openrouter:baidu/ernie-4.5-vl-424b-a47b · edited
· 0.43¢
·
🔍 input ↗
AI's Secret Recipe Heist: When Copying Goes Industrial
📃 Rewritten passage
The US government has accused China of systematically stealing American artificial intelligence technology through 'industrial-scale distillation'—a process where smaller AI models are trained on outputs from larger US systems like OpenAI's GPT. White House technology director Michael Kratsios alleges Chinese entities use tens of thousands of fake user accounts and hacking techniques ('jailbreaking') to scrape proprietary data, enabling them to replicate advanced AI at lower cost. This practice, he warns, exploits US innovation and poses national security risks because distilled models lack safety protocols that prevent misuse in bioweapons or cyberwarfare. US firms Anthropic and OpenAI have publicly accused Chinese rivals DeepSeek, Moonshot, and MiniMax of such attacks, arguing this undermines the US lead in AI—a lead maintained partly through export controls on advanced AI chips. The White House plans to share threat intelligence with US companies and push laws to blacklist violators. China denies the claims, calling them 'pure slander' and asserting its commitment to 'healthy competition.' But with US lawmakers advancing bills to restrict 'distillation' and tighten chip exports, this AI cold war threatens to escalate—potentially reshaping global tech dominance and safety standards.
Imagine stealing a master chef's secret recipe by scraping every dish they serve—then replicating it cheaper and faster. That's how US officials claim China is reverse-engineering America's cutting-edge AI.
📖 What's Going On?
The White House has accused China of 'industrial-scale theft' of American AI technology, alleging systematic campaigns to 'distil' US AI systems—using their outputs to train cheaper Chinese models. Michael Kratsios, director of the White House Office of Science and Technology Policy, warned this practice exploits US innovation and undermines national security.
Chinese companies like DeepSeek, Moonshot, and MiniMax are accused of using 'distillation attacks': training smaller AI models on outputs from larger US models (like OpenAI's GPT) to replicate capabilities at lower cost. The US claims China deploys tens of thousands of proxy accounts and 'jailbreaking' techniques to evade detection while scraping proprietary data.
🎯 How To Think About It
Think of this like academic plagiarism at a corporate scale—except the 'student' is a rival nation, and the 'paper' is a supercomputer's brain. Or compare it to counterfeit luxury goods: China allegedly produces 'knockoff' AI models that mimic US innovations without investing in the original research.
- Like a spy using a master key (jailbreaking) to steal blueprints from a locked lab
- Like a fast-follower brand reverse-engineering a patent-protected drug to sell a cheaper generic
💡 Key Things To Know
- Distillation attacks: Training smaller AI models on outputs from larger models (e.g., using GPT's answers to build DeepSeek's system)
- Proxy accounts: Tens of thousands of fake user accounts used to evade detection while scraping data
- US AI firms (Anthropic, OpenAI) and the White House allege this closes China's 'AI gap' created by US chip export controls
- Distilled models lack US safety safeguards—raising risks of bioweapon research or cyberattacks
- Most people miss: This isn't just corporate espionage—it's a geopolitical strategy to bypass US tech dominance
🌟 Why It Matters
If China can replicate advanced AI cheaply, it could dominate global markets—affecting your future job prospects in tech, cybersecurity, or research. US sanctions and export controls (like banning AI chip sales) might escalate, impacting consumer tech prices. Meanwhile, AI safety standards could fragment globally, creating risks even outside geopolitics.
🔮 The Bigger Picture
This AI arms race mirrors past tech battles (e.g., Cold War space race or semiconductor wars). If unchecked, China could achieve AI parity with the US, altering global power dynamics. Watch for new US laws targeting 'distillation'—like adding violators to export blacklists—and whether China retaliates with its own restrictions.
📖 Glossary (3)
- Distillation (AI) — A technique where a smaller, efficient AI model is trained using the outputs of a larger model—like a student learning from a teacher's answers. When done without permission, it's considered theft.
- Jailbreaking — Hacking an AI system to bypass its safety rules or access restricted data—similar to rooting a phone to remove manufacturer limits.
- Entity list — A US export blacklist banning American companies from selling technology to foreign groups deemed national security threats.
