How to Copy a $100M AI for Pennies โ and Why Washington Is Furious
anthropic:claude-opus-4-8 ยท prompt: edited
ยท 2026-05-30T15:30:27 ยท 15.59ยข
ยท ๐ view original input โ
๐ Rewritten passage
In April 2026, the White House leveled a striking accusation at China: that it was running an "industrial-scale" campaign to copy the most advanced artificial intelligence built in American labs. The charge came from Michael Kratsios, director of the White House Office of Science and Technology Policy, in a memo to government departments. Foreign entities, mostly based in China, he wrote, were deliberately working to "distill" the United States' frontier AI systems โ its most powerful, cutting-edge models. The timing was pointed: the accusation landed just weeks before President Trump was set to meet President Xi in Beijing.
To understand the fight, you have to understand distillation. It is a technique where a smaller, cheaper AI model is trained on the outputs of a larger, more capable one โ essentially learning to imitate the bigger model's answers. Used openly, distillation is ordinary and even useful; it's how engineers make lighter, faster versions of heavy models. Kratsios acknowledged as much. But he drew a sharp line between legitimate use and what he called surreptitious, unauthorized campaigns aimed at undermining American research. According to the memo, Chinese efforts leaned on tens of thousands of proxy accounts to avoid detection and used "jailbreaking" tricks โ clever prompts that coax a model into revealing protected information.
Here's the catch that makes the issue so thorny. The United States has spent years trying to slow China's AI ambitions by restricting exports of advanced computer chips, the expensive hardware needed to train top models. Distillation is a way around that wall. American firms such as Anthropic and OpenAI argue that by copying the behavior of US models, foreign labs can close the competitive gap without the chips โ eroding the very advantage the export controls were meant to protect. Notably, distilled copies usually do not match the originals' performance. Yet they can still pay off for a rival, because they cost so dramatically less to produce.
There's a safety dimension too. US companies warn that distilled models often lack the guardrails built into the originals โ the safeguards designed to stop an AI from helping develop bioweapons or launch malicious cyberattacks. A cheap copy that skips those protections, they argue, is a national-security problem, not just a commercial one. This isn't a brand-new complaint: in early 2025, OpenAI said it had evidence that China's DeepSeek had trained on outputs from its GPT models in violation of its terms of service, and in February 2026 Anthropic accused three Chinese firms โ DeepSeek, Moonshot, and MiniMax โ of distillation attacks.
China rejected the latest charge outright, with its embassy in Washington calling it "pure slander" and insisting the country respects intellectual property and pursues progress through fair competition. Meanwhile, Washington is moving from words toward consequences. The administration said it would share threat information with US AI firms and explore ways to hold foreign actors accountable, while the House Foreign Affairs Committee advanced bills to make it harder for China to catch up. One would push the government to add groups that distill US models to the "entity list" โ an export blacklist that would largely block American companies from selling technology to them. The deeper puzzle remains unresolved: in a race where a model reveals something about itself every time it answers a question, how does any nation keep its lead a secret?
Imagine acing a final exam not by studying, but by photographing thousands of a top student's answer keys. That, Washington says, is what China is doing to American AI.
๐ What's Going On?
The White House has formally accused China of running an "industrial-scale" campaign to steal the intellectual property behind America's most advanced AI systems. Michael Kratsios, the director of the White House Office of Science and Technology Policy, wrote in a memo that foreign entities โ mostly based in China โ are deliberately "distilling" US frontier AI models.
Distillation means training a smaller, cheaper AI model by feeding it the outputs of a larger, more powerful one. The administration says it will share threat information with US AI companies and explore ways to punish foreign actors. China's embassy in Washington dismissed the accusation as "pure slander."
๐ฏ How To Think About It
The fight isn't over physical blueprints being stolen from a vault. It's about something subtler: copying a system's behavior by watching how it responds.
- It's like reverse-engineering a secret recipe by tasting the dish thousands of times. You never get the chef's handwritten card, but by sampling enough plates you can reproduce a 'good enough' version at a fraction of the cost.
- It also mirrors a chess student who can't out-calculate a grandmaster, so instead memorizes the master's moves from recorded games โ closing the skill gap without the years of training the original required.
