CISA, NSA, and FBI allege China-based AI labs ran industrial-scale campaigns to extract frontier model capabilities. Anthropic says it disrupted seven such campaigns targeting Claude.
US cybersecurity and intelligence agencies — CISA, the NSA, and the FBI — allege that China-based AI companies have run "industrial-scale" knowledge-distillation campaigns against American frontier-model providers, according to a joint advisory. The claim: coordinated efforts to use model outputs as training material to extract proprietary capabilities from US AI systems — not routine evaluation, but systematic capability theft.
The concern is technically real. Distillation can turn a more capable model's outputs into training data for a competing system, potentially compressing the time and cost needed to reproduce advanced behaviors like coding assistance, data analysis, or multi-step reasoning. But it's important to be precise about what's confirmed: the advisory describes an allegation, not a demonstrated technical outcome. It doesn't establish how much capability was actually transferred, whether any resulting system reached parity with US frontier models, or verify every company named in related coverage participated.
This is where it gets more concrete: Anthropic says it independently disrupted illicit distillation activity attributed to seven China-based labs, targeting Claude's capabilities in agents, software development, data analysis, and reasoning. That's a real, first-party account from a company that says it was directly targeted — giving the government's broader allegation a specific, corroborating example. TechRadar reports the advisory names companies including DeepSeek and Alibaba, describing billions of tokens and millions of interactions with US frontier systems — though that should be read as reporting on the allegation, not independent proof of each company's involvement.
Providers are already responding like it's a genuine security threat. Anthropic says Claude Opus 5.5 introduced "preserved-thinking" protections specifically to make large-scale extraction of model reasoning harder — treating systematic capability extraction as its own security category, alongside more familiar concerns like unauthorized access and misuse.
Bottom line: This is a serious, credible warning backed by both a joint government advisory and a named company's own disruption account — not a claim that any Chinese lab has successfully replicated a US frontier model. The stronger version of this story — quantifying what was actually extracted, and how close any resulting system got — would need independent technical evaluation that hasn't been published yet.
The claim: coordinated efforts to use model outputs as training material to extract proprietary capabilities from US AI systems — not routine evaluation, but systematic capability theft.
But it's important to be precise about what's confirmed: the advisory describes an allegation, not a demonstrated technical outcome.
It doesn't establish how much capability was actually transferred, whether any resulting system reached parity with US frontier models, or verify every company named in related coverage participated.
Continue reading