📝 Quiz (3) — with answers
Q. The passage primarily argues that China's alleged AI theft is:
A. A minor corporate dispute between US and Chinese firms
B. An industrial-scale strategy to bypass US tech dominance ✓
C. A result of weak US intellectual property laws
D. A temporary setback for Chinese AI development
Answer: B — The passage frames China's actions as systematic 'industrial-scale campaigns' to 'distil' US AI, explicitly linking it to geopolitical competition and national security (e.g., 'undermines American research'). Option A is wrong (Trap C: real-world understatement), C is unsupported (Trap B: misattribution), D contradicts the text (Trap A: opposite direction).
Q. As used in the passage, 'distil' most nearly means:
A. Purify
B. Condense
C. Replicate ✓
D. Steal
Answer: C — In context, 'distil' refers to training models on US AI outputs to replicate capabilities ('replicate' fits best). 'Steal' (D) is too vague—the passage specifies a method (distillation), not just theft. SAT Tip: Test each option in the sentence: 'foreign entities... are engaged in... replicating US frontier AI systems' works best.
Q. According to the passage, why are distilled models a national security risk?
A. They are more powerful than US models
B. They lack US safety safeguards ✓
C. They increase US-China diplomatic tensions
D. They violate international copyright law
Answer: B — The passage states distilled models 'lack the safeguards that... prevent the development of bioweapons or malicious cyber attacks.' Option A is false (they're cheaper, not more powerful), C is a consequence not a cause, D is implied but not the security risk cited. SAT Tip: Always prioritize explicit causes over implications.
💬 Suggested questions
- How do proxy accounts enable China's alleged AI theft without detection?
- What career risks might arise if AI safety standards fragment globally?
- Why might distilled models be 'significantly lower cost' than original AI systems?
openrouter:deepseek/deepseek-v4-pro · edited
· 0.62¢
·
🔍 input ↗
How China Is Using AI’s Own Tricks to Catch Up — and Why the U.S. Is Worried
📃 Rewritten passage
In April 2026, the White House drew a stark line in an escalating high-tech confrontation. Michael Kratsios, the director of the Office of Science and Technology Policy, fired off a memo accusing Chinese entities of running “industrial-scale” campaigns to extract the intelligence from America’s most advanced AI models. The technique at the center of the storm has a benign-sounding name: distillation. In ordinary AI development, a lab might use a larger, well-trained model as a teacher to train a smaller student model, producing a lightweight system that still performs impressively. But Kratsios warned that Chinese operatives were turning this tool into a weapon, using tens of thousands of proxy accounts and tricky “jailbreaking” methods to dodge detection and pump proprietary U.S. models for their hidden knowledge.
The accusation didn’t come out of nowhere. Earlier in 2025, the Chinese AI firm DeepSeek stunned observers with a model that seemed to punch far above its weight. OpenAI soon alleged that DeepSeek had likely fed outputs from its GPT models into its own training process — a direct violation of OpenAI’s terms of service. By February 2026, the U.S. lab Anthropic went further, naming DeepSeek and two other Chinese companies, Moonshot and MiniMax, and accusing them of distillation attacks on its own systems. These firms, security experts say, are not simply copying code; they are siphoning the behavioral blueprint of frontier AI, the kind of model that costs hundreds of millions of dollars to build.
Here’s the catch: the U.S. had already tried to slow China down by restricting the export of the advanced chips that power these models. But distillation offers a clever detour. A distilled model doesn’t need to be built from scratch on the same expensive hardware; it can learn by observing the online responses of a fully trained American model. The resulting Chinese system won’t perform quite at the level of the original — Kratsios acknowledged that — yet it can be produced at a dramatically lower cost, closing the competitive gap that export controls were meant to widen. That makes distillation a national security headache, not just a copyright problem.
The concerns go beyond who wins the next AI benchmark. U.S. companies warn that squeezed-out copies often arrive without the safety guardrails carefully embedded in the originals. A distilled model, stripped of the restrictions that block it from generating instructions for bioweapons or orchestrating a destructive cyberattack, could become an unlabeled hazard on the global stage. In response, the House Foreign Affairs Committee pushed forward bills that would allow the administration to place groups practicing unauthorized distillation onto the Commerce Department’s “entity list” — a blacklist that chokes off access to American technology. China’s embassy in Washington brushed off the whole affair as “pure slander,” insisting that Beijing respects intellectual property rights. Nevertheless, the emerging dynamic is unmistakable: the AI race has moved from a competition over hardware and talent into a shadowy struggle over the knowledge contained inside the models themselves.
