China’s ‘Industrial-Scale’ AI Theft: The Distillation Hack Fueling the US-China AI Arms Race
openrouter:stepfun/step-3.7-flash · prompt: edited
· 2026-05-30T12:19:16 · 2.09¢
· 🔍 view original input ↗
📃 Rewritten passage
On April 23, 2026, the White House dropped a bombshell accusation against China: state-linked groups are running coordinated, large-scale campaigns to steal American artificial intelligence intellectual property. The alleged theft doesn’t involve breaking into lab servers or stealing proprietary code — instead, attackers are exploiting the open, query-based nature of public AI tools to copy their core functionality for a fraction of the development cost.
The technique in question is called distillation. In legitimate use, distillation lets developers train small, lightweight AI models to mimic the behavior of larger, more powerful “teacher” models, making AI tools cheaper and more accessible for everyday users. But according to a memo published by White House AI policy director Michael Kratsios, Chinese actors are using distillation at an industrial scale to steal US AI secrets: by routing tens of thousands of queries through proxy accounts to avoid detection, and using “jailbreaking” techniques to bypass AI safety guardrails, they collect thousands of outputs from leading US models like those built by OpenAI and Anthropic. They then use those outputs to train their own competing models, no access to the original models’ proprietary training data or code required.
The accusation is the latest escalation in a years-long US-China AI arms race, and it comes just weeks before a scheduled summit between US President Donald Trump and Chinese President Xi Jinping in Beijing. US AI firms have raised alarms about distillation for months: in early 2025, OpenAI accused Chinese firm DeepSeek of violating its terms of service by using GPT model outputs to train its own competing system, and in February 2026, Anthropic named DeepSeek, Moonshot, and MiniMax as perpetrators of distillation attacks on its models. These firms argue that distillation lets Chinese competitors close the gap created by strict US export controls on advanced AI chips, which give US firms a major head start in building cutting-edge AI systems. There’s also a national security angle: distilled models often lack the safety guardrails built into original US models, making them easier to use for harmful purposes like developing bioweapons or malicious cyber tools.
Kratsios’ memo outlines a two-pronged US response: first, the government will share threat intelligence with US AI firms to help them identify and block distillation attempts, and second, it will explore sanctions for actors involved in the practice. The House Foreign Affairs Committee has already passed a slate of bills aimed at cracking down on distillation, including a measure that would add groups using the technique to the US “entity list” — a blacklist that bars listed groups from buying US technology or doing business with American firms. The Chinese embassy has dismissed the accusations as “pure slander”, noting China’s commitment to intellectual property protection and scientific cooperation.
The dispute highlights a fundamental tension in the global AI ecosystem: the same open, accessible design that makes public AI tools useful for legitimate users also makes them vulnerable to exploitation. If the US successfully cracks down on distillation, it could preserve US dominance in the global AI market, shaping the tools, jobs, and regulatory standards that will define the next decade of tech. If China finds ways to bypass the restrictions, it could lead to a fragmented global AI landscape, with separate US and Chinese ecosystems built to different safety and regulatory standards — a split that will shape how the next generation of users around the world interacts with AI.
The US government just accused China of running a massive, coordinated campaign to steal American AI secrets — not by hacking servers, but by tricking public AI models into giving up their ‘answer keys’.
📖 What's Going On?
On April 23, 2026, White House AI policy director Michael Kratsios published a memo formally accusing Chinese state-linked groups of running ‘industrial-scale’ campaigns to steal US artificial intelligence intellectual property. The alleged theft uses a technique called distillation, where attackers query public US AI models thousands of times to train their own cheaper, competing models without permission. Kratsios warned the US government would share threat intelligence with US AI firms and explore sanctions against actors involved in the practice.
The accusation comes weeks before a scheduled summit between US President Donald Trump and Chinese President Xi Jinping in Beijing, and follows public allegations from US AI firms Anthropic and OpenAI that Chinese competitors DeepSeek, Moonshot, and MiniMax used distillation to copy their models. Chinese embassy spokesperson Liu Pengyu dismissed the claims as ‘pure slander’, noting China’s commitment to intellectual property protection and scientific cooperation.
