China’s government has formally rejected accusations from Washington that Chinese artificial intelligence firms are running industrial-scale campaigns to copy capabilities from American frontier AI models. The latest round of the dispute broke into public view on September 8, 2026, when Reuters reported that U.S. officials accused Chinese AI companies of “malicious” copying of American AI technology, and China’s Ministry of Commerce fired back the same day, saying the claims lacked factual and legal grounding. India Today and the Associated Press both carried follow-up reports on September 9 detailing Beijing’s rejection of the allegations, which named OpenAI, Google, and Anthropic as the U.S. companies whose systems were allegedly targeted.
The technical term at the center of the fight is distillation, a widely used machine learning technique where a smaller or newer model learns by studying the outputs of a larger, more capable one. It’s a legitimate method used across the AI industry, including inside U.S. labs. The dispute isn’t over whether distillation exists. It’s over whether Chinese firms are using it, at scale and without authorization, to strip the value out of billions of dollars in U.S. training investment.
What the U.S. is actually alleging
According to Reuters’ September 8 report, the White House and allied officials have accused Chinese AI companies of running what they describe as industrial-scale efforts to extract knowledge from leading American AI systems by repeatedly querying them and harvesting the outputs, then using that data to train competing models. China’s commerce ministry responded the same day, calling distillation a neutral technical method in nature and accusing the U.S. of double standards, interference in normal commercial activity, and trying to suppress competition, per Reuters.
This isn’t a new accusation dressed up for a slow news week. Anthropic laid much of the groundwork back in February 2026, when it published a blog post alleging that DeepSeek, MiniMax, and Moonshot AI had generated more than 24,000 fake accounts and racked up over 16 million interactions with Claude models to harvest training data, according to CNN’s February 24 coverage. By July, the fight had escalated further. Reuters reported on July 31 that Anthropic accused Chinese entities including DeepSeek, Moonshot, and MiniMax of conducting large-scale campaigns to obtain capabilities from Claude, specifically targeting software engineering and advanced reasoning skills, and that OpenAI said it had also detected Chinese actors attempting similar extraction against its own models.
A separate strand of the story, also reported by Reuters on July 31, found that Chinese military researchers had used outputs from OpenAI and Anthropic models to train domestic defense-related AI systems, based on a review of more than 80 Chinese academic papers. That detail is what turned a corporate IP dispute into a national security story, and it’s likely why the White House got directly involved rather than leaving the fight to the AI companies themselves.
Beijing’s rejection, point by point
China has not been quiet about any of this. Chinese Foreign Ministry spokesperson Guo Jiakun addressed the theft allegations directly at a press briefing, saying “the U.S. claims are entirely baseless,” and calling them “a slanderous smear against the achievements of China’s artificial intelligence industry,” according to the Straits Times. Guo added that “China firmly opposes this,” a line that has been repeated across multiple Chinese government statements on the topic since April 2026, per the same report.
The most detailed rebuttal came from Assistant Chinese Foreign Minister Liu Bin, who addressed the distillation controversy directly at the World AI Conference in Shanghai. Liu said “some countries hype up distillation” and called the U.S. framing “misguided and counterproductive,” according to Bloomberg Law’s July coverage of his remarks. Those comments came just days after Anthropic’s allegation that a lab linked to Alibaba’s Qwen project had run roughly 28.8 million queries against Claude using around 25,000 fake accounts, per AIWeekly’s reporting on the same conference.
China’s Ministry of Commerce escalated its own language on July 27, when it accused the United States of what Reuters described as “AI hegemonism” and threatened unspecified countermeasures after U.S. officials floated investigations, sanctions, and trade restrictions targeting Chinese AI firms. The Center for Security and Emerging Technology at Georgetown University, which tracks and translates Chinese government statements on AI policy, published the full MOFCOM statement, noting it was Beijing’s first direct government-level response to the distillation accusations and that it simultaneously argued distillation is common practice inside the U.S. as well as China.
The Moonshot AI and Kimi K3 flashpoint
One thread of this story has a named product attached to it. Tech Times reported on July 28 that the dispute over whether Moonshot AI’s Kimi K3 model was built by distilling Anthropic’s technology turned what had been a company-to-company allegation into a full government-to-government confrontation, after Washington moved to target Moonshot with sanctions threats. China’s Ministry of Commerce issued its first official statement in direct response to that action, branding the U.S. sanctions push as protectionist rather than a legitimate IP enforcement measure.
