China’s AI Distillation Campaigns Prompt US Government Warning, but Show That US Firms Are Still Well Ahead

September 15, 2026


New memo says Chinese AI firms including DeepSeek and Moonshot are conducting AI distillation against leading US models at “industrial scale”, using billions of tokens and proxy “transfer stations” to disguise traffic while extracting model capabilities and probing API access.

A memorandum recently issued by CISA (with the backing of the NSA and FBI) warns that Chinese firms are parasitically drawing from the frontier models of US developers via AI distillation techniques, but the developers were likely aware of that already. The other piece of information to take from this is that China’s AI developers remain substantially behind their US competitors, given that these methods can only be used to catch up at reduced time and cost.

AI distillation memo provides clearer picture of Chinese competitive threat

If “AI distillation” is an unfamiliar term, it is essentially making use of a larger more complex model to directly train a smaller and less sophisticated model via millions of queries that gradually suss out its assorted capabilities. Obviously AI developers would like to only do this in-house between model versions, but there is little stopping anyone from tapping into their work in this way save for cost and access controls.

The new memo suggests that pretty much all of the big names in Chinese AI are doing this to all of the big names in US AI. Some are more selective about who they target and what information they are probing for, possibly due to being less well-funded; the biggest ones, such as DeepSeek and Moonshot, seem to target all the leading models and collect all the information they can.

The danger of this is mostly to developers. While the Chinese firms cannot innovate this way, AI distillation does greatly help to reduce the cost and time needed to catch up to where US frontier models are at. As the memo notes, developers still do have an assortment of cards to play in bolstering their defenses. This could mean more stringent identity checks for premium subscriptions going forward, however, as the Chinese firms are reliant on maximal access to the AI models to make their methods work.

Chinese developers run massive cloaking operations to hide traffic origin

In addition to needing very heavy access to frontier models, the Chinese developers have to go to great lengths to disguise the origin of their traffic. The memo refers to these operations as “industrial scale” and using “billions” of tokens. This means “transfer stations” of proxies run to help obscure traffic, as well as individual users altering metadata. One element of this scheme that organizations (or even individuals) with premium subscriptions might watch out for is attempts to illicitly access them, particularly in the area of API access.

The memo briefly mentions that the Chinese government is likely at least aware of these AI distillation efforts, but does not delve into whether or not it is directly providing resources or assistance. It does trace the campaigns back to at least late 2024, when DeepSeek is thought to have begun running AI distillation against assorted US firms. Other Chinese developers came in from early to mid 2025.

While this does make it look like the Chinese firms have been playing catch-up for some time now, AI distillation does remain a substantial threat to US developers in terms of maintaining a competitive advantage. DeepSeek has already proven that a slightly lesser but still comparably capable model can be a real threat to undercut the market. AI developers have encountered numerous security issues in recent months that have yet to be fully addressed, and this will have to be added to the list.

While individual organizations are not particularly at risk from this, there is a relevant lesson to be taken: subscription plans, terms of service and even regional IP bans cannot be considered real security measures for preventing access when the attacker is fairly well-resourced, technically capable and determined.