
China has rejected American allegations that leading Chinese AI companies engaged in “aggressive, malicious” distillation of US models. The Associated Press reported on 9 September 2026 that a joint advisory from the FBI, NSA and CISA accused companies including DeepSeek, Alibaba, Moonshot AI and Z.ai of extracting capabilities from systems such as OpenAI’s GPT and Google’s Gemini since at least late 2024.
China’s Commerce Ministry called the claims groundless and accused the United States of attempting to monopolise artificial intelligence. The allegations have not been judicially established. That distinction is essential: this is a contested government claim inside a wider strategic rivalry, not a settled finding of liability.
What model distillation actually means
Distillation is a technical method in which a smaller or specialised model learns from the outputs or behaviour of a more capable system. A teacher model may generate examples, labels or probability patterns that help train a student model. Developers use the method to reduce cost, improve speed or transfer performance into a different product.
Distillation is not automatically malicious. A company may distil its own model, use a teacher with permission or learn from openly licensed outputs. The ethical and legal problem depends on how access was obtained, what contractual restrictions applied, how much was extracted and whether protected material or security controls were bypassed.
The boundary between use and extraction
Ordinary users ask a model questions and learn from the answers. Researchers compare systems. Companies test compatibility. At scale, however, millions of strategically designed queries can map a system’s behaviour and create training data for a competitor. The same interface can therefore support ordinary use or industrial extraction.
The American advisory reportedly alleges bulk premium subscriptions, violations of user agreements and coordinated collection. Those details would matter if supported by evidence. Terms-of-service violations are not automatically equivalent to theft, while circumventing access controls may engage different law. Public debate should avoid collapsing contract, copyright, trade secrets and cybersecurity into one dramatic word.
Five tests for responsible distillation
- Authority: Did the teacher-model provider permit the intended training or benchmarking use?
- Access: Were accounts, rate limits, identity controls or technical safeguards bypassed?
- Material: Did the process collect ordinary answers, confidential information, protected expressions or hidden system behaviour?
- Substitution: Was the student designed to replace the paid service by copying its distinctive value?
- Transparency: Can the developer identify its sources, methods and restrictions without misleading users?
These tests will not answer every case, but they separate legitimate research from concealed extraction more carefully than nationality alone.
Open models complicate the argument
The United States has its own disagreement about access. MaryChuks reported NVIDIA’s warning against suppressing open-weight models. Open releases allow researchers and smaller companies to adapt technology without querying a closed provider, but licences may still restrict certain uses.
A world in which every useful learning method is treated as proprietary could entrench the largest laboratories. A world with no enforceable access rules could make expensive research impossible to finance and reward actors that ignore consent. Policy must protect competition and legitimate learning while recognising genuine investment and security risk.
Why this is now geopolitics
The named companies are central to China’s AI ambitions. DeepSeek’s reported IPO preparation shows how technical reputation is becoming financial value. Moonshot’s Kimi K3 has also strengthened the argument that Chinese laboratories can compete internationally.
American officials view advanced AI capabilities as national-security assets. Chinese officials frame restrictions as an attempt to preserve US dominance. Once model outputs become strategic resources, subscription accounts, API limits and training methods are interpreted through the same lens as chips and export controls.
Creators should pay attention
The dispute resembles the question facing journalism, books and music: when does learning from existing work become unlicensed appropriation? MaryChuks examined this conflict in the journalism lawsuits against AI companies. Model developers now find themselves making an ownership argument similar to the one creators have made about training data.
That symmetry should produce better rules. A laboratory that demands protection from industrial output extraction should be prepared to explain how it respects the rights of people whose work trained its own systems.
The governance gap
International rules have not caught up with model-to-model learning. Governments could require providers to publish permitted research uses, create secure licensing routes for high-volume distillation and disclose when a commercial model was substantially trained on another system’s outputs. Independent technical evidence should precede sanctions or sweeping accusations.
The MaryChuks position
Distillation is a valuable engineering method, not a nationality-based wrongdoing. The line is crossed through unauthorised access, deceptive collection, protected material or systematic substitution—not because one machine learned from another. The US–China dispute should become an opportunity to define evidence-based rules that apply consistently to laboratories, governments and creators.
Primary CTA: Subscribe to the MaryChuks AI Ethics briefing for balanced analysis of model access, ownership and global technology policy.
Discussion question: If AI companies can learn from public human work, under what conditions should another AI company be allowed to learn from their outputs?
Source
- Associated Press: China rejects US claims of malicious AI distillation, 9 September 2026. The allegations and denials should be reported as competing claims unless supported by independently tested evidence.
Discover more from Marychuks.com AI, Psychology, Business & CreativeVerse
Subscribe to get the latest posts sent to your email.