Security

DeepSeek and Alibaba: US Authorities Accuse China of AI Theft

3 min read

TL;DR Too Long; Didn’t read

NSA, CISA, and FBI accuse six Chinese AI firms in a joint warning of having copied US models on an industrial scale. Variants of Claude, GPT, Gemini, and Grok are affected, tapped through fake accounts and proxy services since late 2024. China denies the allegations and refers to technological independence.

A copy machine prints sheets bearing the DeepSeek logo from an original document carrying the Anthropic, OpenAI, and Google logos, while a magnifying glass in US flag colors hovers above. Image generated with GPT Image 2

Key takeaways

  • Three US security agencies jointly name six Chinese AI firms for the first time as systematic model copiers.
  • DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI are said to be affected.
  • Methods range from fake user accounts to disguised proxy services, the so-called transfer stations.
  • Alibaba is said to have used Claude-4 variants and GPT-5 for the Qwen model family by the end of 2025.
  • Beijing denies the allegations – just weeks before planned talks between Trump and Xi Jinping.
  • The authorities recommend US providers deliberately alter responses to suspicious inquiries.

The US authorities NSA, CISA, and FBI accuse six Chinese AI companies in a joint security warning of copying US leading models on an industrial scale. The warning from September 8 names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI and estimates the outflow at billions of tokens over millions of requests since the end of 2024. China rejects the allegations.

Advisory names methods and affected models

The warning published as AA26-251A describes so-called distillation: companies extract the response behavior of foreign models through massive queries to train their own systems. Several variants of Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini, and xAI’s Grok are affected. The six mentioned companies allegedly used fake user accounts, mass-purchased premium subscriptions, and disguised proxy services, which the authorities refer to as “transfer stations.” Individual campaigns reportedly ran for days to months and included thousands to millions of requests per knowledge domain. The campaign attributed to DeepSeek reportedly dates back to at least the end of 2024 and is thus considered one of the longest-running. Specific token and campaign numbers for each individual company are independently unverified. As an example, the warning additionally mentions Alibaba: the company allegedly used responses from Claude 4, Claude Opus, Claude Sonnet, and GPT-5 at the end of 2025 to improve the programming capabilities, customer dialogue, and image and character creation of its Qwen model family. According to the advisory, the campaigns not only formed a supplement but the core of the AI development strategy of the mentioned companies.

Moonshot case receives official confirmation

Already in July, a White House advisor accused Moonshot AI of developing its model Kimi K3 through distillation of Anthropic’s Fable – the company denied this at the time, citing only fifteen days between the launch of Fable and K3. The new advisory now confirms the case with technical details at the agency level: Kimi K3 is said to originate from Fable versions, while the older model Kimi K2 comes from responses of GPT-4o. Unlike the former government advisor, NSA, CISA, and FBI now speak together and with technical evidence – a step that elevates the allegations from a political statement to an official security warning. Similar disputes had previously occurred between Anthropic and Alibaba regarding Claude Code, where hidden tracking code was supposed to identify Chinese users while Alibaba simultaneously prohibited its employees from using the tool. The new warning now officially integrates both cases into a larger pattern that is operated with the knowledge of the Chinese government.

Beijing rejects allegations

China rejects the allegations. Foreign Ministry spokesperson Mao Ning stated literally: “We reject unfounded accusations,” and referred to technological independence as the basis of Chinese AI development. The ministry instead called for increased cooperation between both countries. The named companies themselves initially did not respond to press inquiries. The warning comes a few weeks before planned talks in September between the government of Donald Trump and China’s head of state and party Xi Jinping, where AI governance is expected to be a topic. The authorities also recommend that affected US providers monitor suspicious account patterns and query ratios, deliberately alter responses to alleged distillation attempts, and share insights across providers. For IT managers in companies, this primarily means one thing: access to Chinese AI services could be more strictly scrutinized or additionally documented in the coming months if US providers implement the recommendations.

It will be crucial whether concrete consequences follow from the warning – such as new export restrictions or entries on US trade lists – or whether it remains a political gesture for now. So far, neither the US Department of Commerce nor the State Department has announced plans to impose sanctions on the advisory. It also remains open how US providers will technically implement the recommended targeted response distortion without unfairly disadvantaging regular users from China.

Frequently asked questions

What does 'AI distillation' mean in this context?

In the distillation process, the responses of a foreign AI model are collected through massive queries and used to train one's own, often cheaper model. The US authorities assess the described scope as systematic know-how outflow rather than a usual research practice.

What evidence does the advisory present specifically?

Methods such as fake accounts, mass-purchased subscriptions, and proxy services are mentioned, as well as examples of individual companies, such as Alibaba's use of Claude and GPT-5 responses for the Qwen models. The authorities do not publish exact token numbers per company.

How have the affected companies reacted?

DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI did not individually comment on the allegations at the time of publication. China's Foreign Ministry rejected the accusations overall.

What consequences could the warning have for companies in Germany?

Direct regulatory steps are initially aimed at US providers, not at European users. However, if US companies implement the recommended countermeasures, local users of Chinese AI services may notice more thorough checks of their access in the future.

Are the named Chinese companies now facing sanctions?

The advisory itself does not contain any sanction announcements. Previous cases, such as the Moonshot allegations from July, show that US government representatives have threatened entity list entries or sanctions in confirmed technology theft cases.

Sources (3)
  1. CISA/NSA/FBI Advisory AA26-251A
  2. Bloomberg: US Says Alibaba, DeepSeek Have 'Systematically' Siphoned AI Models
  3. China hits back at US claims of 'malicious' AI distillation ahead of planned Trump-Xi talks

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog