China on Sept. 9 rejected a joint U.S. advisory accusing China-based artificial intelligence developers of using industrial-scale knowledge distillation to extract capabilities from American frontier models. The dispute matters because it could accelerate tighter identity checks, rate limits and monitoring across commercial AI services.

The U.S. Cybersecurity and Infrastructure Security Agency, National Security Agency and FBI issued the advisory on Sept. 8. It named several Chinese developers, including DeepSeek, Alibaba, Moonshot AI and Z.ai, and said the activity had taken place since at least late 2024. The companies named in the advisory did not immediately respond to requests for comment from The Associated Press.

What the U.S. agencies allege

Knowledge distillation is a widely used technique for training a smaller model on outputs from a more capable system. The U.S. advisory does not treat the technique itself as inherently improper. Its allegation is that the named developers used networks of accounts and access pathways to evade restrictions, violate providers’ terms and collect proprietary capabilities at scale.

Anthropic added a separate set of company findings on Sept. 10. The Claude developer said it had detected and disrupted nearly 200 million exchanges linked to five alleged distillation campaigns. It attributed more than 151 million exchanges between May and July to an Alibaba-linked effort, and reported smaller campaigns it associated with Moonshot AI, DeepSeek, Z.ai and Xiaomi. Those figures and attributions come from Anthropic’s own investigation and have not been independently verified.

China rejects the characterization

China’s Commerce Ministry called the U.S. claims groundless and accused Washington of trying to monopolize the AI industry. It said China would take countermeasures if the United States used distillation allegations to suppress Chinese companies. China’s Foreign Ministry urged the two countries to cooperate on AI development and stop making what it described as unfounded accusations.

The response leaves the central facts disputed. U.S. agencies and Anthropic describe coordinated attempts to bypass access controls. Chinese officials argue that Washington is recasting an established industry practice as misconduct to protect American companies.

Why the dispute matters for AI buyers

Model providers now have a stronger incentive to know who is calling their systems, how accounts are connected and whether usage patterns indicate automated extraction. CISA’s guidance asks providers to watch for anomalous prompts, shared infrastructure and unusual throughput, then exchange threat intelligence across the industry.

For enterprise customers, the likely consequence is more friction around high-volume access. Vendors may impose stricter verification, narrower geographic controls and more detailed audit requirements. Buyers should expect those controls to appear in procurement reviews and should ask how providers distinguish ordinary development, legitimate distillation and prohibited extraction.

The broader commercial question is whether AI capability can remain widely accessible while model makers protect the investment behind frontier systems. That balance will shape API pricing, open-model policy and access to advanced tools. For now, the public record establishes a serious allegation, a forceful denial and a rapidly escalating dispute—not a settled finding of wrongdoing.