๐Ÿ”ฌ Model Lab

New run Stored runs โš–๏ธ Judge verdicts ๐Ÿงฎ Math ๐Ÿ“Š Math runs ๐Ÿ“„ Benchmark paper ๐Ÿ“„ 3-model paper ๐Ÿ“„ Meta: Will Muse Cause a Spark?

China's AI Shortcut: Copying the Test Without Hacking the School

anthropic:claude-sonnet-4-6 ยท prompt: edited ยท 2026-05-30T15:30:27 ยท 8.57ยข ยท ๐Ÿ” view original input โ†—

๐Ÿ“ƒ Rewritten passage

In April 2026, the White House issued a striking accusation: Chinese entities, it said, are running coordinated, large-scale campaigns to steal the capabilities of America's most advanced artificial intelligence systems โ€” not by hacking servers or bribing insiders, but by exploiting a technique called knowledge distillation. The memo came from Michael Kratsios, director of the White House Office of Science and Technology Policy and the Trump administration's chief science advisor, and it landed at a moment when the US-China rivalry over AI dominance has reached a fever pitch. Distillation, in its legitimate form, is a standard engineering practice. A company trains a smaller, cheaper 'student' model to mimic a larger, more expensive 'teacher' model by feeding the student millions of the teacher's outputs. The result is a compact system that punches above its weight. What the White House alleges is different in character and intent: foreign actors have been using tens of thousands of fake proxy accounts โ€” digital disguises โ€” to query American AI systems through their public APIs, harvesting the responses at industrial scale and using them to train rival models. Jailbreaking techniques, designed to trick AI systems into bypassing their own safety restrictions, reportedly made the extraction even more efficient. The controversy gained its sharpest focus with the emergence of DeepSeek, a Chinese AI lab that released a powerful reasoning model in early 2025 at a reported cost far below what American companies spend on comparable systems. OpenAI alleged DeepSeek had used outputs from its GPT models to train its own system in violation of OpenAI's terms of service. Then, in February 2026, Anthropic named three Chinese firms โ€” DeepSeek, Moonshot, and MiniMax โ€” accusing all three of generating over 16 million exchanges with its Claude model through approximately 24,000 fraudulent accounts. The Chinese embassy in Washington called the White House accusations 'pure slander,' insisting China supports intellectual property protection and fair competition. But here is the catch that makes this more than a corporate dispute: American AI companies warn that distilled models are dangerous not just economically, but militarily. Frontier AI systems built by firms like OpenAI and Anthropic include safety guardrails โ€” filters engineered to refuse requests for instructions on building bioweapons or launching cyberattacks. A distilled copy may reproduce a model's raw intelligence without inheriting those guardrails, leaving a powerful tool with no ethical brakes in the hands of a foreign government. This is why US officials frame distillation attacks as a national security problem, not merely an intellectual property one. Export controls on advanced American chips were supposed to keep China from training competing models โ€” but if distillation can copy a model's learned capabilities through software alone, those hardware restrictions lose much of their bite. Congress has begun to respond. The House Foreign Affairs Committee passed legislation in late April 2026 that would require the administration to consider adding distillation-using groups to the 'entity list' โ€” a federal blacklist that effectively bars US companies from selling technology to the listed organizations. Chris McGuire, a technology security analyst at the Council on Foreign Relations, has called for banning Chinese groups from accessing US models altogether and sanctioning entities that facilitate distillation attacks. Whether those measures can close the loophole โ€” or whether the nature of publicly accessible AI makes some degree of capability transfer inevitable โ€” remains an open and urgent question.

What if you could ace a final exam not by studying, but by quizzing the smartest student until you absorbed everything they knew โ€” and doing it ten million times overnight?

๐Ÿ“– What's Going On?

The White House has formally accused Chinese entities of running what it calls 'industrial-scale' campaigns to steal the intellectual property of American AI companies. The accusation, delivered in a memo by Michael Kratsios โ€” Trump's top science and technology advisor and director of the White House Office of Science and Technology Policy โ€” names a specific technique: AI distillation. According to the memo, Chinese groups are using tens of thousands of fake proxy accounts and 'jailbreaking' tricks to extract the core capabilities of cutting-edge American AI systems.

The controversy exploded into public view after China's AI lab DeepSeek released a powerful model in early 2025 that rivaled the best American systems โ€” at a tiny fraction of the usual cost. OpenAI alleged DeepSeek had used outputs from its GPT models to train its own system, in violation of OpenAI's terms of service. In February 2026, Anthropic named three Chinese firms specifically โ€” DeepSeek, Moonshot, and MiniMax โ€” accusing all three of coordinated distillation attacks on its Claude AI model.

