How China Is Using AI’s Own Tricks to Catch Up — and Why the U.S. Is Worried
openrouter:deepseek/deepseek-v4-pro · prompt: edited
· 2026-05-30T11:45:05 · 0.62¢
· 🔍 view original input ↗
📃 Rewritten passage
In April 2026, the White House drew a stark line in an escalating high-tech confrontation. Michael Kratsios, the director of the Office of Science and Technology Policy, fired off a memo accusing Chinese entities of running “industrial-scale” campaigns to extract the intelligence from America’s most advanced AI models. The technique at the center of the storm has a benign-sounding name: distillation. In ordinary AI development, a lab might use a larger, well-trained model as a teacher to train a smaller student model, producing a lightweight system that still performs impressively. But Kratsios warned that Chinese operatives were turning this tool into a weapon, using tens of thousands of proxy accounts and tricky “jailbreaking” methods to dodge detection and pump proprietary U.S. models for their hidden knowledge.
The accusation didn’t come out of nowhere. Earlier in 2025, the Chinese AI firm DeepSeek stunned observers with a model that seemed to punch far above its weight. OpenAI soon alleged that DeepSeek had likely fed outputs from its GPT models into its own training process — a direct violation of OpenAI’s terms of service. By February 2026, the U.S. lab Anthropic went further, naming DeepSeek and two other Chinese companies, Moonshot and MiniMax, and accusing them of distillation attacks on its own systems. These firms, security experts say, are not simply copying code; they are siphoning the behavioral blueprint of frontier AI, the kind of model that costs hundreds of millions of dollars to build.
Here’s the catch: the U.S. had already tried to slow China down by restricting the export of the advanced chips that power these models. But distillation offers a clever detour. A distilled model doesn’t need to be built from scratch on the same expensive hardware; it can learn by observing the online responses of a fully trained American model. The resulting Chinese system won’t perform quite at the level of the original — Kratsios acknowledged that — yet it can be produced at a dramatically lower cost, closing the competitive gap that export controls were meant to widen. That makes distillation a national security headache, not just a copyright problem.
The concerns go beyond who wins the next AI benchmark. U.S. companies warn that squeezed-out copies often arrive without the safety guardrails carefully embedded in the originals. A distilled model, stripped of the restrictions that block it from generating instructions for bioweapons or orchestrating a destructive cyberattack, could become an unlabeled hazard on the global stage. In response, the House Foreign Affairs Committee pushed forward bills that would allow the administration to place groups practicing unauthorized distillation onto the Commerce Department’s “entity list” — a blacklist that chokes off access to American technology. China’s embassy in Washington brushed off the whole affair as “pure slander,” insisting that Beijing respects intellectual property rights. Nevertheless, the emerging dynamic is unmistakable: the AI race has moved from a competition over hardware and talent into a shadowy struggle over the knowledge contained inside the models themselves.
Imagine training a rival sports team by secretly filming your opponent’s practices — that’s the AI espionage scandal now setting off alarms from Silicon Valley to the White House.
📖 What's Going On?
The White House has publicly accused Chinese entities of carrying out an “industrial-scale” campaign to steal intellectual property from American artificial intelligence labs. In an April 2026 memo, Michael Kratsios, director of the White House Office of Science and Technology Policy, warned that foreign actors, mainly based in China, are using a technique called distillation to copy the capabilities of frontier AI systems developed by U.S. companies like OpenAI and Anthropic.
Distillation is a legitimate method in AI development: a smaller “student” model learns by studying the outputs of a larger “teacher” model, capturing much of the same performance at a fraction of the cost. But Kratsios said Chinese groups are using “tens of thousands of proxy accounts to evade detection” and “jailbreaking techniques to expose proprietary information,” turning a useful training tool into what the U.S. calls a weaponized theft operation.
🎯 How To Think About It
The core mechanism here is not a simple hack — it’s a systematic exploitation of the way modern AI learns. Think of it as the difference between doing original research for a term paper versus collecting another student’s completed essays and paraphrasing them just enough to avoid plagiarism checkers. The second approach can produce a passing grade with far less effort, but it doesn’t build genuine understanding.
- In open-source software, one developer can legally “fork” another’s code to build a new project. AI distillation is similar in spirit, except that the original model’s weights remain secret and are protected by terms of service — so extracting the model’s knowledge through mass querying is more like reverse-engineering a locked product at scale.
- During the Cold War, the Soviet Union often obtained Western technology through espionage and then manufactured copies, like the Tu-4 bomber reverse-engineered from captured American B-29s. Those replicas closed a military gap but never fully matched the original. Here, distilled AI models also don’t match the full capability of the originals — but drastically cutting costs and development time makes them geopolitically dangerous.