🎯 How To Think About It
The core tension here isn’t about breaking into a lab to steal a prototype — it’s about exploiting the open, query-based nature of public AI tools to copy their core functionality at a fraction of the cost. To grasp how this works, and why it’s so hard to stop, compare it to two familiar scenarios:
- A high school student who can’t afford a $300 private SAT tutor instead sits next to the class valedictorian during every practice test, writes down every answer the valedictorian marks, and builds their own $25 study guide from those answers — they never steal the valedictorian’s actual notes or pay for the tutor’s time.
- A fast-food chain that can’t afford to develop its own signature burger recipe sends 200 employees to the competing popular burger joint every week, records every ingredient, cooking time, and plating step, and trains its own $30k kitchen staff to replicate the burger exactly — no need to steal the competitor’s secret recipe documents or hire their head chef.
💡 Key Things To Know
- The US memo specifically names three Chinese AI firms — DeepSeek, Moonshot, and MiniMax — as perpetrators of distillation attacks on US models, with DeepSeek first accused of violating OpenAI’s terms of service in early 2025.
- Distillation works by feeding thousands of queries to a large, proprietary ‘teacher’ AI model, collecting its outputs, and using those outputs to train a smaller, cheaper ‘student’ model that replicates the teacher’s capabilities at a fraction of the development cost.
- Key US stakeholders in the dispute include the White House Office of Science and Technology Policy, AI firms Anthropic and OpenAI, and the House Foreign Affairs Committee, which passed multiple bills in April 2026 to crack down on distillation.
- A non-obvious national security risk of distilled models is that they often lack the safety guardrails built into original US models, making them easier to use for developing bioweapons or malicious cyber tools.
- Most people assume stealing AI technology requires hacking into company servers or stealing code, but distillation exploits the open, query-based access most public AI tools offer to users, no breach required.
🌟 Why It Matters
This isn’t just abstract geopolitical squabbling — it’s shaping the AI tools you’ll use in college, the jobs that will exist when you graduate, and the global tech landscape you’ll navigate as an adult. If export controls and anti-distillation rules slow China’s AI progress, US AI firms will dominate the global market, meaning the AI tools you learn to use (and the companies you might work for) will likely be American-made. If distillation lets China close the gap fast, you could see a far more fragmented global AI ecosystem, with different countries using different, potentially less safe, AI tools built to different regulatory standards.
🔮 The Bigger Picture
This dispute is the latest escalation in a decades-long pattern of US-China tech competition that mirrors the Cold War’s space and nuclear arms races, with AI framed as the defining strategic technology of the 21st century. The upcoming Trump-Xi summit will likely put AI theft and export controls at the top of the agenda, and second-order effects to watch include tighter global AI regulation, more US tech export restrictions, and a potential split of the global internet into separate US and Chinese AI ecosystems with no interoperability.
📖 Glossary (5)
- Distillation — A machine learning technique where a smaller, more efficient ‘student’ AI model is trained to replicate the behavior of a larger, more powerful ‘teacher’ model, using the teacher’s outputs as training data. When used without permission to copy proprietary models, it is considered intellectual property theft.
- Intellectual property (IP) — Legal rights granted to creators over their original inventions, creative works, and proprietary processes, including patents, copyrights, and trade secrets. Stealing IP means using someone else’s protected work without permission or compensation.
- Export controls — Government-imposed restrictions on the sale or transfer of specific goods, technology, or services to foreign countries or entities, usually for national security or foreign policy reasons. The US has strict export controls on advanced AI chips to China.
- Entity list — A US government blacklist of foreign individuals, companies, or organizations that are restricted from accessing US technology or doing business with US firms, usually due to national security concerns. Being added to the list makes it nearly impossible for a group to buy US AI chips or software.
- Jailbreaking (AI) — The practice of manipulating an AI model’s input prompts to bypass its built-in safety guardrails and access restricted functionality or proprietary information. The article notes Chinese actors use jailbreaking to extract sensitive data from US AI models.