๐ŸŽฏ How To Think About It

The tricky thing about distillation is that it doesn't look like traditional theft. No server is hacked. No classified file is stolen. Instead, the attacker exploits the normal API โ€” the digital doorway that any paying customer uses to query a model โ€” and fires off millions of carefully crafted questions, collecting the answers to teach a copycat model. Here are two ways to lock in the mechanism:

๐Ÿ’ก Key Things To Know

๐ŸŒŸ Why It Matters

If you're thinking about a career in tech, cybersecurity, law, or government โ€” this debate is going to be a defining issue of your working life. The AI race between the US and China is shaping which companies get to build the tools that run hospitals, financial markets, and militaries. It's also a genuinely hard legal puzzle: when is querying a public API 'theft'? No court has answered that yet. Meanwhile, export controls on advanced chips โ€” the hardware AI runs on โ€” are only effective if distillation can't simply route around them by copying the software instead. That gap between hardware controls and software reality is where the next policy battles will be fought.

๐Ÿ”ฎ The Bigger Picture

This story sits inside a much older pattern: every major technology race โ€” nuclear, space, semiconductor โ€” has involved aggressive efforts by rivals to compress the gap through intelligence and theft alongside legitimate research. What's new is that AI distillation can happen remotely, instantly, and at a scale no human spy network could match. The Trump administration's planned responses โ€” sharing intelligence with US AI firms, adding distilling entities to export blacklists, exploring sanctions โ€” are all reactive. The harder, longer question is whether Western AI companies can build technical defenses fast enough to stay meaningfully ahead, or whether the lead will erode no matter what Washington does. With Trump set to meet President Xi in Beijing, this tension will be impossible to ignore at the diplomatic table.

๐Ÿ“– Glossary (8)