๐ก Key Things To Know
- The accusation came from Michael Kratsios, head of the White House Office of Science and Technology Policy, weeks before a planned TrumpโXi meeting in Beijing.
- Distillation works by training a small model on the answers of a big one โ it's legitimate and common, but the US objects to 'industrial-scale' unauthorized use.
- The memo claims Chinese campaigns use tens of thousands of proxy accounts and 'jailbreaking' to evade detection and extract proprietary information.
- US firms like Anthropic and OpenAI worry distilled models lack safety guardrails โ meaning they might more easily help build bioweapons or cyberattacks.
- What people miss: distilled copies are usually weaker than the originals, but their dramatically lower cost still makes them a competitive threat.
๐ Why It Matters
AI is shaping the careers and tools you'll inherit โ from college admissions software to the jobs that exist in 2030. This dispute decides whether cutting-edge AI stays expensive and controlled or becomes cheap and globally available, which affects everything from national security to which apps you'll use. It's also a live case study in how technology, trade law, and geopolitics now fuse into a single contest.
๐ฎ The Bigger Picture
Washington has tried to slow China with export controls on advanced chips; distillation is a way to climb that wall without the hardware. Watch for the 'entity list' โ an export blacklist โ to expand, and for US labs to lock down model access. The deeper question: in an arms race where ideas leak the moment a model talks to the world, can any country truly keep its lead secret?
๐ Glossary (7)
- Distillation โ A machine-learning technique where a smaller 'student' model is trained on the outputs of a larger 'teacher' model, capturing much of its ability at lower cost. It's standard practice; the controversy is using it on a rival's model without permission.
- Frontier AI model โ The most advanced, cutting-edge AI systems at the leading edge of capability โ the kind built by labs like OpenAI and Anthropic that cost enormous sums to train.
- Jailbreaking โ Crafting clever prompts that trick an AI into bypassing its built-in rules, revealing hidden instructions or producing output it was designed to refuse.
- Proxy accounts โ Many separate user accounts, often disguised, used to spread activity around so it doesn't look like one party making suspiciously large numbers of requests.
- Export controls โ Government rules restricting which technologies (like advanced AI chips) can be sold to certain countries, used here to slow China's AI progress.
- Entity list โ A US government blacklist of foreign groups that American companies are largely barred from selling technology to without special licenses.
- Guardrails (AI safeguards) โ Built-in safety limits that stop an AI from helping with dangerous tasks, such as designing bioweapons or launching cyberattacks.
๐ Quiz (10) โ with answers
Q. The passage most directly argues that the US-China AI dispute centers on which concern?
A. China physically stealing American AI computer chips
B. China copying US models' behavior through unauthorized distillation โ
C. American firms selling models too cheaply abroad
D. Chinese students enrolling in US engineering programs
Answer: B โ The passage's core claim is that China is accused of 'industrial-scale' distillation โ training smaller models on US models' outputs. Option A is the trap (right scope, wrong mechanism): chip export controls are mentioned, but the central accusation is about distillation, not physically stealing chips. SAT Tip: The 'primary argument' answer must match the passage's main thread, not a side detail it merely references in passing.
Q. Which choice best states the central idea of the passage?
A. Distillation is always illegal and harms global AI research
B. China has admitted to stealing US intellectual property
C. The US accuses China of cheaply copying its AI, sparking countermeasures โ
D. American AI models are technically inferior to Chinese ones
Answer: C โ The passage frames a US accusation of large-scale copying plus proposed US responses like blacklists. Option A is wrong (Trap B, passage vocabulary misused): the passage explicitly says distillation is legitimate when used properly. SAT Tip: A central-idea answer should capture both the conflict and the response, not seize on one extreme word like 'always.'
Q. According to the passage, US AI firms worry that distilled models are dangerous because they ___
A. outperform the original American models in every task
B. lack safeguards against uses like bioweapons or cyberattacks โ
C. are sold only to the US government at high prices
D. require more computing power than original models
Answer: B โ The passage states distilled models can lack the safeguards that prevent bioweapon development or malicious cyberattacks. Option A reverses the facts (Trap A): the passage says distilled models usually do NOT match the originals' performance. SAT Tip: When a question asks 'because,' locate the exact cause stated in the text rather than picking a plausible-sounding effect.