Imagine training a rival sports team by secretly filming your opponent’s practices — that’s the AI espionage scandal now setting off alarms from Silicon Valley to the White House.
📖 What's Going On?
The White House has publicly accused Chinese entities of carrying out an “industrial-scale” campaign to steal intellectual property from American artificial intelligence labs. In an April 2026 memo, Michael Kratsios, director of the White House Office of Science and Technology Policy, warned that foreign actors, mainly based in China, are using a technique called distillation to copy the capabilities of frontier AI systems developed by U.S. companies like OpenAI and Anthropic.
Distillation is a legitimate method in AI development: a smaller “student” model learns by studying the outputs of a larger “teacher” model, capturing much of the same performance at a fraction of the cost. But Kratsios said Chinese groups are using “tens of thousands of proxy accounts to evade detection” and “jailbreaking techniques to expose proprietary information,” turning a useful training tool into what the U.S. calls a weaponized theft operation.
🎯 How To Think About It
The core mechanism here is not a simple hack — it’s a systematic exploitation of the way modern AI learns. Think of it as the difference between doing original research for a term paper versus collecting another student’s completed essays and paraphrasing them just enough to avoid plagiarism checkers. The second approach can produce a passing grade with far less effort, but it doesn’t build genuine understanding.
- In open-source software, one developer can legally “fork” another’s code to build a new project. AI distillation is similar in spirit, except that the original model’s weights remain secret and are protected by terms of service — so extracting the model’s knowledge through mass querying is more like reverse-engineering a locked product at scale.
- During the Cold War, the Soviet Union often obtained Western technology through espionage and then manufactured copies, like the Tu-4 bomber reverse-engineered from captured American B-29s. Those replicas closed a military gap but never fully matched the original. Here, distilled AI models also don’t match the full capability of the originals — but drastically cutting costs and development time makes them geopolitically dangerous.
💡 Key Things To Know
- The February 2025 revelation that China’s DeepSeek likely used outputs from OpenAI’s GPT models brought distillation into the spotlight; Anthropic later accused DeepSeek, Moonshot, and MiniMax — three major Chinese AI firms — of distillation attacks on its own models.
- Distillation works by feeding a large model’s answers into a small model so the small model learns to mimic its behavior. When done without authorization and at massive scale using automated queries, it can effectively copy a model’s core capabilities.
- Michael Kratsios is a Trump administration official leading the White House’s tech policy response. The Chinese embassy in Washington denied the claims, calling them “pure slander” and stating that China values intellectual property protection.
- A lesser-known concern is that distilled models often lack the safety guardrails of the originals — making it easier for them to be used for developing bioweapons or launching malicious cyber attacks, which raises the stakes beyond commercial competition.
- Most people assume AI theft means stealing lines of code or training data. The real target here is the model’s latent knowledge — the way it solves problems — which is extracted by bombarding it with carefully designed prompts, not by hacking into servers.
🌟 Why It Matters
This isn’t just a dispute between governments — it’s reshaping the career fields you might enter. The AI boom has created high-paying jobs in model training, safety research, and cybersecurity, but it also means future engineers and policy-makers will have to wrestle with intellectual property rules written for physical goods, not for knowledge that can be extracted through software. If you’re interested in computer science, international law, or national security, these are exactly the tensions you’ll navigate.
🔮 The Bigger Picture
The US-China AI rivalry is moving beyond chip export controls into the murkier territory of information warfare. Congress is already considering laws that would add companies using unauthorized distillation to an export blacklist, known as the “entity list,” which would choke off their access to American technology. The long-term effect could be a more fragmented internet, where AI models are regional weapons and cooperation erodes — and that would change how the entire world innovates.
📖 Glossary (6)
- Distillation (in AI) — A training method where a smaller “student” model learns from a larger “teacher” model’s outputs, capturing similar performance while using far less computing power. Authorized distillation is common; unauthorized distillation at scale becomes a form of IP theft.
- Frontier AI systems — The most advanced, cutting-edge AI models, often trained on enormous datasets with massive computational resources, and typically developed by well-funded labs like OpenAI or Anthropic.
- Jailbreaking (in AI) — Techniques used to bypass the safety restrictions or usage policies built into an AI model — for instance, tricking it into revealing prohibited information or behaving in unintended ways.
- Proxy accounts — Fake or intermediary user accounts that mask the real identity and location of the person making queries, often employed to circumvent rate limits or detection systems on online platforms.