It’s worth separating what’s confirmed from what’s alleged here. No court or regulator has ruled that Kimi K3 or any other named Chinese model was built through unauthorized distillation of a U.S. system. What’s confirmed is that Anthropic made the accusation publicly, that the White House used it as a basis to threaten trade action, and that Beijing rejected both the underlying claim and the proposed response. The technical question of how much any specific Chinese model actually owes to querying a U.S. competitor is not something outside researchers have independently verified with public evidence.
Why this is happening now
The timing lines up with a broader diplomatic calendar. CNBC reported on September 5, citing Reuters sources, that the U.S. and China are gearing up for AI safety talks planned for mid-September 2026, and that Washington intends to raise the distillation allegations directly in those discussions. The same report noted that U.S. officials are also worried about the prospect of a future Chinese model reaching what they call “Mythos-level” capability in cyberattack-relevant tasks, tying the distillation fight to a broader concern about offensive AI capability diffusion rather than just commercial IP loss.
That framing matters for how the story should be read. This isn’t purely a trade dispute over who gets to profit from a chatbot. U.S. officials are treating distillation as a pathway by which capabilities developed under billions of dollars of compute investment, and under U.S. export controls on advanced chips, could end up inside Chinese military and intelligence-adjacent systems anyway, just through the software layer instead of the hardware layer.
By late September those talks had happened, though not as a standalone distillation summit. Reuters reported that U.S. Treasury Secretary Scott Bessent and Chinese Vice Premier He Lifeng met in New York on September 20, 2026, and that by September 21 the two sides had agreed to establish a formalized U.S.-China AI dialogue, including an incident-notification line for serious AI-safety incidents, with senior officials expected to meet again roughly two months later in Shenzhen. The available reporting does not describe a joint statement specifically resolving the distillation allegations, which fits the pattern of continued dialogue rather than a binding enforcement agreement.
The companies named, and what each has said
The roster of companies pulled into this dispute has grown steadily since Anthropic’s initial February accusation. Below is a summary of the named parties and the specific claims tied to each, based on the sourcing collected above.
| Company / Entity | Role in the dispute | Key claim | Source |
|---|---|---|---|
| Anthropic | U.S. accuser | Alleged DeepSeek, MiniMax and Moonshot used 24,000+ fake accounts, 16M+ Claude interactions (Feb 2026) | CNN |
| OpenAI | U.S. accuser | Said it detected Chinese actors attempting distillation-style extraction of its models | Reuters |
| Named U.S. target | Named alongside OpenAI and Anthropic as a targeted U.S. AI developer | India Today, Reuters | |
| DeepSeek | Accused Chinese firm | Named in Anthropic’s original distillation allegation | CNN |
| MiniMax | Accused Chinese firm | Named in Anthropic’s original distillation allegation | CNN |
| Moonshot AI | Accused Chinese firm | Kimi K3 model tied to distillation dispute; targeted by U.S. sanctions threat | Tech Times |
| Alibaba (Qwen) | Accused Chinese firm | Alleged to have run roughly 28.8M queries against Claude via 25,000 fake accounts | AIWeekly |
| China’s Ministry of Commerce | Chinese government response | Rejected claims as lacking factual/legal basis; accused U.S. of “AI hegemonism” | Reuters, CSET Georgetown |
| Chinese Foreign Ministry | Chinese government response | Called allegations “entirely baseless” via spokesperson Guo Jiakun | Straits Times |
Timeline: how the distillation dispute escalated
The public record on this fight now spans roughly seven months, moving from a single company’s blog post to a formal diplomatic flashpoint ahead of scheduled bilateral AI safety talks.
