FBI and NSA Accuse Chinese AI Firms of ‘Industrial-Scale’ Model Distillation

US intelligence and cybersecurity agencies have accused several Chinese artificial intelligence companies of carrying out large-scale campaigns to extract knowledge from leading American AI models.

The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) said the activity involves what they describe as malicious model distillation targeting advanced US-developed AI systems.

The agencies identified leading AI models including ChatGPT, Claude, Gemini and Grok as among the systems allegedly targeted by the campaigns.

According to the US agencies, the activity has been taking place since at least 2024 and has involved millions of requests directed at AI services.

Rather than relying on a single account or access point, the alleged operations reportedly used a broad network of accounts, application programming interfaces (APIs), proxy services, cloud infrastructure and third-party aggregators.

The agencies described the activity as an “industrial-scale” effort, suggesting that the alleged data collection was conducted systematically and at significant volume.

Model distillation is a technique in artificial intelligence development in which a smaller or less capable model learns from the outputs of a more advanced model. The process can allow developers to reproduce some capabilities of a larger system without training an equivalent model entirely from scratch.

Distillation itself is a legitimate AI research and development technique. However, the US agencies are specifically alleging that the Chinese firms used unauthorized or malicious methods to obtain large quantities of outputs from American AI systems.

The alleged use of multiple accounts, APIs, proxies and cloud services could make it more difficult for AI companies to identify and stop unusually large-scale access. Third-party aggregators can also provide additional routes through which AI models may be accessed.

The accusations add another layer to the growing technological competition between the United States and China. Both countries are investing heavily in artificial intelligence, while US technology companies continue to develop increasingly capable models.

For American AI companies, the alleged activity raises concerns about intellectual property, competitive advantages and the security of advanced AI technologies.

The agencies’ warning also highlights the importance of monitoring how AI models are accessed. Companies operating advanced AI systems increasingly use restrictions, monitoring systems and other safeguards to detect unusual usage patterns.

The accusations involving ChatGPT, Claude, Gemini and Grok are significant because these models represent some of the most prominent AI systems developed by US technology companies.

The US agencies said the alleged activity has involved millions of requests since at least 2024. The scale described in the assessment suggests that the issue extends beyond isolated attempts to obtain AI-generated information.

The development is likely to intensify discussions about AI security and the protection of advanced models as the technology becomes increasingly important to businesses, governments and national security.

The allegations also demonstrate how competition in artificial intelligence is increasingly extending beyond simply building better models. Access to training data, computing infrastructure, model outputs and proprietary technology has become an important part of the global AI race.

The claims made by the FBI, NSA and CISA represent the US government’s assessment of the activity. The allegations should therefore be distinguished from independently established findings about every company or individual potentially involved.

As governments and technology companies continue to strengthen AI security measures, preventing unauthorized large-scale extraction of model capabilities is expected to remain an important challenge for the industry.