📝 Quiz (10) — with answers
Q. According to the passage, what is the primary method Chinese actors are accused of using to steal US AI intellectual property?
A. Hacking into US AI lab servers to steal proprietary code
B. Using distillation to train competing models from US AI outputs ✓
C. Smuggling banned US AI chips out of the country
D. Recruiting US AI researchers to share proprietary information
Answer: B — The passage explicitly states Chinese groups are accused of using distillation, the process of training smaller models on larger US models’ outputs, to steal IP. The most tempting wrong answer is A, which is a common real-world tech theft method but is never mentioned as the tactic in question in the passage (Trap C: true real-world claim but unsupported by the passage). SAT Tip: For detail questions, eliminate options that describe related real-world issues but are not cited in the passage as the specific focus of the author’s argument.
Q. Which of the following best describes the US government’s stated response to the alleged Chinese distillation campaigns?
A. Immediately banning all Chinese access to US AI models
B. Sharing threat intelligence with US AI firms and exploring sanctions ✓
C. Filing a formal lawsuit against the three named Chinese AI firms
D. Imposing a total embargo on all technology exports to China
Answer: B — Kratsios’ memo states the administration will share information with US AI companies about distillation attempts and explore measures to hold foreign actors accountable. The most tempting wrong answer is A, which describes a more extreme action than the planned, exploratory response outlined in the passage (Trap A: right scope, wrong direction). SAT Tip: When a question asks about a group’s planned or stated response, look for language like “will,” “plans to,” or “exploring” rather than language describing actions that have already been completed.
Q. According to the passage, what is the primary national security risk posed by distilled Chinese AI models?
A. They are cheaper for Chinese firms to build than US models
B. They lack safety guardrails against bioweapon or cyber misuse ✓
C. They outperform the original US models they copy
D. They give China direct access to US military AI systems
Answer: B — The passage explicitly states distilled models are a national security risk because they lack the safeguards in US models that block harmful use cases like bioweapon development. The most tempting wrong answer is A, which mentions a real detail from the passage (lower cost) but is not cited as the security risk (Trap B: uses passage vocabulary but in a wrong combination). SAT Tip: When a question asks for a specific reason (like a risk or cause), make sure the answer directly matches the cause stated in the passage, not a related but irrelevant detail.
Q. As used in the passage, the word ‘distillation’ most nearly means ___.
A. The process of separating liquid mixtures by boiling point
B. Training a smaller AI model using outputs from a larger proprietary model ✓
C. The process of hacking into a server to steal proprietary code
D. Exporting restricted technology to foreign countries without a license
Answer: B — The passage defines distillation in the AI context as training smaller models based on the output of larger ones. The most tempting wrong answer is A, which is the common scientific definition of distillation but is unrelated to the AI usage in the passage (Trap C: true real-world claim but unsupported by the passage context). SAT Tip: For vocab-in-context questions, substitute each option into the original sentence first — the correct answer will make the sentence match the passage’s overall meaning, while the common definition will often feel out of place in the specific context.
Q. As used in the passage, the word ‘surreptitious’ most nearly means ___.
A. Open and publicly acknowledged
B. Done secretly or without official permission ✓
C. Approved by the original model’s creators
D. Conducted for non-commercial research purposes
Answer: B — The passage uses ‘surreptitious’ to describe distillation campaigns that are unauthorized and hidden from US AI firms. The most tempting wrong answer is A, which is the direct opposite of the word’s meaning in context (Trap A: right scope, wrong direction). SAT Tip: When you encounter an unfamiliar word in a vocab-in-context question, look for context clues in the surrounding sentences — here, the phrase “unauthorized, industrial-scale distillation” directly signals the secret, unapproved nature of the action.