- Entity list — A U.S. government blacklist maintained by the Commerce Department; companies on the list are subject to strict export restrictions, making it nearly impossible for American firms to sell them certain technologies without a license.
- Export controls — Laws and regulations that restrict the sale or transfer of certain goods, software, or technologies to other countries — in this context, advanced AI chips and the models trained on them.
📝 Quiz (10) — with answers
Q. According to the passage, what is the primary concern the White House raises about Chinese distillation campaigns?
A. They weaken the overall performance of U.S. AI models.
B. They exploit U.S. innovation at an industrial scale. ✓
C. They make it harder for U.S. companies to hire talent.
D. They cause a decline in the global stock market.
Answer: B — The passage directly states that the White House memo accused Chinese entities of “industrial-scale” campaigns to distil U.S. frontier AI systems and that Kratsios called unauthorized distillation that undermines U.S. R&D “unacceptable.” Option A is wrong because the passage notes that distilled models do not match the originals’ performance, meaning they don’t weaken the original models. SAT Tip: For main-idea questions, look for the phrase that the author repeats or emphasizes across paragraphs — here, “industrial-scale” is a key signal.
Q. Which choice best states the central idea of the passage?
A. Chinese AI companies are surpassing U.S. firms through legitimate competition.
B. The U.S. government is planning to ban all forms of AI model distillation.
C. A technique once considered a normal part of AI development is now at the center of a geopolitical clash over intellectual property theft. ✓
D. Export controls on computer chips have failed to slow China’s AI progress.
Answer: C — The passage frames distillation as a legitimate technique that has been weaponized, and it describes the U.S. accusations as an escalation in the AI arms race. Option D is a real-world claim that might be true but is not the central thesis of the passage. SAT Tip: When a question asks for the central idea, eliminate answers that focus on a single detail rather than the overall argument.
Q. According to the passage, what did Anthropic accuse DeepSeek, Moonshot, and MiniMax of doing?
A. Stealing hardware blueprints from U.S. chip manufacturers
B. Conducting distillation attacks on its AI models ✓
C. Hiring away its top engineers through higher salaries
D. Distributing false information about its safety record
Answer: B — The passage states, “In February, Anthropic accused three leading Chinese AI companies — DeepSeek, Moonshot and MiniMax — of distillation attacks on its models.” Option A is a distraction because export controls involve chips, but the accusation here is about distillation, not hardware theft. SAT Tip: On detail questions, scan the passage for the specific names or dates mentioned in the answer choices to locate the relevant line.
Q. As used in the passage, the word “frontier” most nearly means
A. geographical border
B. most advanced and novel ✓
C. military-related
D. publicly available
Answer: B — The passage refers to “frontier AI systems” as the ones being targeted by distillation. In this context, “frontier” describes the leading edge of AI development, not a physical border. Option A is the common meaning but would make no sense in the phrase “frontier AI.” SAT Tip: For vocabulary-in-context questions, substitute each option back into the sentence and see which one preserves the original meaning.
Q. As used in the passage, the word “distillation” most nearly means
A. a chemical purification process
B. a method of training a smaller model using a larger model’s outputs ✓
C. a legal agreement to share technology
D. a hacking technique that breaks into servers
Answer: B — The passage defines distillation as “the process of training smaller AI models based on the output of larger ones.” Option A is the scientific meaning but not the AI-specific usage here. SAT Tip: Even if you know a word’s common definition, check how it is used in the passage — technical terms often get a specialized meaning.
Q. The passage suggests that which of the following makes distilled AI models particularly concerning for national security?
A. They run on Chinese-manufactured chips that are incompatible with U.S. systems.
B. They often outperform the original U.S. models on safety benchmarks.
C. They may lack the safeguards that prevent dangerous applications like bioweapons development. ✓
D. They are impossible to detect using current cybersecurity methods.
Answer: C — The passage explicitly states that “distilled models pose national security risks because they lack the safeguards that, for example, prevent the development of bioweapons or malicious cyber attacks.” Option B contradicts the passage, which says distilled models do not match the original models’ performance. SAT Tip: Inference questions require finding a direct statement in the passage; do not bring in outside knowledge unless the passage clearly supports it.