Q. As used in the passage, the word "distill" most nearly means to ___
A. purify a liquid by boiling it
B. extract a model's abilities by copying its outputs โ
C. summarize a long document briefly
D. destroy data to hide evidence
Answer: B โ In this passage, distilling means training smaller models on a larger model's outputs to capture its capabilities. Option A is the trap (common meaning): 'distill' usually refers to purifying liquids, but that's not the passage's technical sense. SAT Tip: On vocab-in-context, substitute each option into the sentence โ the right one preserves the sentence's actual meaning in context.
Q. As used in the passage, the word "frontier" most nearly means ___
A. a guarded national border
B. the most advanced, leading-edge โ
C. an empty, unexplored wilderness
D. a low-cost, budget version
Answer: B โ "Frontier AI systems" refers to the most advanced models at the cutting edge. Option A is the trap (common meaning): 'frontier' often means a geographic border, but here it describes technological leadership. SAT Tip: Watch for words with everyday meanings that take on specialized senses in technical writing โ context overrides the dictionary's first definition.
Q. Which statement about export controls can most reasonably be inferred from the passage?
A. They have completely stopped China's AI progress
B. Distillation lets China bypass the advantage controls create โ
C. They are opposed by every US AI company
D. They primarily target American firms, not Chinese ones
Answer: B โ The passage says distillation lets foreign labs close the competitive gap the US enjoys thanks to chip export controls โ implying distillation is a workaround. Option A is the trap (Trap C, true-sounding but unsupported and too absolute): nothing says controls have 'completely' stopped China. SAT Tip: Inference answers should follow logically from the text; reject any option with sweeping words like 'completely' unless the passage explicitly supports them.
Q. The passage suggests that a distilled model can still benefit a foreign group even when it ___
A. costs more than the original to build
B. performs worse than the original model โ
C. is fully authorized by the original lab
D. includes stronger safety guardrails
Answer: B โ The passage notes distilled models don't match originals' performance but still help because they're far cheaper. Option D is tempting but contradicts the text (Trap B): the passage warns distilled models often lack guardrails, not that they include stronger ones. SAT Tip: When an option states the opposite of a detail in the passage, eliminate it immediately โ even if it sounds reassuring.
Q. The author's primary purpose in the passage is to ___
A. celebrate China's clever engineering achievements
B. explain a US accusation and the conflict surrounding it โ
C. argue that all AI distillation should be banned
D. predict the exact winner of the AI arms race
Answer: B โ The passage neutrally lays out the US accusation, China's denial, and proposed responses โ an explanatory purpose. Option C is the trap (Trap C, real-world position but unsupported): the passage notes distillation is legitimate when used properly, so it doesn't argue for a total ban. SAT Tip: Identify purpose by the author's overall stance โ reporting both sides signals 'explain,' not 'argue.'
Q. Which statement can most reasonably be inferred about the timing of the US accusation?
A. It was issued to coincide with a major Chinese holiday
B. It arrived shortly before a high-level US-China summit โ
C. It was delayed for several years after the first complaints
D. It was released only after China admitted wrongdoing
Answer: B โ The passage says the accusation came just weeks before Trump was set to meet Xi in Beijing, implying sensitive timing ahead of a summit. Option D is the trap (Trap A, opposite of facts): China denied the accusation as 'pure slander,' so no admission occurred. SAT Tip: For inference, anchor to a concrete textual detail (here, the upcoming meeting) rather than guessing at motives the text never states.
Q. Which choice provides the BEST evidence for the answer to the previous question?
A. "China dismissed the accusation as pure slander"
B. "distillation is legitimate when used properly"
C. "weeks before Trump was set to meet Xi in Beijing" โ
D. "distilled models often lack safety guardrails"
Answer: C โ The phrase about meeting Xi in Beijing directly supports the inference that the accusation preceded a major summit. Option A is the trap: it's a real quote from the passage, but it supports China's denial, not the timing inference. SAT Tip: On evidence-pairing, first pin down the line that supports your prior answer, then choose the option that matches it โ ignore quotes that are true but irrelevant.
๐ฌ Suggested questions
- Why does distillation let China dodge US chip export controls?
- If distilled models are weaker, why is Washington so worried?
- How exactly do 'jailbreaking' prompts extract a model's secrets?
Raw JSON