💡 Key Things To Know
- The February 2025 revelation that China’s DeepSeek likely used outputs from OpenAI’s GPT models brought distillation into the spotlight; Anthropic later accused DeepSeek, Moonshot, and MiniMax — three major Chinese AI firms — of distillation attacks on its own models.
- Distillation works by feeding a large model’s answers into a small model so the small model learns to mimic its behavior. When done without authorization and at massive scale using automated queries, it can effectively copy a model’s core capabilities.
- Michael Kratsios is a Trump administration official leading the White House’s tech policy response. The Chinese embassy in Washington denied the claims, calling them “pure slander” and stating that China values intellectual property protection.
- A lesser-known concern is that distilled models often lack the safety guardrails of the originals — making it easier for them to be used for developing bioweapons or launching malicious cyber attacks, which raises the stakes beyond commercial competition.
- Most people assume AI theft means stealing lines of code or training data. The real target here is the model’s latent knowledge — the way it solves problems — which is extracted by bombarding it with carefully designed prompts, not by hacking into servers.
🌟 Why It Matters
This isn’t just a dispute between governments — it’s reshaping the career fields you might enter. The AI boom has created high-paying jobs in model training, safety research, and cybersecurity, but it also means future engineers and policy-makers will have to wrestle with intellectual property rules written for physical goods, not for knowledge that can be extracted through software. If you’re interested in computer science, international law, or national security, these are exactly the tensions you’ll navigate.
🔮 The Bigger Picture
The US-China AI rivalry is moving beyond chip export controls into the murkier territory of information warfare. Congress is already considering laws that would add companies using unauthorized distillation to an export blacklist, known as the “entity list,” which would choke off their access to American technology. The long-term effect could be a more fragmented internet, where AI models are regional weapons and cooperation erodes — and that would change how the entire world innovates.
📖 Glossary (6)
- Distillation (in AI) — A training method where a smaller “student” model learns from a larger “teacher” model’s outputs, capturing similar performance while using far less computing power. Authorized distillation is common; unauthorized distillation at scale becomes a form of IP theft.
- Frontier AI systems — The most advanced, cutting-edge AI models, often trained on enormous datasets with massive computational resources, and typically developed by well-funded labs like OpenAI or Anthropic.
- Jailbreaking (in AI) — Techniques used to bypass the safety restrictions or usage policies built into an AI model — for instance, tricking it into revealing prohibited information or behaving in unintended ways.
- Proxy accounts — Fake or intermediary user accounts that mask the real identity and location of the person making queries, often employed to circumvent rate limits or detection systems on online platforms.
- Entity list — A U.S. government blacklist maintained by the Commerce Department; companies on the list are subject to strict export restrictions, making it nearly impossible for American firms to sell them certain technologies without a license.
- Export controls — Laws and regulations that restrict the sale or transfer of certain goods, software, or technologies to other countries — in this context, advanced AI chips and the models trained on them.
📝 Quiz (10) — with answers
Q. According to the passage, what is the primary concern the White House raises about Chinese distillation campaigns?
A. They weaken the overall performance of U.S. AI models.
B. They exploit U.S. innovation at an industrial scale. ✓
C. They make it harder for U.S. companies to hire talent.
D. They cause a decline in the global stock market.
Answer: B — The passage directly states that the White House memo accused Chinese entities of “industrial-scale” campaigns to distil U.S. frontier AI systems and that Kratsios called unauthorized distillation that undermines U.S. R&D “unacceptable.” Option A is wrong because the passage notes that distilled models do not match the originals’ performance, meaning they don’t weaken the original models. SAT Tip: For main-idea questions, look for the phrase that the author repeats or emphasizes across paragraphs — here, “industrial-scale” is a key signal.
Q. Which choice best states the central idea of the passage?
A. Chinese AI companies are surpassing U.S. firms through legitimate competition.
B. The U.S. government is planning to ban all forms of AI model distillation.
C. A technique once considered a normal part of AI development is now at the center of a geopolitical clash over intellectual property theft. ✓
D. Export controls on computer chips have failed to slow China’s AI progress.
Answer: C — The passage frames distillation as a legitimate technique that has been weaponized, and it describes the U.S. accusations as an escalation in the AI arms race. Option D is a real-world claim that might be true but is not the central thesis of the passage. SAT Tip: When a question asks for the central idea, eliminate answers that focus on a single detail rather than the overall argument.
Q. According to the passage, what did Anthropic accuse DeepSeek, Moonshot, and MiniMax of doing?
A. Stealing hardware blueprints from U.S. chip manufacturers
B. Conducting distillation attacks on its AI models ✓
C. Hiring away its top engineers through higher salaries
D. Distributing false information about its safety record
Answer: B — The passage states, “In February, Anthropic accused three leading Chinese AI companies — DeepSeek, Moonshot and MiniMax — of distillation attacks on its models.” Option A is a distraction because export controls involve chips, but the accusation here is about distillation, not hardware theft. SAT Tip: On detail questions, scan the passage for the specific names or dates mentioned in the answer choices to locate the relevant line.