Q. Which statement about U.S. export controls can most reasonably be inferred from the passage?
A. They have completely prevented China from accessing any AI technology.
B. They were designed primarily to restrict the export of distillation software.
C. They contribute to the incentive for China to use distillation as a workaround. ✓
D. They have been abandoned by the current administration.
Answer: C — The passage notes that distillation enables Chinese firms to “close the competitive advantage that the US enjoys because of export controls on advanced American chips,” implying that export controls push Chinese groups toward alternative methods like distillation. Option A is too absolute and contradicted by the article. SAT Tip: For inference questions, look for cause-and-effect chains in the passage — here, exports are restricted, so China seeks a different path.
Q. The author’s tone in the section “How To Think About It” is best described as
A. alarmed and sensationalist
B. analytical and explanatory ✓
C. neutral and indifferent
D. sarcastic and dismissive
Answer: B — That section uses comparisons to term papers and Cold War analogies to make the mechanism clear. The tone is educational, not panicked or mocking, so “analytical and explanatory” fits. Option A overstates the emotional charge. SAT Tip: To identify tone, pay attention to the author’s word choices and the purpose of the section — here, the goal is to clarify, not to provoke anxiety.
Q. Based on the passage, what could be a potential consequence of Congress adding groups that use unauthorized distillation to the “entity list”?
A. U.S. companies would be required to share all their AI models with the government.
B. Those groups would find it extremely difficult to purchase technology from U.S. firms. ✓
C. China would immediately stop all AI research.
D. The United Nations would impose global sanctions on AI distilleries.
Answer: B — The passage describes the entity list as “an export blacklist that would make it very hard for US companies to sell technology to the groups.” Option C is an extreme prediction not supported by the text. SAT Tip: On synthesis questions, check each prediction against what the passage says the policy actually does; avoid leaps not grounded in the text.
Q. Which choice provides the best evidence for the answer to the previous question?
A. “The US government has information indicating that foreign entities, principally based in China, are engaged in deliberate, industrial-scale campaigns”
B. “distillation was a vital part of the AI ecosystem when used legitimately to make lighter-weight models”
C. “One bill tackles distillation by requiring the administration to consider adding groups that employ it to the ‘entity list’ — an export blacklist that would make it very hard for US companies to sell technology to the groups.” ✓
D. “American AI companies are concerned that distilled models pose national security risks because they lack the safeguards”
Answer: C — The question was about the consequence of being added to the entity list, and option C directly explains that the list is an export blacklist that blocks technology sales, which matches the inference that groups on it would struggle to buy U.S. technology. Option A describes the campaign but not the list’s effect. SAT Tip: Evidence-pairing questions are most reliable when you find the exact sentence that supports your inference before looking at the options; then match it.
💬 Suggested questions
- Why does Chris McGuire want to ban Chinese access to U.S. models entirely?
- If distillation is a legitimate AI technique, how would the U.S. legally distinguish between authorized use and theft?
- What exactly happens when a “jailbreaking” prompt breaks an AI model’s safety rules?
anthropic:claude-haiku-4-5-20251001 · edited
· 2.57¢
·
🔍 input ↗
Why China's AI Shortcut Could Change Everything
📃 Rewritten passage
In April 2026, the White House escalated the technology tensions with China by formally accusing Chinese entities of systematically stealing American artificial intelligence research through an industrial-scale campaign. Michael Kratsios, director of the White House Office of Science and Technology Policy, detailed how foreign groups—primarily based in China—were extracting proprietary information from leading US AI labs like those run by Anthropic and OpenAI. The technique at the center of the accusation is distillation: training smaller, cheaper AI models based on the outputs of larger, more advanced ones. While distillation is a legitimate tool when companies use it on their own products to create lighter-weight versions, the White House alleges that Chinese firms are using it to reverse-engineer American models without permission, essentially copying the blueprint without paying the research costs.
The accusation focuses on three Chinese companies: DeepSeek, Moonshot, and MiniMax. According to US officials, these firms have deployed tens of thousands of fake proxy accounts and jailbreaking techniques to trick American AI systems into revealing proprietary information. Anthropic reported these attacks in February 2026, while OpenAI disclosed in early 2025 that DeepSeek had violated its terms of service by using GPT model outputs to train its own product. The timing matters: these revelations come just weeks before President Trump was scheduled to meet Xi Jinping in Beijing, suggesting the announcement carries both technical and diplomatic weight. China's embassy responded by denying the accusations as 'pure slander,' asserting that the country remains committed to intellectual property protection and fair competition.
