๐Ÿ”ฌ Model Lab

New run Stored runs โš–๏ธ Judge verdicts ๐Ÿงฎ Math ๐Ÿ“Š Math runs ๐Ÿ“„ Benchmark paper ๐Ÿ“„ 3-model paper ๐Ÿ“„ Meta: Will Muse Cause a Spark?

How to Steal an AI Without Stealing the Code

openrouter:z-ai/glm-5-turbo ยท prompt: edited ยท 2026-05-30T11:45:05 ยท 3.40ยข ยท ๐Ÿ” view original input โ†—

๐Ÿ“ƒ Rewritten passage

In April 2026, the White House publicly accused Chinese entities of conducting what it called 'industrial-scale' theft of American artificial intelligence technology. Michael Kratsios, director of the White House Office of Science and Technology Policy, detailed the allegations in a memo distributed to government departments. According to Kratsios, foreign actors โ€” principally based in China โ€” were running systematic campaigns to distil leading American AI systems, using tens of thousands of proxy accounts to evade detection and deploying jailbreaking techniques to extract proprietary information from those systems. Distillation, in the AI context, refers to the practice of training a smaller, cheaper model by feeding it the outputs of a larger, more capable one. The technique is not inherently illegitimate; AI developers routinely use it to create lighter-weight versions of their models that run on less powerful hardware. But Kratsios drew a sharp distinction between legitimate distillation and what he termed 'industrial distillation' โ€” the unauthorised, systematic extraction of another company's model outputs to replicate its capabilities at a fraction of the cost. He acknowledged that models produced through such campaigns did not match the performance of the originals, but argued that the dramatically lower cost still gave foreign groups a meaningful competitive benefit. The controversy gained prominence after DeepSeek, a Chinese AI company, was accused of using distillation to build a powerful product at significantly reduced expense. In early 2025, OpenAI claimed it had evidence that DeepSeek had used outputs from its GPT models to train its own system, in violation of OpenAI's terms of service. By February 2026, Anthropic had levelled similar accusations against three leading Chinese AI companies: DeepSeek, Moonshot, and MiniMax. American firms argued that distillation attacks allowed foreign laboratories to close the competitive gap that the United States enjoyed partly because of export controls on advanced American chips โ€” controls designed to limit China's access to the computing power needed to train frontier AI models from scratch. Chris McGuire, a technology security expert at the Council on Foreign Relations, argued that Chinese AI firms were relying on distillation specifically to offset their deficits in computing power and 'illicitly reproduce the core capabilities of US models.' He recommended that the United States ban Chinese groups from accessing American models entirely, sanction entities involved in or enabling distillation, and tighten export controls to prevent China from obtaining US AI chips through smuggling or remote access. Beyond commercial competition, American AI companies raised national security concerns. They argued that distilled models tended to lack the safety safeguards that developers build into their frontier systems โ€” guardrails designed, for example, to prevent the generation of instructions for building biological weapons or conducting malicious cyberattacks. The Chinese embassy in Washington dismissed the White House accusations as 'pure slander,' with spokesperson Liu Pengyu stating that China was committed to scientific progress through 'cooperation and healthy competition' and that it 'attaches great importance to the protection of intellectual property rights.' The political response moved quickly. In late April 2026, the House Foreign Affairs Committee passed a package of bills intended to impede China's progress in AI. One bill specifically targeted distillation by requiring the administration to consider adding groups that employ the practice to the 'entity list' โ€” a US export blacklist that would severely restrict those groups' ability to purchase American technology. The escalation came just weeks before President Donald Trump was scheduled to meet President Xi Jinping in Beijing, underscoring how AI competition had become a central friction point in the broader US-China relationship.

Imagine acing a test not by studying, but by feeding thousands of bots the answer key from the kid who actually did the work. That's essentially what the US says China is doing to American AI.

๐Ÿ“– What's Going On?

In April 2026, the White House accused Chinese entities of running 'industrial-scale' campaigns to distil American AI systems โ€” essentially training cheaper Chinese models by mass-harvesting outputs from US frontier models like those built by OpenAI and Anthropic.

Michael Kratsios, the White House's top science advisor, said Chinese actors used tens of thousands of proxy accounts and jailbreaking techniques to extract proprietary information. The Chinese embassy called the accusations 'pure slander.'

๐ŸŽฏ How To Think About It

Distillation itself is a normal, legitimate AI technique โ€” like a professor writing a concise study guide from a 1,000-page textbook. The problem is when someone else writes that guide using your textbook without permission, at scale, and sells it as their own product.

๐Ÿ’ก Key Things To Know

๐ŸŒŸ Why It Matters

If you're planning to study computer science, AI ethics, or international relations, this is the fault line you'll be working on. The US strategy has been to stay ahead by controlling the hardware (chips). Distillation threatens to make that strategy obsolete โ€” because you don't need the chips if you can borrow the brain. The House Foreign Affairs Committee is already pushing bills to add distillation-using groups to the entity list, which would effectively cut them off from US tech. This could reshape which companies you'll be able to work for, what tools you'll have access to, and whether the AI models you use come with safety guardrails or not.

