China’s AI models are improving quickly, but it’s not all through innovation. Much of the progress is thanks to stolen American tech. On September 8, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA) and FBI, published a joint advisory warning that six Chinese AI companies are systematically extracting the capabilities of American frontier models through “industrial-scale knowledge distillation.” The advisory is a welcome step, but it places the onus for theft prevention on U.S. AI labs. For the United States to maintain its competitive edge in the AI race with China, the federal government must also play a role in deterring and punishing tech theft. Chinese AI Firms Were Caught Red-Handed Stealing American IP Distillation is the process where a smaller AI model is trained to copy the outputs of a larger, more advanced model. Distillation in and of itself isn’t illegal. In fact, it’s a common tactic used within AI labs and makes training new models easier and cheaper. It becomes problematic when it’s used against a competitor. According to the advisory, “DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of text fragments across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024,” likely with Chinese government awareness. The Chinese labs violated the terms of service of the American AI labs by creating thousands of fraudulent users and proxies to evade geographic restrictions and detection. Illegal distillation allows China to free ride on enormous American investments in AI. The federal government already has tools built to stop this behavior. The Department of Commerce maintains a list of companies that are “reasonably believed to be involved, or to pose a significant risk of being or becoming involved, in activities contrary to the national security or foreign policy interests of the United States” called the Entity List. The Chinese AI companies named in the advisory should be placed on this list, as Z.AI already has been. Alibaba is already on the 1260H list — companies identified as Chinese Military Companies — and many others, like MiniMax, are closely tied to companies that are. Putting a company on the Entity List means that the U.S. government restricts it from receiving American technology, goods, and software without a special license. The systematic extraction of proprietary U.S. technology by a foreign adversary qualifies as a significant risk to American national security. The U.S. Needs To Create Deterrence To close the gap between warning and deterrence, the government should act on several fronts. The Office of the Director of National Intelligence should ensure that economic espionage and distillation are specifically prioritized, which would allow more resources from the intelligence community to be dedicated to the topic. Second, criminal networks and technical infrastructure enabling distillation should be targeted. Chinese distillation efforts rely on massive networks of inauthentic or purchased accounts, as well as global residential proxy networks and other illicit tooling — similar to those used in influence and cyber operations. Taking down this infrastructure would degrade foreign capabilities to distill at scale and avoid detection. Third, Congress should reauthorize the Cybersecurity Information Sharing Act of 2015, and the federal government should expedite the intelligence declassification process to enable threat indicators to be shared, including accounts, IP addresses, and other infrastructure information to prevent distillation efforts before they begin. Finally, the government should build on this advisory, which calls for AI companies to “deploy targeted response changes” and downgrade outputs when they suspect malicious distillation. This is a start, but it is insufficient. U.S. AI firms should consider, after the appropriate legal and operational review, other methods to effectively deter distillation, including poisoning responses to pollute training data. Leah Siskind is director of impact and an AI research fellow for the Center on Cyber and Technology Innovation (CCTI) at the Foundation for Defense of Democracies (FDD). Ari Ben Am is an adjunct fellow at CCTI. For more analysis from Leah, Ari, and FDD, please subscribe HERE. Follow FDD on X @FDD and @FDD_CCTI. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.
Countering Chinese AI Distillation: The Case for Federal Action
Full Article
Original Source
Read the full article at Fdd →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.