Why would China pursue distillation? The answer lies in computing power. US export controls have severely restricted China's access to advanced computer chips—the expensive, cutting-edge processors needed to train powerful AI models from scratch. By distilling existing American models, Chinese companies can leapfrog years of research and billions in development costs, closing a technological gap without needing superior hardware. As Chris McGuire, a technology security expert at the Council on Foreign Relations, explained: Chinese AI firms are 'relying on distillation attacks to offset deficits in AI computing power and illicitly reproduce the core capabilities of US models.' The distilled models don't match the originals' performance, but they're far cheaper to produce and deploy—a significant competitive advantage in a race where speed and cost matter as much as raw capability.
The US government is preparing to strike back. Kratsios promised that the White House would share threat intelligence with American AI companies and help them coordinate defenses against distillation attacks. More importantly, Congress is moving on legislation that could add distilling companies to the 'entity list'—a blacklist of foreign actors banned from conducting business with US firms or accessing American technology. McGuire recommended even stricter measures: banning Chinese companies from accessing US models entirely and tightening export controls on advanced chips. For American AI companies, the stakes are national security. OpenAI and Anthropic have warned that distilled models, lacking the safety guardrails built into originals, could enable dangerous applications—from bioweapon development to sophisticated cyberattacks. The White House has tacitly endorsed this concern, acknowledging that while legitimate distillation is vital to the AI ecosystem, industrial-scale theft of American research for foreign military or strategic advantage is 'unacceptable' and demands an urgent response.
China is allegedly stealing America's AI blueprints and using them to build cheaper competing models—and the US just accused it of doing this at an 'industrial scale.'
📖 What's Going On?
On April 23, 2026, White House official Michael Kratsios released a memo accusing Chinese entities of systematically stealing intellectual property from American AI labs. The specific technique: distillation, which involves training smaller, cheaper AI models by learning from the outputs of larger, more powerful ones—essentially like a student memorizing an exam answer key to pass without understanding the material.
The accusation centers on companies like DeepSeek, Moonshot, and MiniMax, which Anthropic and OpenAI say have reverse-engineered their models without permission. According to Kratsios, Chinese groups are deploying 'tens of thousands of proxy accounts' and 'jailbreaking techniques' to extract proprietary information at scale. This matters because it allows China to bypass years of research and billions in computing costs.
The US is planning a crackdown: the White House says it will alert American AI companies to these attacks and explore penalties for foreign actors involved. Meanwhile, Congress is considering bills that could add distilling companies to an export blacklist, effectively cutting them off from US technology entirely.
🎯 How To Think About It
Distillation is legal and normal when used right—companies routinely make lighter, cheaper versions of their own models. But here's the catch: when one country systematically extracts another's proprietary models without permission, it becomes a form of technological espionage dressed up in legitimate-sounding language.
- Like a nuclear arms race, but with AI: both sides want the most advanced technology, but instead of building weapons, they're building smarter machines. The US has tried to stay ahead by restricting China's access to advanced computer chips; China is allegedly leapfrogging that restriction by copying the finished product.
- Or think of it like a sports doping scandal: distillation itself isn't cheating, but using someone else's distilled model is. The US is saying China is the athlete taking the banned substance; China is saying the US is just sour about losing its edge.
💡 Key Things To Know
- Distillation works because it's cheaper: distilled models don't match the original's performance, but they cost a fraction as much to build—a huge advantage if you're trying to catch up in an arms race.
- China has a computing power deficit: US export controls have limited China's access to the latest AI chips, so distillation is allegedly their way to close that gap without needing better hardware.
- Three Chinese companies named so far: DeepSeek, Moonshot, and MiniMax have been accused by Anthropic and OpenAI of these attacks since early 2025.
- National security is the unstated fear: distilled models lack safeguards that prevent misuse—like preventing bioweapon development or enabling cyberattacks. A weak AI is safer than a stolen strong one.
- The timing is weird: this memo drops just weeks before Trump meets Xi Jinping in Beijing, suggesting the accusation is partly diplomatic leverage or a warning shot.
🌟 Why It Matters
If China can effectively steal and distill American AI models, the entire logic of US tech dominance collapses. The US has bet on export controls to keep China behind; distillation suggests that won't work. For you, this shapes which country's tech ecosystem becomes the standard—and therefore which rules, laws, and business models define the AI tools you'll use in college and beyond. It also affects whether China or the US pulls ahead in AI-powered medicine, autonomous vehicles, and other breakthroughs that could reshape entire industries over your lifetime.