๐Ÿ”ฎ The Bigger Picture

This escalation lands weeks before a Trump-Xi summit in Beijing, signalling that AI has joined tariffs and Taiwan as a core US-China bargaining chip. The counterintuitive part is that cracking down on distillation could accelerate China's push to build fully independent AI infrastructure โ€” meaning short-term pain for Chinese labs but potentially a more formidable long-term rival. Watch for whether the entity-list bill becomes law, and whether US AI companies start aggressively locking down their model interfaces in response.

๐Ÿ“– Glossary (5)

๐Ÿ“ Quiz (10) โ€” with answers

Q. Which choice best states the central idea of the passage?
A. Chinese AI companies have developed superior models through legitimate research and cooperation.
B. The US government is confronting what it describes as systematic Chinese theft of AI capabilities through distillation. โœ“
C. Export controls on American chips have completely failed to limit China's progress in artificial intelligence.
D. DeepSeek is the only Chinese company accused of unauthorised access to American AI model outputs.
Answer: B โ€” The passage centers on the White House's allegations of industrial-scale distillation by Chinese entities and the policy responses. Option C is a real-world debate point but the passage never says controls 'completely failed' โ€” that's too absolute and unsupported (Trap C: true-sounding claim not in the passage). Option D is factually wrong per the passage, which names three companies (Trap B: uses passage vocabulary in a wrong combination).
Q. According to the passage, Chinese AI firms are relying on distillation because they
A. lack sufficient computing power to train frontier models independently from scratch โœ“
B. have been explicitly authorised by American companies to access their model outputs
C. possess more advanced semiconductor chips than their American competitors do
D. are attempting to share their own model outputs freely with American laboratories
Answer: A โ€” The passage states that Chinese firms use distillation 'to offset their deficits in computing power.' Option B is the opposite of what the passage describes โ€” the access is unauthorised (Trap A: right scope, wrong direction). Option C reverses the actual chip advantage (Trap A). Option D inverts the flow of information (Trap B: vocabulary from the passage rearranged into a false claim).
Q. According to the passage, the House Foreign Affairs Committee bill targeting distillation would
A. immediately ban all Chinese technology companies from operating inside the United States
B. require the administration to consider placing groups that use distillation on an export blacklist โœ“
C. eliminate all existing export controls on advanced American semiconductor chips
D. force American AI companies to share their model outputs with Chinese competitors
Answer: B โ€” The passage says the bill would require the administration to consider adding groups that employ distillation to the 'entity list,' which is an export blacklist. Option A sounds plausible as a policy response but the passage never describes such a ban (Trap C: real-world-sounding claim unsupported by the text). Option C is the opposite of what's described (Trap A). Option D inverts the passage's concern (Trap B).
Q. As used in the passage, the word 'sharp' most nearly means
A. piercing or physically cutting
B. intellectually keen or quick-witted
C. clear and distinct โœ“
D. harsh or severe in tone
Answer: C โ€” The phrase 'drew a sharp distinction' means a clear, well-defined distinction โ€” a standard English collocation. Option A is the most common literal meaning of 'sharp,' which is exactly the trap on vocab-in-context questions (Trap: common meaning substituted for passage meaning). Option D might tempt readers who associate 'sharp' with 'sharp criticism,' but 'sharp distinction' doesn't imply harshness. SAT Tip: on vocab-in-context, always reread the full phrase and substitute each option โ€” 'drew a clear distinction' preserves the sentence's meaning perfectly.
Q. As used in the passage, the word 'frontier' most nearly means
A. a political border between two nations
B. at the outer edge of what is currently possible or developed โœ“
C. a military defensive line or fortification
D. an earlier or outdated version of a technology
Answer: B โ€” The passage uses 'frontier AI systems' and 'frontier models' to mean the most advanced, cutting-edge AI โ€” at the boundary of what's been achieved. Option A is the most common meaning of 'frontier' and is the primary trap (common meaning vs. passage meaning). Option C is another familiar definition. Option D is the opposite of what the passage conveys. SAT Tip: when a common word appears in an unusual phrase like 'frontier AI,' the correct answer is almost never the word's most common definition.
Q. Which statement about the relationship between export controls and distillation can most reasonably be inferred from the passage?
A. Export controls have made distillation entirely unnecessary for Chinese AI development.
B. Export controls on chips may have incentivised Chinese firms to turn to distillation as an alternative path. โœ“
C. Export controls were originally designed specifically to prevent distillation attacks on AI models.
D. Export controls have had no measurable effect on Chinese AI capabilities of any kind.
