News
Beijing Threatens Retaliation Over US Accusations of Mass AI Model Copying

China's Ministry of Commerce dismissed NSA, FBI and CISA accusations against six Chinese AI companies as baseless and threatened firm retaliatory measures if Washington uses the case to justify new restrictions.
Contents
The dispute over AI model copying between the United States and China is entering a new phase. A day after three US security agencies officially accused six Chinese companies of industrial-scale "distillation" of the Claude, GPT, Gemini and Grok models, Beijing responded with a threat of retaliation.
The joint NSA, FBI and CISA document from September 8 is the first such formal, interagency statement from the US government on the matter. Previously, similar accusations had come only from the companies themselves, mainly Anthropic. Washington has now elevated the dispute to a matter of national security.
What the US is alleging
The agencies described the Chinese companies' activities as "aggressive, malicious distillation at industrial scale," most likely carried out with the knowledge of the Chinese government. The six named entities allegedly systematically extracted restricted, proprietary features from leading US models, sending millions of queries and pulling billions of tokens from Claude, GPT, Gemini and Grok since late 2024.
Model distillation is a machine learning technique in which a smaller system is trained on the outputs of a larger, more powerful model. The method itself has legitimate uses and is widely applied across the industry, including by US companies to build lighter versions of their own products. The problem arises when it is used to build competing solutions in a fraction of the time and cost that went into the original model.
The agencies' recommendation to US AI companies is unusual: instead of blocking suspicious accounts, they propose quietly degrading response quality for accounts identified with high confidence as engaging in malicious distillation. This is meant to make it harder for attackers to detect the countermeasure and to extend the window for gathering evidence.
Beijing's response
China's Ministry of Commerce rejected the accusations just one day after they were announced. In an official statement, the ministry called model distillation a common and neutral method used by companies worldwide, including US tech giants.
If the American side takes action targeting Chinese AI companies under the pretext of fighting model distillation, China will take firm retaliatory measures - China's Ministry of Commerce (MOFCOM)
Beijing also raised the argument of double standards, pointing out that American companies themselves train their models on huge datasets scraped from the internet, often without the consent of content creators, while objecting when competitors from China use similar methods. The Chinese side also noted that Western labs use Chinese open-source models as a source of data and as benchmarks.
Context of earlier accusations
The dispute did not begin on September 8. As early as February 2026, Anthropic accused DeepSeek, Moonshot AI and MiniMax of creating thousands of fake accounts and making more than 16 million queries to Claude in order to gather data for training their own models. In June, the company went further, holding Alibaba responsible for nearly 29 million interactions with Claude using thousands of falsified customer accounts, which Anthropic CEO Dario Amodei described as an operation turning American investment into direct, illegal technological subsidies for geopolitical rivals.
The September advisory from the NSA, FBI and CISA differs from earlier accusations in that, for the first time, it is officially confirmed by the US government rather than just the affected company. The list of suspected entities also expanded to include StepFun and Z.AI, which Anthropic had not previously named directly.
What it means for the market
The dispute is unfolding at a time when Chinese open-source models are gaining real market share. Data from OpenRouter, a platform that aggregates traffic to AI models, shows that Chinese models have had higher usage than Western competitors for roughly 20 consecutive weeks. This reinforces the American narrative about a threat to its technological edge, but also explains why Beijing treats the case as a potential pretext for new trade or export restrictions, not just a technology dispute.
For companies and institutions using AI models in Poland and Europe, the escalation mainly signals growing regulatory uncertainty around Chinese vendors, whose open-source models, such as those in the Qwen and DeepSeek families, are increasingly used commercially due to their lower cost. The threat of US export restrictions or Chinese retaliatory measures could in practice affect the availability and pricing of these models beyond the United States and China as well.
The next thing to watch is whether Washington turns the agencies' warning into concrete action, such as new chip export restrictions or sanctions against the named companies. The threat of Chinese retaliation suggests that any such decision could trigger a response extending well beyond the AI sector itself.