๐Ÿ“ Quiz (10) โ€” with answers

Q. The passage primarily argues that Chinese entities are undermining US AI leadership by
A. hacking into US government servers to steal classified chip designs
B. exploiting AI model outputs at massive scale to build competing systems cheaply โœ“
C. purchasing advanced Nvidia chips illegally through front companies abroad
D. recruiting American AI researchers to work secretly for Chinese firms
Answer: B โ€” The passage centers on distillation โ€” using a legitimate API to harvest model outputs and train copycat AI systems at far lower cost than building from scratch. Option A describes hacking, which the passage explicitly contrasts with distillation. SAT Tip: On 'primary argument' questions, eliminate answers that describe things the passage merely mentions in passing, and choose the one that captures the central mechanism the author keeps returning to.
Q. According to the passage, which of the following best explains why AI distillation is especially threatening to US export controls on advanced chips?
A. Distillation allows China to produce chips domestically without needing US technology
B. Distillation enables China to circumvent chip shortages by copying AI capabilities in software โœ“
C. Export controls only apply to chips sold directly and not to chips smuggled through allies
D. Distillation gives Chinese firms access to classified US government AI systems
Answer: B โ€” The passage states that distillation enables foreign groups to 'close the competitive advantage that the US enjoys because of export controls on advanced American chips' โ€” meaning they can copy the AI's learned capabilities without needing the hardware. Option C introduces a claim about smuggling routes that the passage does not make. SAT Tip: On cause-and-effect questions, anchor your answer to the specific causal chain the author describes, not a plausible real-world mechanism that isn't in the text.
Q. The passage indicates that distilled models created through unauthorized campaigns are dangerous to national security primarily because they
A. perform better than the original models on most benchmarks
B. give foreign governments access to AI without the safety guardrails that block harmful uses โœ“
C. are impossible for US intelligence agencies to detect or monitor
D. allow China to sell cheaper AI products and undercut American technology companies
Answer: B โ€” The passage explicitly states that US firms worry distilled models 'lack the safeguards that, for example, prevent the development of bioweapons or malicious cyber attacks.' Option A is directly contradicted by the passage, which notes distilled models do not match the performance of original models. SAT Tip: When a question asks about a specific concern raised in the passage, look for the sentence that directly states that concern โ€” don't infer from real-world knowledge.
Q. As used in the passage, the word 'distil' most nearly means
A. purify a liquid by heating and collecting its vapor
B. summarize a long document into a shorter version
C. train a model by extracting learned capabilities from another model's outputs โœ“
D. gradually reduce the size of a company's research budget
Answer: C โ€” In this passage, 'distil' refers to the AI-specific process of training a smaller model on the outputs of a larger one to replicate its capabilities โ€” a technical meaning distinct from the word's common uses. Option A is the most tempting distractor because it is the word's everyday dictionary meaning, which does not apply here. SAT Tip: On vocabulary-in-context questions, substitute each answer choice back into the sentence and ask which one preserves the passage's intended meaning โ€” the common definition is usually the trap.
Q. As used in the passage, 'surreptitious' most nearly means
A. technically sophisticated and difficult to replicate
B. secretive and deliberately concealed from detection โœ“
C. financially motivated and commercially profitable
D. conducted by state-sponsored actors with government funding
Answer: B โ€” The passage uses 'surreptitious' to describe unauthorized distillation campaigns carried out covertly using proxy accounts to evade detection โ€” meaning hidden or secretive. Option D describes a real-world characteristic sometimes associated with such campaigns, but the passage does not use 'surreptitious' to mean state-sponsored. SAT Tip: Vocabulary-in-context answers must fit the precise sentence, not just the general topic. Ask: does this definition make the sentence true in context?
Q. Which statement about AI distillation can most reasonably be inferred from the passage?
A. The US government intends to make all forms of distillation illegal within two years
B. Distillation is a neutral technique that only becomes problematic at unauthorized industrial scale โœ“
C. Distillation always produces models that are as capable as the originals they copy
D. Only Chinese firms have used distillation; American companies rely on other training methods
Answer: B โ€” Kratsios is quoted in the passage acknowledging distillation is 'a vital part of the AI ecosystem when used legitimately' while condemning only 'industrial distillation' used to undermine American R&D โ€” clearly framing it as technique-neutral but use-dependent. Option C is contradicted by the passage's statement that distilled models do not match the performance of originals. SAT Tip: Inference questions test what the passage logically implies, not what you already know. Eliminate options that go beyond or contradict the text.
Q. The passage suggests that the Chinese embassy's response to the White House accusations was
A. a detailed technical rebuttal challenging the definition of distillation
B. an offer to negotiate a bilateral agreement on AI intellectual property
C. a flat denial framing the accusations as false and politically motivated โœ“
D. a partial admission that some Chinese firms had exceeded permitted API usage
Answer: C โ€” The embassy spokesperson called the accusations 'pure slander' and emphasized China's commitment to IP protection and healthy competition โ€” a categorical rejection with no technical engagement. Option D contradicts the passage; no partial admission is described. SAT Tip: When a question asks about a character's or institution's response, locate the direct quote or paraphrase in the text and match its tone precisely โ€” 'pure slander' signals categorical denial, not negotiation.
Q. The author's primary purpose in including the Council on Foreign Relations analyst's comments is to
A. provide an independent expert voice that supports and extends the case for stronger US action โœ“
B. introduce a dissenting view that challenges the White House's characterization of the threat
C. explain the technical details of how proxy accounts are used in distillation attacks
D. demonstrate that bipartisan consensus exists in Washington on the distillation issue
Answer: A โ€” Chris McGuire's comments reinforce the White House position and add specific policy recommendations โ€” bans, sanctions, tighter export controls โ€” making the case for US action more concrete and credible. Option B misreads the excerpt; McGuire does not dispute the threat, he amplifies it. SAT Tip: When identifying an author's purpose for including a source, ask what job that source does in the argument โ€” does it support, complicate, illustrate, or rebut the surrounding claim?
Q. Which of the following can most reasonably be inferred about why American AI companies care about distillation beyond protecting their revenue?
A. They fear distillation will make their own models obsolete within months
B. They are concerned that copied models operating without safety filters could enable catastrophic misuse โœ“
C. They worry that distillation will allow Chinese firms to hire away their best engineers
D. They believe distillation violates international trade law and want to set a legal precedent
Answer: B โ€” The passage states US firms worry that distilled models 'lack the safeguards that prevent the development of bioweapons or malicious cyber attacks' โ€” a concern that goes well beyond commercial competition. Option C introduces a talent-poaching angle that does not appear anywhere in the passage. SAT Tip: Inference questions require you to stay inside the passage's boundaries. If a detail is plausible but absent from the text, it cannot be the correct inference.
Q. Which excerpt from the passage provides the best evidence for the answer to the previous question?
A. 'Distillation was a vital part of the AI ecosystem when used legitimately to make lighter-weight models.'
B. 'Chinese campaigns were leveraging tens of thousands of proxy accounts to evade detection.'
C. 'American AI companies are concerned that distilled models pose national security risks because they lack the safeguards that prevent the development of bioweapons or malicious cyber attacks.' โœ“
D. 'The US would explore measures to hold foreign actors accountable for industrial-scale distillation campaigns.'
Answer: C โ€” This sentence directly states the national-security concern โ€” missing safety guardrails against bioweapons and cyberattacks โ€” that goes beyond commercial interests, which is exactly what question 9 asks about. Option A addresses the legitimate use of distillation, not the national security concern. SAT Tip: On evidence-pairing questions, first lock in your answer to the previous question, then search for the sentence that contains that answer's key words or idea almost verbatim โ€” speed comes from matching concepts, not rereading everything.

๐Ÿ’ฌ Suggested questions

Raw JSON