Investing

Invezz Explains: what is AI distillation, and why is US accusing Chinese firms of it?

Large AI model server transfers data through a funnel into a smaller AI system inside a technology lab.

US security agencies have accused six Chinese artificial intelligence companies of systematically using American AI models to train their own systems, bringing renewed attention to a technical process known as model distillation.

The National Security Agency, Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency said on Tuesday that DeepSeek, Moonshot, Alibaba Group Holding, MiniMax, StepFun and Z.AI had engaged in what they described as “aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of US frontier AI models.”

The agencies said the companies had used distillation since at least 2024 to gain access to information from US AI models and use it to develop their own systems.

What is AI model distillation?

Distillation is a technique used to transfer some of the capabilities of a large, sophisticated AI model into a smaller or more specialized model.

The larger system is generally known as the “teacher” model, while the smaller system is called the “student” model.

Instead of building the smaller model entirely from scratch, developers train it using information generated by the teacher.

The approach was formalized by Geoffrey Hinton and his Google co-authors in 2015 as a way of compressing the behavior of a large model into a smaller one using the outputs produced by the larger system.

In practical terms, a developer can ask a powerful AI model to respond to large numbers of prompts and then use those responses as training material for another model.

The student model learns patterns in the teacher’s responses and can eventually reproduce some of its capabilities without requiring the same scale of computing resources.

The result can be an AI system that is considerably cheaper and easier to operate while retaining much of the performance of the larger model.

That makes distillation an important part of the AI industry’s efforts to make increasingly capable models more efficient.

Distillation has legitimate applications across the AI industry.

Frontier AI companies can use the technique to create smaller versions of their own models that are cheaper to run, faster to respond and more suitable for particular applications.

When does distillation become controversial?

Distillation becomes contentious when a company attempts to reproduce the capabilities of another company’s proprietary model without authorization.

A competitor can potentially use thousands or millions of interactions with a frontier model to generate training data for its own system.

Rather than spending years and enormous sums developing similar capabilities independently, it can use the responses of an existing model as a shortcut.

The US security agencies said Chinese companies had been using multiple pathways to gain unauthorized access to American AI systems.

“China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating US AI companies’ terms of use,” they said in the notice.

OpenAI and Anthropic have separately accused Chinese AI companies of attempting to extract capabilities from their models.

Anthropic said in February that it had uncovered campaigns involving DeepSeek, Moonshot AI and MiniMax that sought to extract capabilities from its Claude chatbot.

According to Anthropic, the campaigns involved approximately 16 million exchanges with Claude and 24,000 fake accounts, with MiniMax alone accounting for more than 13 million exchanges.

OpenAI made similar allegations in January.

The accusations have made distillation a focal point in the broader debate over intellectual property and competition in the AI industry.

The issue gained particular prominence following the emergence of DeepSeek, whose low-cost AI model released last year demonstrated capabilities that appeared competitive with leading US systems.

The development challenged assumptions that the US had an unassailable lead in frontier AI and raised questions about how Chinese companies were achieving comparable performance with substantially different cost structures.

Pukar Hamal, founder of AI security firm SecurityPal, previously compared the practice to a student copying another student’s work.

“It’s almost like someone went to the lectures, read the textbook, and did all the hard work of doing the homework,” Hamal said in an earlier CNBC report.

“Then some other student is like, ‘Hey, I didn’t do that. Can I just copy your work?’”

Why Washington sees a national security risk

The latest US advisory goes beyond concerns about commercial competition.

The agencies said industrial-scale distillation could reduce research and development costs for Chinese AI companies while enhancing China’s “military and cyberattack capabilities that could be used against the US and our allies.”

A Reuters report on July 31 said Chinese military researchers had used outputs from leading US AI models to train domestic systems and advance defense capabilities.

Anthropic has also argued that illicit distillation can create a security problem because safety protections built into American frontier models may not be transferred to the resulting systems.

“Illicitly distilled models lack necessary safeguards, creating significant national security risks,” Anthropic said in a February note.

US AI companies build safeguards intended to prevent their models from assisting with activities such as developing biological weapons or conducting malicious cyber operations.

Anthropic has warned that a model created through unauthorized distillation may not retain those protections.

