The battle for artificial-intelligence supremacy has moved into a new and increasingly uncomfortable phase.
The United States is no longer merely competing with China over who can build the most powerful AI models.
Washington is now accusing several of China's biggest AI companies of systematically extracting capabilities from American models on an industrial scale.
The allegations, issued jointly by the National Security Agency, FBI and Cybersecurity and Infrastructure Security Agency, name some of China's most important AI developers, including DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI. U.S. security agencies say the companies have used a technique known as model distillation to draw information from American AI systems and use it to improve their own models.
The accusation is serious because distillation itself is not illegal or inherently abusive.
AI companies routinely use a stronger model to teach a smaller or more specialized model. The process can make AI systems cheaper, faster and more efficient.
The controversy is about how that process is being used.
According to the U.S. agencies, Chinese companies have allegedly created large networks of accounts and used proxy services and carefully designed prompts to extract information from leading American models while avoiding usage limits and restrictions.
In Washington's description, this is not ordinary competition.
It is a systematic effort to obtain capabilities that took American companies enormous amounts of money, computing power and research time to develop.
The agencies say Chinese firms have been conducting these campaigns since at least 2024 and at an “industrial scale.” They also allege that some activity has likely occurred with awareness by Chinese government authorities.
The allegations come at an extremely sensitive moment.
Artificial intelligence has become one of the central battlegrounds in the broader U.S.-China strategic rivalry.
Washington wants to preserve America's lead in frontier AI because policymakers increasingly view advanced models as critical to economic productivity, cybersecurity, intelligence and military capabilities.
Beijing has its own ambition: reduce dependence on Western technology and build globally competitive AI systems using Chinese companies and infrastructure.
The rivalry has intensified as Chinese models have demonstrated that they can sometimes approach the performance of expensive American systems at significantly lower cost.
That is precisely why model distillation has become such a politically sensitive issue.
If a smaller AI developer can repeatedly query a much more expensive model, capture useful behavior and use those outputs to improve its own system, the cost of catching up with a frontier model could fall dramatically.
The original developer still paid for the research, engineers, training data, GPUs and experiments.
The competitor can potentially learn from the finished product.
That is the concern U.S. officials are now trying to address.
The agencies' advisory goes further than previous public accusations.
It details which American systems were allegedly targeted by particular Chinese companies and what those companies were reportedly trying to improve, including mathematical reasoning, coding and other capabilities.
That specificity raises the political stakes.
OpenAI and Anthropic have been warning for months that Chinese competitors may be using their models to accelerate development.
Anthropic previously accused Alibaba of attempting to access Claude through thousands of fraudulent accounts, describing the campaign as a large-scale effort to obtain model capabilities without authorization.
The latest U.S. government announcement effectively turns those corporate complaints into a national-security matter.
And that could have consequences far beyond the companies directly named.
American AI developers are being advised to take immediate action.
The government wants companies to alter responses to suspected malicious distillation attempts and share intelligence about attack patterns and campaigns with one another.
That could change the way frontier models are made available.
AI companies may become more aggressive in detecting unusual usage.
They may impose tighter limits on accounts.
They may monitor prompts for patterns associated with automated extraction.
And they may increasingly distinguish ordinary customers from users that appear to be trying to replicate model behavior systematically.
For legitimate users, that could create new friction.
For AI companies, it may become another cost of operating at the frontier.
But Washington appears willing to accept those costs.
The argument is that America's AI lead represents a strategic asset that cannot simply be treated like ordinary software.
The timing is especially sensitive because President Donald Trump is scheduled to welcome Chinese President Xi Jinping to Washington later this month.
The accusations could complicate discussions between the world's two largest economies at precisely the moment officials are already negotiating over trade, technology and strategic competition.
There is also the possibility of sanctions.
Treasury Secretary Scott Bessent has previously warned that Chinese ventures involved in intellectual-property theft could face penalties.
If the United States moves from warnings to sanctions, the consequences could spread into the global AI supply chain.
American companies could be restricted from working with certain Chinese AI firms.
Chinese developers could face additional limitations on access to American technology.
Investors could begin assigning higher geopolitical risk premiums to Chinese technology companies.
And AI researchers could find themselves operating inside an increasingly divided technology ecosystem.
That possibility worries businesses on both sides.
AI development benefits from global research collaboration.
Fragmenting the industry into separate American and Chinese ecosystems could increase costs and slow innovation.
But Washington's counterargument is straightforward.
The United States cannot allow a strategic advantage to be eroded by what officials describe as unauthorized extraction of proprietary AI capabilities.
The issue is also becoming harder to separate from cybersecurity.
A powerful AI model contains information about how the system reasons, writes code, solves problems and responds to different types of prompts.
A sufficiently sophisticated extraction campaign could potentially reveal useful behavioral patterns without accessing the model's underlying source code or training data.
That makes the model itself a valuable target.
The security problem resembles a new type of industrial espionage.
There may be no stolen hard drive.
No engineer necessarily needs to defect.
Instead, a competitor can interact with the product itself, repeatedly probe its capabilities and collect the outputs.
AI companies therefore face an unusual security challenge: protecting what the model reveals while still making the model useful to customers.
That tension could become one of the defining cybersecurity problems of the AI era.
For Chinese AI companies, meanwhile, the accusations are likely to be politically damaging even before any formal penalties appear.
China has previously rejected U.S. allegations involving unfair use of AI technology, and representatives of the companies named in the latest advisory had not immediately responded to requests for comment.
The companies also have legitimate reasons to pursue model distillation.
It is a standard AI-development technique.
Smaller models can become dramatically cheaper and faster through distillation.
The line between legitimate research and unauthorized copying is therefore not always obvious from the outside.
That will make enforcement difficult.
Washington must prove that specific behavior violated terms of use or otherwise crossed legal boundaries.
It also needs evidence strong enough to withstand international scrutiny.
But even without courtroom victories, the strategic consequences are already clear.
AI has entered a new phase of geopolitical competition.
The question is no longer only who has the biggest data center or the most GPUs.
It is also who controls access to the knowledge generated by frontier models.
And who can stop rivals from learning too quickly.
For the United States, the answer may require stronger defenses around AI models.
For China, it could mean greater pressure to demonstrate that domestic AI development can advance without relying on capabilities allegedly obtained from American systems.
For investors, the story adds another layer of risk to an industry already dealing with enormous valuations, energy demands and semiconductor bottlenecks.
The AI race was already expensive.
Now it is becoming more political.
And as the world's two largest economies compete to control the technology of the future, the most valuable asset may not be a chip or a data center.
It may be the intelligence inside the model.
Washington now says China is trying to copy it.
And the fight over who owns that intelligence may only be beginning.