Q. Which statement about US-China AI relations can most reasonably be inferred from the passage?
A. The two countries have fully agreed to global AI safety standards
B. US export controls on AI chips have given US firms a competitive advantage ✓
C. China has stopped all distillation attacks on US AI models
D. The US and China plan to merge their AI research efforts by 2027
Answer: B — The passage states US AI firms argue distillation lets Chinese groups close the competitive advantage the US enjoys because of export controls on advanced chips, implying the controls do give the US an edge. The most tempting wrong answer is C, which describes a resolved situation that the passage does not support (Trap C: true real-world claim but unsupported by the passage). SAT Tip: For inference questions, eliminate options that make absolute claims (“all,” “never,” “stopped completely”) unless the passage explicitly states them — most real-world disputes are ongoing, not resolved.
Q. The passage suggests that the upcoming Trump-Xi summit will likely ___.
A. Result in a total end to all US-China tech competition
B. Address AI theft and export controls as key agenda items ✓
C. Lead to the US lifting all export controls on AI chips
D. Focus exclusively on trade disputes unrelated to technology
Answer: B — The passage notes the accusation comes weeks before the summit, and AI theft is the core subject of the memo, implying it will be a top agenda item. The most tempting wrong answer is A, which describes a positive outcome that contradicts the passage’s framing of the accusation as an escalation in tensions (Trap A: right scope, wrong direction). SAT Tip: For inference questions about future events, base your answer only on the passage’s explicit framing of the event’s context, not on assumptions about what “should” happen in the real world.
Q. The author’s primary purpose in the passage is to ___.
A. Advocate for the total banning of all Chinese access to US AI technology
B. Report on a new US government accusation of Chinese AI intellectual property theft ✓
C. Argue that US AI firms are overreacting to Chinese distillation practices
D. Explain the technical process of AI distillation in detail for a general audience
Answer: B — The passage is a news report that lays out the US accusation, the details of the alleged theft, the US response, and Chinese rebuttal, without taking a clear advocacy stance. The most tempting wrong answer is A, which misrepresents the author’s neutral reporting as advocacy for a specific policy (Trap B: uses passage vocabulary but in a wrong combination). SAT Tip: To identify an author’s primary purpose, ask what the passage spends most of its time doing: here, it reports facts and multiple perspectives, rather than arguing for a single policy position.
Q. Which of the following can be most reasonably inferred about distilled AI models?
A. They are always more powerful than the original models they are based on
B. They are developed at a significantly lower cost than original proprietary models ✓
C. They are always fully compliant with US terms of service
D. They are banned in every country outside of China
Answer: B — The passage states Kratsios noted models from surreptitious distillation campaigns do not match the original’s performance but benefit foreign groups because of their significantly lower cost. The most tempting wrong answer is A, which contradicts the passage’s explicit statement that distilled models do not match the original’s performance (Trap A: right scope, wrong direction). SAT Tip: For inference questions, look for language in the passage that supports a general claim, rather than absolute language — here, “significantly lower cost” supports the inference that they are cheaper to develop, even if the passage doesn’t give an exact price.
Q. Which choice provides the BEST evidence for the answer to the previous question?
A. ‘Chinese AI firms are relying on distillation attacks to offset deficits in AI computing power and illicitly reproduce the core capabilities of US models.’
B. ‘He added that while models created by ‘surreptitious, unauthorised distillation campaigns’ did not match the performance of the original models, they can benefit foreign groups because of the significantly lower cost.’ ✓
C. ‘The US would explore measures “to hold foreign actors accountable for industrial-scale distillation campaigns”.’
D. ‘China has always been committed to promoting scientific and technological progress through co-operation and healthy competition.’
Answer: B — Option B directly states that distilled models have a significantly lower cost than original models, which is the evidence for the inference that they are cheaper to develop. The most tempting wrong answer is A, which describes why Chinese firms use distillation but does not mention the lower cost of the resulting models (Trap B: uses passage vocabulary but in a wrong combination). SAT Tip: For evidence-pairing questions, first confirm your answer to the previous question, then scan the passage for the exact line that supports the supporting fact — the correct option will match that line closely, while distractors will reference related but irrelevant details.
💬 Suggested questions
- Why can’t US AI firms just block all distillation queries?
- What’s the downside of banning distillation for US AI developers?
- How does the US entity list restrict Chinese AI firms’ access to tech?
Raw JSON