Q. As used in the passage, the word “frontier” most nearly means
A. geographical border
B. most advanced and novel ✓
C. military-related
D. publicly available
Answer: B — The passage refers to “frontier AI systems” as the ones being targeted by distillation. In this context, “frontier” describes the leading edge of AI development, not a physical border. Option A is the common meaning but would make no sense in the phrase “frontier AI.” SAT Tip: For vocabulary-in-context questions, substitute each option back into the sentence and see which one preserves the original meaning.
Q. As used in the passage, the word “distillation” most nearly means
A. a chemical purification process
B. a method of training a smaller model using a larger model’s outputs ✓
C. a legal agreement to share technology
D. a hacking technique that breaks into servers
Answer: B — The passage defines distillation as “the process of training smaller AI models based on the output of larger ones.” Option A is the scientific meaning but not the AI-specific usage here. SAT Tip: Even if you know a word’s common definition, check how it is used in the passage — technical terms often get a specialized meaning.
Q. The passage suggests that which of the following makes distilled AI models particularly concerning for national security?
A. They run on Chinese-manufactured chips that are incompatible with U.S. systems.
B. They often outperform the original U.S. models on safety benchmarks.
C. They may lack the safeguards that prevent dangerous applications like bioweapons development. ✓
D. They are impossible to detect using current cybersecurity methods.
Answer: C — The passage explicitly states that “distilled models pose national security risks because they lack the safeguards that, for example, prevent the development of bioweapons or malicious cyber attacks.” Option B contradicts the passage, which says distilled models do not match the original models’ performance. SAT Tip: Inference questions require finding a direct statement in the passage; do not bring in outside knowledge unless the passage clearly supports it.
Q. Which statement about U.S. export controls can most reasonably be inferred from the passage?
A. They have completely prevented China from accessing any AI technology.
B. They were designed primarily to restrict the export of distillation software.
C. They contribute to the incentive for China to use distillation as a workaround. ✓
D. They have been abandoned by the current administration.
Answer: C — The passage notes that distillation enables Chinese firms to “close the competitive advantage that the US enjoys because of export controls on advanced American chips,” implying that export controls push Chinese groups toward alternative methods like distillation. Option A is too absolute and contradicted by the article. SAT Tip: For inference questions, look for cause-and-effect chains in the passage — here, exports are restricted, so China seeks a different path.
Q. The author’s tone in the section “How To Think About It” is best described as
A. alarmed and sensationalist
B. analytical and explanatory ✓
C. neutral and indifferent
D. sarcastic and dismissive
Answer: B — That section uses comparisons to term papers and Cold War analogies to make the mechanism clear. The tone is educational, not panicked or mocking, so “analytical and explanatory” fits. Option A overstates the emotional charge. SAT Tip: To identify tone, pay attention to the author’s word choices and the purpose of the section — here, the goal is to clarify, not to provoke anxiety.
Q. Based on the passage, what could be a potential consequence of Congress adding groups that use unauthorized distillation to the “entity list”?
A. U.S. companies would be required to share all their AI models with the government.
B. Those groups would find it extremely difficult to purchase technology from U.S. firms. ✓
C. China would immediately stop all AI research.
D. The United Nations would impose global sanctions on AI distilleries.
Answer: B — The passage describes the entity list as “an export blacklist that would make it very hard for US companies to sell technology to the groups.” Option C is an extreme prediction not supported by the text. SAT Tip: On synthesis questions, check each prediction against what the passage says the policy actually does; avoid leaps not grounded in the text.
Q. Which choice provides the best evidence for the answer to the previous question?
A. “The US government has information indicating that foreign entities, principally based in China, are engaged in deliberate, industrial-scale campaigns”
B. “distillation was a vital part of the AI ecosystem when used legitimately to make lighter-weight models”
C. “One bill tackles distillation by requiring the administration to consider adding groups that employ it to the ‘entity list’ — an export blacklist that would make it very hard for US companies to sell technology to the groups.” ✓
D. “American AI companies are concerned that distilled models pose national security risks because they lack the safeguards”
Answer: C — The question was about the consequence of being added to the entity list, and option C directly explains that the list is an export blacklist that blocks technology sales, which matches the inference that groups on it would struggle to buy U.S. technology. Option A describes the campaign but not the list’s effect. SAT Tip: Evidence-pairing questions are most reliable when you find the exact sentence that supports your inference before looking at the options; then match it.
💬 Suggested questions
- Why does Chris McGuire want to ban Chinese access to U.S. models entirely?
- If distillation is a legitimate AI technique, how would the U.S. legally distinguish between authorized use and theft?
- What exactly happens when a “jailbreaking” prompt breaks an AI model’s safety rules?
Raw JSON