China called the US accusations unfair and asked for cooperation. The US advisory gives technical warning signs, but the named companies have not been judged by a court.
New to this? Read it in simple words
- China rejected US claims against six Chinese AI companies, including DeepSeek and Alibaba. It called the claims unfair and said the countries should work together on AI.
- US and allied security agencies say the companies secretly copied skills from US models. They claim millions of requests went through many accounts and services.
- Distillation is a common method and is often used with permission. The US says the problem was hidden access on a very large scale.
- The named companies have not been judged by a court. China’s denial also does not answer each technical claim.
- Distillation
- A way to train an AI model using the answers of another, often bigger, model.
China rejected the accusation
A Chinese Foreign Ministry spokesperson called the US claims unfair and asked the United States to stop what China described as unfounded attacks. The spokesperson also said the countries should work together on AI.
The response followed a joint notice from US and allied security agencies. That notice named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. It accused them of hidden efforts to learn from US frontier models.
The named companies were not judged by a court in the documents we reviewed. The Chinese government’s denial also does not answer each technical claim. Readers need to keep both limits visible.
The US advisory gives warning signs. China rejects the accusation. No court has judged the named companies.
Distillation can be normal or abusive
Model distillation teaches one AI model by using answers from another model. Companies often use it with permission to make a smaller or cheaper system. The method itself is common research and engineering work.
The US notice says the problem was hidden access at a very large scale. It alleges millions of requests through many accounts and services. The agencies call this malicious distillation because they say it avoided rules and copied protected skills.
The public notice gives warning signs and a broad picture. It does not publish every account record or show how each company directed the work. Some evidence may be private for security reasons, but that makes careful public language more important.
Evidence should guide the next step
AI providers can watch for strange request patterns and share security signals. They should also protect normal customers from unfair blocks. Heavy use, work from China, or interest in one topic is not proof of abuse by itself.
A stronger public case would connect technical records to named organisations and explain the level of confidence. The accused companies should have a clear chance to answer the detailed evidence. Legal review may also be needed.
The disagreement now includes technology, trade, and diplomacy. Cooperation may be difficult, but common rules for model access could reduce confusion. Until stronger public proof appears, the most accurate words are “US allegation” and “Chinese denial.”
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1Research · September 9, 2026China rejects US accusations over AI model distillation Associated Press
- 2Primary source · September 8, 2026NSA and others warn China-based AI companies are distilling US frontier AI models US National Security Agency
- 3Primary source · September 8, 2026China-based AI companies conduct malicious distillation against US frontier AI models NSA, FBI, CISA and partners
We used Associated Press for China’s response and the official US release and advisory for the allegations. We do not decide which government is correct. We distinguish ordinary model distillation from the hidden abuse alleged by US agencies.