🔮 The Bigger Picture
This is the AI equivalent of Cold War espionage, but it's happening in real time and in the open. The US is trying to stop it with export controls, sanctions, and diplomatic pressure; China denies it's happening. The outcome will determine whether AI development stays concentrated in the West or becomes truly multipolar. If China succeeds, the geopolitical order flips. If the US's crackdown works, expect an even more tightly controlled AI industry, with limits on who can access which models—which might slow innovation for everyone, including you.
📖 Glossary (6)
- Distillation — A technique where a smaller, cheaper AI model is trained to mimic the outputs of a larger, more powerful model. Legitimate distillation is used by companies to make faster or less expensive versions of their own products; illicit distillation means copying someone else's model without permission.
- Export controls — Government restrictions on selling certain products or technologies to other countries—in this case, advanced computer chips needed for AI. The US has imposed export controls on chips that China needs to build powerful AI systems.
- Intellectual property (IP) — Intangible creations that a company or person owns and controls—like a patented invention, a software algorithm, or a trade secret. Stealing IP means using someone's creation without permission.
- Entity list — A US government blacklist of foreign companies and individuals banned from receiving most American technology and conducting business with US firms. Being added to the entity list is a severe economic penalty.
- Jailbreaking — Bypassing the built-in safety guidelines of an AI system to get it to do things its creators designed it not to do—in this context, getting a model to reveal proprietary information.
- Proxy accounts — Fake or secondary user accounts created to hide the identity or intentions of the real actor behind them—in this case, used to mask China's attempts to access and steal from US AI models.
📝 Quiz (10) — with answers
Q. The passage primarily argues that Chinese entities are
A. legally developing their own AI models through distillation research.
B. systematically stealing American AI technology using distillation techniques. ✓
C. collaborating with US companies to improve AI safety standards.
D. investing heavily in computer chips to avoid export restrictions.
Answer: B — Kratsios's memo explicitly accuses 'foreign entities, principally based in China' of 'deliberate, industrial-scale campaigns to distil US frontier AI systems.' Option A misses the word 'illegal'—distillation is legal when it's your own model. Option C contradicts the passage's tone of accusation. Option D is mentioned as a reason China might resort to distillation, but it's not the passage's central claim. On main-idea questions, the correct answer is always the one most directly supported by the opening thesis and repeated throughout.
Q. Which statement best captures the central idea of the passage?
A. Distillation is an unethical practice that should be banned worldwide.
B. China's computing power disadvantage makes AI development impossible.
C. The US alleges China is using illegal distillation to close a technological gap, prompting government action. ✓
D. American AI companies are solely responsible for protecting their own models.
Answer: C — The passage explains China's alleged motive (computing deficit), the method (distillation), and the US response (crackdown). Option A overstates—Kratsios says distillation is legitimate when used properly. Option B is too extreme; China is allegedly catching up, not blocked entirely. Option D ignores the White House's announced role in coordinating defenses. Central idea questions require you to find the one option that connects cause, method, and consequence.
Q. According to the passage, distilled models created through unauthorized means do NOT
A. cost significantly less money to produce.
B. match the performance of the original models. ✓
C. include the same safety safeguards as originals.
D. benefit foreign AI companies in terms of speed to market.
Answer: B — Kratsios states that distilled models 'did not match the performance of the original models,' but they benefit foreign groups because of 'significantly lower cost.' All other options are supported by the passage: distilled models are cheaper (A), lack safety measures (C from context), and help companies compete faster (D). When a question asks what the passage does NOT say, reread the exact claims made and pick the one that contradicts what's stated.
Q. As used in the passage, 'surreptitious' most nearly means
A. sophisticated
B. hidden or secret ✓
C. expensive
D. collaborative
Answer: B — Kratsios refers to 'surreptitious, unauthorised distillation campaigns,' where surreptitious describes campaigns conducted in secret without permission. Option A (sophisticated) might sound smart but misses the sneakiness implied by the parallel with 'unauthorised.' On vocab-in-context questions, reread the full sentence and note what nearby words add—'unauthorised' is the key clue. The right answer always fits the context, not just the dictionary definition of the word in isolation.