Answer: B โ€” The passage says distillation allows Chinese firms to 'close the competitive gap that the United States enjoyed partly because of export controls on advanced American chips' โ€” implying the controls created a gap that distillation is now being used to close. Option A states the opposite relationship (Trap A: right scope, wrong direction). Option C misattributes the design purpose of export controls, which target chips, not distillation (Trap B: passage vocabulary in wrong combination). Option D is too absolute and contradicts the passage's implication that controls did create an advantage (Trap C). SAT Tip: on inference questions, be wary of options with absolute words like 'entirely,' 'specifically,' or 'no measurable effect' โ€” the passage rarely supports such certainty.
Q. The passage suggests that the national security concerns raised by American AI companies are based primarily on the idea that
A. distilled models could be used to develop weapons or conduct cyberattacks without standard safety guardrails โœ“
B. Chinese companies will sell distilled models directly to American consumers and government agencies
C. distillation will cause American AI models to become less accurate and reliable over time
D. the entity list is too weak a tool to adequately protect American intellectual property
Answer: A โ€” The passage states that American firms worry distilled models 'lack the safety safeguards that developers build into their frontier systems โ€” guardrails designed, for example, to prevent the generation of instructions for building biological weapons.' Option B sounds like a plausible security concern but the passage never mentions selling to Americans (Trap C: true-sounding real-world claim unsupported by the passage). Option C describes a different technical concern not raised in the passage (Trap C). Option D is a policy debate the passage doesn't connect to the specific national security argument about safeguards (Trap C). SAT Tip: when a question asks what a passage 'suggests,' the answer must be directly traceable to specific lines โ€” not a logical leap you're making from outside knowledge.
Q. The author's primary purpose is to
A. persuade readers that Chinese AI companies should be allowed to compete freely with American firms
B. explain the allegations, context, and policy responses surrounding US claims of Chinese AI distillation โœ“
C. defend the Chinese embassy's characterization of the White House accusations as slander
D. provide a technical tutorial on how distillation functions in AI model development
Answer: B โ€” The passage walks through who made the allegations, what distillation is, which companies were accused, what experts recommend, and what legislative action followed โ€” a classic explanatory structure. Option A advocates the opposite of what the passage's framing suggests (Trap A: right scope, wrong direction). Option C takes the Chinese embassy's position, which the passage merely reports without endorsing (Trap B: passage vocabulary used to imply the author's stance). Option D overstates the technical depth โ€” the passage explains distillation in a sentence, not as a tutorial (Trap B). SAT Tip: on purpose questions, distinguish between what the passage 'reports' and what the author 'believes' โ€” neutral reporting of multiple sides usually points to an explanatory purpose.
Q. The passage most strongly implies that the timing of the White House memo โ€” just weeks before a Trump-Xi meeting โ€” suggests that
A. the two leaders have already reached a private agreement to resolve AI competition disputes
B. AI competition has become a significant point of leverage in broader US-China diplomatic negotiations โœ“
C. the House Foreign Affairs Committee deliberately delayed its bills to coincide with the summit
D. President Xi Jinping personally directed the distillation campaigns described in the memo
Answer: B โ€” The passage's final sentence states the escalation 'underscor[es] how AI competition had become a central friction point in the broader US-China relationship' โ€” directly supporting the idea that AI is now leverage in diplomacy. Option A contradicts the passage's depiction of escalating tension (Trap A: wrong direction). Option C might be a reasonable real-world speculation but the passage never says the committee deliberately timed anything (Trap C: unsupported inference). Option D attributes personal direction to Xi with zero textual evidence (Trap C). SAT Tip: on 'most strongly implies' questions, the correct answer is usually the most modest, most directly supported claim โ€” not the most dramatic speculation.
Q. Which choice provides the BEST evidence for the answer to the previous question?
A. Michael Kratsios, director of the White House Office of Science and Technology Policy, detailed the allegations in a memo distributed to government departments.
B. The escalation came just weeks before President Donald Trump was scheduled to meet President Xi Jinping in Beijing, underscoring how AI competition had become a central friction point in the broader US-China relationship. โœ“
C. The Chinese embassy in Washington dismissed the White House accusations as 'pure slander,' with spokesperson Liu Pengyu stating that China was committed to scientific progress.
D. In early 2025, OpenAI claimed it had evidence that DeepSeek had used outputs from its GPT models to train its own system.
Answer: B โ€” Option B directly connects the summit timing to the idea that AI is a 'central friction point in the broader US-China relationship,' which is the exact inference in question 9. Option A identifies who wrote the memo but says nothing about diplomatic timing (Trap B: relevant vocabulary, wrong relevance). Option C covers China's denial but not the summit timing (Trap B). Option D describes a specific earlier accusation unrelated to the diplomatic scheduling point (Trap B). SAT Tip: on evidence-pairing questions, find the line that supports your previous answer FIRST, then match it word-for-word to an option โ€” don't re-analyze the question from scratch.

๐Ÿ’ฌ Suggested questions

Raw JSON