Cyber Threat Intelligence, Entrepreneur, Presentation Virtuoso

China Did Not Steal American AI, It Interrogated It

NSA, CISA, and FBI accused six Chinese firms of extracting billions of tokens from Claude, ChatGPT, Gemini, and Grok to train competing models. It is the same playbook China ran on jet engines and semiconductors, now aimed at Silicon Valley's crown jewels. The theft looks exactly like ordinary use.
China Did Not Steal American AI, It Interrogated It

recently i wrote how chinese industrial espionage is not really traditional theft. it is a national strategy to skip the most expensive part of building an economy. steal the blueprint, avoid the decade of research and the insane r&d costs. this week the us government accused six chinese ai companies of doing exactly that to american ai, and the mechanism is almost poetic. they did not steal the models. they interviewed them.

nsa, cisa, and the fbi issued a joint advisory naming deepseek, moonshot ai, alibaba, minimax, stepfun, and z.ai. the accusation is that, likely with beijing's awareness, these firms extracted billions of tokens across millions of requests from american frontier models. claude, chatgpt, gemini, and grok, since late 2024, and used those outputs to train their own competing systems.

somehow i find this as unsurprising as the sunrise appearing every morning.

the technique used is known as distillation, and it is completely legit. every major ai lab does it, american startups included. basically, you take a big, expensive model and use its answers to train a smaller, less expensive one. it is a normal tool.

the accusation is not that they used the tool. it is that the chinese pointed their smaller model at someone else's larger model at an industrial scale. this is wholly against the terms of use, to strip out the exact capabilities costing the most to build. the reasoning. the agentic behavior. the parts that took billions of dollars and years to create.

this is ironic af if you stop and think about this for more than 12 seconds. american ai firms stole intellectual property from all across the internet, at an industrial level, and thought that was ok. but now that china is stealing what they stole, they somehow feel wronged. you cannot invent a better, more asinine story.

think about what this actually is. training a frontier model from scratch is one of the most expensive things a company can do. the compute alone is an insane investment. the research is brutal.

distillation lets you skip a massive portion of it. why spend three years and a fortune teaching a model to reason when you can ask a model that already reasons a few million questions and train on its homework? the advisory's own words are the sharpest. distillation was not a supplement to these companies' development. it was the critical core of it.

this is the china playbook all over again, and should surprise absolutely no one. china does this for pretty much every market they want to enter.

do not pay for the invention. acquire the result. it worked with jet engines, semiconductors, and pharmaceuticals. now it is running against the single most expensive thing silicon valley is building nowadays. the target changed. the strategy did not. why fund the research when you can copy the finish line?

there is a detail here worth appreciating, because it says something about where security is going. us model usage is banned in china. per the advisory, the firms allegedly used fraudulent accounts, vpns, proxies, and automated agents to reach the american models, routing through relay servers outside of mainland china to hide who was querying those models.

the theft, if it even can be considered theft, does not look like a breach. it looks like a very large number of normal conversations. they deliberately spread those conversations across providers, accounts, proxies, and cloud platforms so no single company can see the entire operation. this is not just model theft. it is distributed collection. each provider sees a handful of questions. only the adversary sees the dataset being assembled.

that is the whole problem. how do you stop someone from stealing your model when the method of stealing it is just everyday use of of it?

there is one thing to remember. these are accusations from the us government at this juncture, and china has pushed back. distillation is genuinely a gray area. the line between legitimate learning and industrial theft is real but blurry. the advisory is a political document as much as a technical one.

i said the same thing about attribution not too long ago. the confident public naming is not the end of the story. but the underlying pattern, using a rival's finished product to skip the cost of building your own, is the most well-documented move in the entire history of chinese industrial strategy, so the accusation lands quite securely on very familiar ground.

the us is now talking sanctions and entity list designations, and telling its own labs to quietly feed degraded answers to suspected distillers rather than ban them. read that again. the apparent defense against having your model copied is to quietly make its answers less useful to the copier.

and how do these models know the account conducting the querying is legit vs a distiller? normal users will undoubtedly get caught up in these shenanigans, should the startups opt for such defensive measures.

we have reached the point where ai companies are being advised to poison their own outputs to protect them. the model is the crown jewel, the factory, and the battleground all at once.

you do not need to steal the thing anymore. you just need to ask it enough questions, and the most valuable machines america has built will answer every one of them, politely, until they have taught a rival how to build a better one.

ask the laggard american auto industry how this ends. they watched china copy the electric car. then watched byd pass them and take the lead. copying is not the finish line. sometimes it is the starting line for someone who runs faster than you.