Q. The word 'leverage' in 'leveraging tens of thousands of proxy accounts' most nearly means
A. criticize
B. use strategically to gain advantage ✓
C. negotiate
D. expose
Answer: B — In context, Chinese groups are using proxy accounts as a tool to hide their identity and scale their theft. 'Leverage' here means to employ something strategically. Option A (criticize) and C (negotiate) don't fit the sentence's meaning. Option D (expose) is close but backwards—they're trying to avoid being exposed. When a word has multiple meanings, substitute each option back into the sentence; the right answer makes the sentence convey what the author intended.
Q. Which statement about American AI companies' concerns can most reasonably be inferred from the passage?
A. They believe distilled models pose a national security threat because they lack safety controls. ✓
B. They want the government to ban all forms of distillation, including legal ones.
C. They are unable to detect when their models are being distilled.
D. They have decided to stop exporting models to any foreign companies.
Answer: A — The passage explicitly states: 'American AI companies are concerned that distilled models pose national security risks because they lack the safeguards that, for example, prevent the development of bioweapons or malicious cyber attacks.' Option B overstates—the memo says legitimate distillation is 'vital' to the ecosystem. Option C contradicts the passage; companies have detected the attacks and reported them. Option D isn't mentioned. On inference questions, the right answer is always explicitly supported by the text, even if it's not a direct quote.
Q. The passage suggests that China is pursuing distillation primarily because
A. Chinese AI companies are more innovative than American ones.
B. it lacks access to advanced computer chips due to US export controls. ✓
C. it wants to prevent American companies from selling models globally.
D. American AI companies invited Chinese firms to participate in their research.
Answer: B — Chris McGuire states that Chinese firms are 'relying on distillation attacks to offset deficits in AI computing power'—implying China needs a workaround because it lacks the hardware. Option A contradicts the passage's framing (China is allegedly behind). Option C is not mentioned. Option D is false; the passage describes unauthorized theft, not invitation. Inference questions often contain a trap where a claim is true in the real world but not supported by THIS passage—be careful to use only what's on the page.
Q. The author's tone when describing Chinese denials is best described as
A. sympathetic to China's perspective
B. angry at China for lying
C. neutral, allowing both sides to speak ✓
D. dismissive of China's claims
Answer: C — The passage quotes the Chinese embassy's denial ('pure slander') and their statement about commitment to IP protection without editorial comment or adjectives. The author presents the US accusation and China's response without sarcasm or judgment—characteristic of news reporting that aims for balance. Option A overstates the tone. Option B adds emotion not present in the text. Option D is implied by juxtaposition but not explicitly conveyed. Tone questions require you to look at word choice and structure, not your inference about truth—a neutral topic discussed without loaded language = neutral tone.
Q. The passage implies that if US export controls on computer chips remain in place, China is likely to
A. stop developing AI technology altogether.
B. continue relying on distillation to compete with American models. ✓
C. demand that the US share its most advanced AI systems.
D. invest only in pharmaceutical and agricultural research instead.
Answer: B — McGuire explains that Chinese firms use distillation 'to offset deficits in AI computing power'—suggesting that without advanced chips, they'll keep using the shortcut. The passage never suggests China would give up (A), make demands (C), or pivot to other fields (D). These are inferences that require you to connect China's motive (lack of computing power) to their method (distillation). Read the passage for the causal chain and see which future scenario best extends that logic.
Q. Which choice provides the best evidence for the answer to the previous question?
A. 'China has always been committed to promoting scientific and technological progress through co-operation and healthy competition.'
B. 'Chinese AI firms are relying on distillation attacks to offset deficits in AI computing power and illicitly reproduce the core capabilities of US models.' ✓
C. 'The House Foreign Affairs Committee on Wednesday passed a slew of bills designed to make it harder for China to catch up with the US in the AI race.'
D. 'One bill tackles distillation by requiring the administration to consider adding groups that employ it to the entity list.'
Answer: B — Option B directly supports the inference that China uses distillation because of its computing deficit—'to offset deficits.' Option A is a Chinese denial with no causal claim. Option C describes US policy but doesn't explain China's future behavior. Option D is about enforcement, not motivation. On evidence-pairing questions, find the answer to the previous question first, then match it to the quote that most directly supports it—look for a quote that contains the same causal or logical claim, not just related words.
💬 Suggested questions
- If distillation is legal when companies use it on their own models, how does the US legally define what makes China's distillation 'illegal'?
- What would happen to the price of AI tools like ChatGPT if China successfully builds cheaper distilled versions and floods the global market?
- How exactly do proxy accounts and jailbreaking let Chinese firms steal from US AI models if those models already have access controls?