The timing is pointed. The accusations came weeks before a planned Trump-Xi summit, adding friction to an already tense bilateral agenda. The targeting is specific: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.ai are accused of extracting knowledge from U.S. models. The U.S. agencies named included the NSA, FBI, and CISA—not the Commerce Department. That choice signals national security classification, not just trade dispute.
The White House had already accused Moonshot of distilling Anthropic's Fable model in July, alleging the company created a sophisticated internal platform for industrial-scale extraction while rapidly switching access methods to avoid detection. The September 8 joint statement escalated the accusation to a multi-agency level, naming a broader set of targets.
Distillation: The Standard Practice That Became a Crime
Model distillation is not secret. It's a widely used optimization technique where a smaller model learns from a larger one's outputs. It is the same method Anthropic, OpenAI, and Google use to refine their own models. NVIDIA CEO Jensen Huang described the practice as analogous to how "human knowledge transmission is a never-ending process of mutual distillation."
The U.S. agencies are not arguing that distillation itself is illegal. Their accusation is that the named companies conducted unauthorized extraction and deliberately bypassed access restrictions. But the distinction is hard to verify from the outside—especially when many U.S. companies also distill Chinese models.
The Chinese Response: "Many U.S. Companies Do It Too"
China's Ministry of Commerce responded to the July threats by noting that "many U.S. AI companies distill Chinese models during research and training." The ministry called the U.S. approach "a typical example of AI hegemony" and accused Washington of applying a double standard.
The statement also noted that nearly 200 U.S. startups have urged the U.S. government not to cut off access to Chinese open-source AI models, warning that such restrictions would "weaken the competitiveness of U.S. companies." Some U.S. multinationals have also described distillation as a widely used industry practice.
China's patent filings add weight to its argument. According to World Intellectual Property Organization data, Chinese inventors accounted for nearly 77% of global generative AI patents in 2024 and 2025. For every four AI patents globally, three come from China. The accusation that China relies on "stealing" U.S. knowledge is difficult to square with that output.
What the Startups Are Saying
More than 200 Silicon Valley startups have signed letters urging the White House not to block access to Chinese open-weight models. Their argument is not political. It's survival. Chinese models are cheap, capable, and open-source. Cutting off access would raise costs for startups that cannot afford Anthropic's or OpenAI's API fees. Particle founder Suhail Doshi warned that a ban would kill hundreds of companies overnight.
The startup coalition is directly challenging the big AI labs that are lobbying for restrictions. OpenAI has been pushing harder for curbs on Chinese models, while Anthropic has accused Moonshot of using fraudulent accounts to generate over 3.4 million exchanges with its Claude models. The divide is clear: established U.S. labs want protection; U.S. startups want access.

The Geopolitical Frame: AI as the New Semiconductor
The distillation accusations mirror the semiconductor ban playbook. The U.S. restricted advanced chips. When that didn't stop China's AI progress, it shifted to the training method itself. The target is no longer just hardware. It's the process that turns model knowledge into capability.
If China's AI progress is "the result of high-level technological self-reliance," as the Foreign Ministry stated, then the U.S. is attempting to restrict a process it cannot fully define—and one that many of its own companies use.
P.S. The quiet signal in the U.S. complaint: The agencies did not claim China stole code. They claimed China used the outputs of U.S. models to improve its own. That is the same method Meta uses to train Llama from its own data. If distillation is theft, then much of the open-source AI ecosystem is built on stolen knowledge. That would make the accusers complicit in the very practice they are trying to criminalize.
Frequently Asked Questions
Q: What is model distillation?
A: Model distillation is a technique where a smaller AI model learns from the outputs of a larger, more powerful model. It is a standard industry practice used by both U.S. and Chinese AI companies to improve efficiency and reduce costs.
Q: Which Chinese companies were accused?
A: The U.S. agencies named DeepSeek, Moonshot AI (Kimi), Alibaba, MiniMax, StepFun, and Z.ai (Zhipu).
Q: What U.S. agencies made the accusation?
A: The NSA, FBI, and CISA issued the joint statement on September 8, 2026. The involvement of intelligence and security agencies signals national security classification, not just trade dispute.
Q: What was China's response?
A: The Foreign Ministry said China's AI development is "the result of high-level technological self-reliance." The Ministry of Commerce noted that "many U.S. AI companies distill Chinese models too" and called the U.S. approach a double standard and a form of "AI hegemony."
Q: How do U.S. startups view this?
A: Nearly 200 U.S. startups have urged the U.S. government not to cut off access to Chinese open-source models, warning that doing so would raise costs and weaken U.S. competitiveness. Some founders said a ban could kill hundreds of companies overnight.
Q: When did this start?
A: In July 2026, the White House first accused Moonshot AI of distilling Anthropic's Fable model. On September 8, 2026, the NSA, FBI, and CISA escalated the accusation to a multi-agency level naming six companies.
Q: What is the significance of the timing?
A: The accusation came weeks before a planned Trump-Xi summit, potentially adding tension to bilateral AI dialogue negotiations.
Q: How does China's AI patent output compare?
A: Chinese inventors accounted for nearly 77% of global generative AI patents in 2024 and 2025, according to WIPO data. For every four AI patents globally, three come from China.
Q: What is the "teacher-student" model concept?
A: In distillation, a more capable "teacher" model trains a smaller "student" model. The technique can make AI cheaper to run while preserving much of the larger model's capability.
Q: Could distillation become a trade war trigger?
A: German media have warned that the U.S. accusations could trigger "the first U.S.-China AI trade war." The Chinese Ministry of Commerce has stated it will take "all necessary measures" to defend its interests against any actions that substantially harm China's interests.