Key takeaway

Foreign labs that distill American models can then feed these unprotected capabilities into military, intelligence, and surveillance systems—enabling authoritarian governments to deploy frontier AI for offensive cyber operations, disinformation campaigns, and mass surveillance. If distilled models are open-sourced, this risk multiplies as these capabilities spread freely beyond any single government’s control.

Anthropic

AI’s military dimension raises the stakes

The concern is also tied to China’s broader efforts to integrate artificial intelligence into military capabilities.

A February analysis by the Centre for Security and Emerging Technology examined Chinese-language requests for proposals issued by the People’s Liberation Army between January 2023 and December 2024.

The analysis found that the PLA was pursuing AI-enabled capabilities across areas including decision-support systems, sensor enhancement and data fusion.

The researchers also identified significant interest in technologies designed to counter perceived US military advantages, including systems capable of detecting US naval assets above and below the sea and technologies intended to counter US space-based systems.

If advanced AI capabilities can be acquired through unauthorized distillation rather than developed independently, US officials argue, the technology could reach military and intelligence applications more quickly.

China rejects the accusations

Beijing has rejected US allegations that Chinese AI companies are improperly distilling American frontier models.

Chinese Foreign Ministry spokeswoman Mao Ning on Wednesday urged Washington not to make what she called unfounded accusations against China.

“We hope the US side will earnestly implement the important consensus reached by the heads of state of the two countries and refrain from making unfounded accusations and smearing China,” Mao said at a daily news conference in Beijing.

“Both China and the US are major countries in the field of artificial intelligence and they should strengthen cooperation,” she said.

China’s development in artificial intelligence is the result of its high level of self-reliance and independent advancement in science and technology, and it has also benefited from our consistent adherence to the principles of consultation, joint contribution, and shared benefits, as well as open cooperation.

Chinese Foreign Ministry spokeswoman
Mao Ning

In July, a Chinese government statement similarly rejected claims that Chinese AI companies were relying on distillation to reproduce US AI capabilities.

It argued that Chinese models had achieved world-leading capabilities independently and accused Washington of applying a double standard because US companies also use distillation in research and development.

“Many US AI companies have distilled from China’s models for their own R&D and training,” the statement said, adding that US companies had opposed restrictions on access to Chinese open-source models.

How the US is responding

Washington has already begun considering measures to counter what it views as industrial-scale AI model theft.

In April, the White House Office of Science and Technology Policy issued a memorandum, saying the Trump administration would share intelligence with US AI companies about attempts by foreign actors to conduct unauthorized, industrial-scale distillation.

The administration also said it would help the private sector coordinate responses, work with industry to develop methods for identifying and mitigating such activity and explore measures to hold foreign actors accountable.

US lawmakers are pursuing legislation as well.

The House Foreign Affairs Committee advanced the Deterring American AI Model Theft Act in April, aimed at addressing concerns over unauthorized copying of US AI models.

The latest security advisory could add momentum to those efforts.

The agencies advised American AI developers to take “immediate action,” including changing responses to suspected malicious distillation attempts and sharing intelligence about such campaigns with other AI companies.

Why the distinction matters

The debate over distillation ultimately reflects a larger question about how AI capabilities should be developed and shared.

As a technology, distillation is neither new nor inherently illicit. It is a widely used method for making powerful AI systems smaller, cheaper and more practical.

The dispute is instead about access, authorization and what happens when a competitor uses a proprietary model’s outputs to reproduce capabilities that took another company years and billions of dollars to develop.

That distinction is likely to become increasingly important as AI models become more capable and their commercial and military value rises.

For US AI companies, the challenge is no longer simply building better models. They must also protect those models from being used as an inexpensive source of training data by competitors.

For policymakers, meanwhile, the question is how to prevent unauthorized extraction of AI capabilities without restricting legitimate research, open-source development and the normal use of distillation across the industry.

The latest US allegations against six Chinese companies suggest that the battle over AI leadership is moving beyond chips and computing power.

Increasingly, the outputs generated by AI models themselves are becoming a strategic asset.

The post Invezz Explains: what is AI distillation, and why is US accusing Chinese firms of it? appeared first on Invezz

You may also like