrial-scale distillation of American models since late 2024. The document, filed as AA26-251A and published Tuesday, targets the Claude, GPT, Gemini and Grok families, according to the advisory. The agencies say the campaigns were likely known to the Chinese government and describe the extracted capabilities as the core of China's AI strategy.
The advisory puts the alleged payoff in stark terms: billions of dollars in training costs and years of engineering effort saved. It also takes aim at a figure that has circulated widely, disputing DeepSeek's claim that it trained a model for $5.6 million on the grounds that the number leaves out the cost of data the advisory says was distilled. The advisory presents the agencies' account rather than a court finding.
The mechanics described in the advisory are specific. Operators bought fake accounts in bulk and routed their traffic through proxies to get around geographic restrictions. The queries were coordinated, running from the thousands into the millions per topic. Prompt-injection jailbreaks were used to pull out hidden chain-of-thought reasoning, and DeepSeek prompts asked models to reconstruct their internal reasoning step by step, the advisory says.
DeepSeek's targets, according to the document, included agentic functions, writing optimization and reasoning. OpenAI publicly flagged DeepSeek's conduct last year, and Google reported over 100,000 prompts sent to Gemini in what looked like a cloning attempt. Anthropic has made its own accusation against Alibaba over a Claude-cloning effort it says was bigger than any it had logged before. China's foreign ministry dismissed the accusations as groundless and credited the country's progress to self-reliance in science and technology.
Rather than pushing for outright blocking, the advisory recommends quietly degrading responses for accounts identified as malicious. That approach is framed as preferable to a hard cutoff, and the detection strategy assumes the campaigns will continue even after the disclosure.
The advisory follows earlier warnings about distillation from OpenAI, Google and Anthropic, each of which raised the issue before the agencies consolidated the allegations into a single filing. The six named firms are Alibaba, DeepSeek, MiniMax, Moonshot AI, StepFun and Z.AI, and the advisory ties specific conduct to Moonshot as well as DeepSeek.













