US AI firms warn of Chinese distillation attacks; Beijing threatens countermeasures
U.S. frontier AI companies alert authorities to sophisticated model distillation by China and Russia; Beijing rejects claims and warns of retaliation if America constrains Chinese AI.
What to know
- U.S. AI companies are warning authorities that foreign actors—particularly China and Russia—are using distillation attacks to extract training data from frontier models to build cheaper, faster alternatives.
- Foreign actors have evolved tactics beyond direct model queries to purchasing logs of third-party conversations from legitimate accounts, making detection and prevention more difficult.
- China rejected the distillation allegations but threatened "countermeasures" if the U.S. uses these claims as a pretext to constrain Chinese AI development.
- The dispute highlights conflicting approaches: U.S. companies maintain proprietary closed models while Chinese firms operate open-weight alternatives, raising questions about whose intellectual property claims carry weight.
U.S. frontier AI companies Companies warning of distillation attacksU.S. government Policy authorityChina Alleged perpetrator and respondentOpenAI, Anthropic, Google U.S. frontier AI developersChinese AI developers (Deepseek, Moonshot) Alleged users of distillation
How it unfolded 2 developments, newest first · click a bar or a number to jump articles
-
2
China rejects distillation allegations and warns of countermeasures
China publicly rejected U.S. claims about distillation attacks but pledged to enact "countermeasures" if America used the allegations as a pretext to contain Chinese AI development.
“China has publicly rejected these claims, but pledged to enact "countermeasures" if America used the pretext of these allegations to "contain" Chinese developments.”
— China -
1
U.S. companies and government warn of ongoing distillation vulnerability
U.S. AI companies and government officials grew increasingly concerned about the effectiveness of distillation attacks, noting that foreign actors have begun purchasing logs of third-party conversations using legitimate accounts—a harder vector to detect and prevent than direct attacks.
“This may be helping China and Russia develop AI models with similar capabilities, but at a fraction of the cost and compute requirements.”
— Tom's Hardware -
background
Kimi K3 released following distillation pattern — Chinese developers released Kimi K3 in 2026 following similar trajectory to Deepseek, suggesting reliance on distillation to achieve frontier-level performance at fraction of the cost.
-
background
Western AI labs pledge to combat distillation attacks — Major Western AI laboratories committed to working together against distillation attacks at some point earlier in 2026, signaling growing concern about the threat.
-
background
Distillation suspected in Chinese AI breakthroughs — Deepseek achieved significant capability leaps in 2025, with analysis suggesting distillation from frontier models may have played a role in rapid development at lower cost.