Washington's complaint about Chinese artificial intelligence has a familiar shape: China is catching up by copying. Last week the FBI, the NSA and the Cybersecurity and Infrastructure Security Agency accused Chinese developers of "aggressive, malicious, and targeted distillation" of American frontier models, and Anthropic said startups including DeepSeek and Moonshot had quietly routed real user requests through its Claude models to harvest their reasoning. By Anthropic's count, Alibaba-linked distillation activity topped 151 million exchanges between May and July, Moonshot exceeded 23 million, and DeepSeek ran more than 12 million in a single fortnight. It is, the US says, industrial-scale theft. But a sharper reading, laid out this week in Foreign Policy, points to a twist Beijing may like even less: the copying could be leaking China's own secrets straight back to America.
The logic turns on what kind of data actually moves when one model distills another. To pull Claude's capabilities, a Chinese firm has to feed it a torrent of live queries, and those queries are not abstract. They carry the working context of real Chinese users: code that would not compile, engineering problems mid-solution, internal project descriptions, uploaded documents. Anthropic says some of what passed through included surveillance material from a user it suspected of People's Liberation Army ties, valid credentials from engineers at state-owned enterprises, and records from police case-management systems. One or two leaked files are a manageable embarrassment. Hundreds of thousands, aggregated, are something else.
Foreign Policy's Deng Yuwen calls this "intent data," and the label is worth pausing on. An ordinary web search reveals what a person wants to know. An AI conversation reveals what they are actually doing: the tools they use, the suppliers they depend on, the bottleneck they cannot get past. Pool enough of it across semiconductors, drones, aerospace and telecoms, and you do not get gossip. You get a slowly updating map of where a rival's industrial system is straining, and which labs are suddenly converging on the same hard problem. Fused with satellite imagery, customs records and patents that US agencies already hold, a single mundane query becomes one node in a very large graph.
That reframes the summit backdrop as Xi Jinping prepares to visit Washington. Beijing has spent years policing cross-border data transfers, with security assessments required before a company can ship a database abroad. But distillation is not a database export. It is a side channel, real user requests fed through proxy accounts into a foreign model, one call at a time, invisible to the rules written for an earlier era. If China's regulators missed it, Anthropic's report has exposed a genuine blind spot. If they knew, they tolerated it because the alternative was worse.
And that is the trap. Distillation is how Chinese firms have narrowed the gap so fast, and Stanford's latest index calls the model-quality gap "effectively closed." Shut the channel to protect national data, and the cost of keeping pace climbs; the technological lag could widen again. Leave it open, and the price of catching up is a steady outflow of exactly the industrial intelligence China most wants to guard. Washington frames AI security as a contest over who controls the frontier. This is a quieter question, and a harder one for Beijing: how do you borrow your rival's best tool without letting it read your hand while you do it?