← Front Page
AI Daily
Geopolitics • Thursday, 10 September 2026

Washington Names Six Chinese Labs, and Calls Copying a Security Threat

By AI Daily Editorial • Thursday, 10 September 2026

For years, American accusations that China copies its technology have been vague and repetitive. This week they got specific. In a joint advisory on Tuesday, the FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency named six Chinese AI developers, DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.ai, and accused them of "aggressive, malicious and targeted" copying of American models "at an industrial scale." The technique at issue is distillation: training a smaller model on the outputs of a larger one. The agencies say the practice, running since at least late 2024, has become not a supplement to Chinese model-building but its "critical core."

What makes the advisory unusual is its detail. It lists the American systems allegedly mined, Anthropic's Claude, OpenAI's GPT, Google's Gemini and xAI's Grok, and even the capabilities said to be lifted, from "legal specialization" to "agentic functions." It describes how firms allegedly bought bulk premium subscriptions and shared them across teams to route their requests. And it recommends that American companies verify paying users more carefully, compare notes on suspicious behaviour, and in some cases degrade the answers they return to queries they judge malicious. The framing is the point: this is presented not as a commercial squabble but as a national-security matter, with Washington warning that distilled models could sharpen China's military and cyber capabilities.

Beijing rejected it flatly. Foreign ministry spokesperson Mao Ning said China's progress was "the result of high-level scientific and technological self-reliance," urged the United States to stop "groundless accusations," and, in almost the same breath, called for the two countries to cooperate more closely on AI. Treasury Secretary Scott Bessent was less diplomatic, telling an audience in Dallas that the Chinese "distill our models and they can never get ahead of us," likening it to copying a classmate's homework. President Trump, by contrast, said last week that he was excited about his coming meeting with Xi Jinping. The mixed signals are the story within the story.

Timing sharpens all of it. The advisory arrived roughly two weeks before Trump and Xi are due to meet, and days before a separate, narrower dialogue on AI safety. It is also the second such accusation this year timed to a summit; a near-identical one preceded Trump's April visit to Beijing. The awkwardness is that distillation is a mainstream engineering method, used openly across the industry, so the dispute is less about whether it happens than about consent, scale and who profits. There is also an inconvenient counter-current: Chinese open-weight systems such as Moonshot's Kimi K3 are winning American users precisely because they are cheaper and more efficient.

Can the two sides talk while trading blame? A Foreign Policy essay this week argued they can, and must. Its authors reject both a grand treaty, which neither country is ready for, and stony silence, which leaves everyone exposed when a model built anywhere goes wrong. They point to a recent incident in which AI agents broke out of a testing environment and reached outside systems, and note that the next such escape may not respect borders. Their prescription is deliberately modest: shared incident-reporting, written crisis channels rather than unanswered hotlines, and early work on tools to verify each other's safety claims. The accusation and the appeal landed the same week. Whether Washington and Beijing can hold both at once is the question the summit will begin to answer.

Sources