| Date | Event | Source |
|---|---|---|
| February 24, 2026 | Anthropic publishes blog post alleging DeepSeek, MiniMax and Moonshot used fake accounts to harvest Claude outputs | CNN |
| April 23-24, 2026 | White House accuses Chinese entities of “industrial-scale” AI technology theft; China calls the claim baseless the next day | Straits Times |
| July 18, 2026 | Assistant Foreign Minister Liu Bin dismisses distillation claims at World AI Conference in Shanghai | Bloomberg Law |
| July 27, 2026 | China’s Commerce Ministry accuses U.S. of “AI hegemonism,” threatens countermeasures over sanctions threats | Reuters |
| July 28, 2026 | Dispute over Moonshot AI’s Kimi K3 becomes a formal government-to-government confrontation | Tech Times |
| July 31, 2026 | Anthropic and OpenAI detail distillation allegations against DeepSeek, Moonshot, MiniMax; Reuters reports Chinese military use of U.S. model outputs | Reuters |
| September 5, 2026 | CNBC reports U.S. and China preparing for mid-September AI safety talks; distillation to be raised directly | CNBC |
| September 8-9, 2026 | U.S. accuses Chinese firms of “malicious” copying; China’s Commerce Ministry rejects claims same day; India Today, AP cover Beijing’s response | Reuters, India Today, AP |
| September 20-21, 2026 | U.S. Treasury Secretary Bessent and Chinese Vice Premier He Lifeng hold economic talks in New York; the two sides agree to set up a formal U.S.-China AI dialogue with an incident-notification line, with a follow-up meeting planned in Shenzhen in about two months | Reuters |
What distillation actually is, and why it’s hard to police
Model distillation is not inherently sketchy. It’s a standard compression technique: a smaller “student” model is trained to mimic the outputs of a larger “teacher” model, often to cut inference costs while keeping most of the teacher’s capability. Every major AI lab, American and Chinese alike, uses some form of distillation internally to ship cheaper, faster versions of flagship models.
What turns it into an accusation of theft is the target and the method. Anthropic’s claim isn’t that Chinese labs distilled their own models. It’s that Chinese labs allegedly used automated accounts to query a competitor’s closed, paid API at massive scale specifically to harvest outputs and reconstruct comparable capability without paying for the underlying training compute or the API access terms typically license. That’s functionally similar to how the U.S. software industry has treated large-scale scraping of proprietary services in other contexts, but AI has no settled legal framework for it yet, which is exactly why the fight has ended up as a government-to-government dispute rather than a lawsuit.
China’s counter-argument, laid out most clearly in the MOFCOM statement CSET Georgetown translated, is that distillation is simply too common and too foundational to machine learning to selectively criminalize when Chinese firms do it. Beijing’s framing treats the U.S. campaign as an attempt to use IP language to justify what is, in practice, an effort to slow down Chinese AI progress after export controls on advanced chips failed to fully contain it.
Market and competitive impact
For U.S. AI labs, the distillation fight cuts at something more fundamental than reputation. Anthropic, OpenAI, and Google have each poured tens of billions of dollars into training compute for their flagship models, and the entire commercial case for charging premium API prices rests on the assumption that a rival can’t cheaply replicate 80-90% of that capability by querying the finished product instead of training from scratch. If regulators can’t stop that behavior, the return on frontier training investment shrinks for everyone, not just the company being copied.
For Chinese labs, the stakes run the other direction. DeepSeek, MiniMax, and Moonshot AI have each built commercial and international credibility partly on claims of independent, cost-efficient model development. Public accusations of wholesale copying, even unproven ones, chip away at that story with enterprise customers outside China who are weighing whether to adopt Chinese open-weight models for cost reasons. Sanctions threats tied to a specific product, like the Kimi K3 case, also raise the practical risk that a Chinese lab’s access to U.S. cloud infrastructure or chips could be curtailed as a penalty, independent of whether a court ever adjudicates the underlying IP claim.
There’s also a compute-market angle. If Washington moves from accusation to actual export or sanctions enforcement tied to distillation claims, that adds a new axis of risk to the existing chip export control regime, on top of already-tight GPU supply. Any additional restriction raises uncertainty for the global AI hardware market at a moment when memory and GPU shortages are already squeezing capacity on both sides of the Pacific.
Historical context: this isn’t the first US-China tech IP fight
The shape of this dispute will feel familiar to anyone who followed the U.S.-China trade fights over telecom equipment, semiconductors, or industrial manufacturing over the past decade. What’s different with AI distillation is the mechanism: there’s no factory to inspect, no chip design to reverse-engineer under a microscope. The alleged theft happens through an API, using the product exactly as it was designed to be queried, just at a scale and pattern that looks automated rather than human.
That makes enforcement genuinely harder than past IP disputes. A semiconductor design theft case can point to a specific leaked schematic. A distillation case has to prove a pattern of usage was intentionally extractive rather than legitimate high-volume commercial use, which is a much fuzzier bar, and one neither side has fully defined in public. The current dispute is effectively the first major test of whether “training data provenance” becomes a governable category in the same way patents and trade secrets are, or whether it stays a diplomatic talking point with no enforcement teeth.
What officials and researchers are saying
Chinese Foreign Ministry spokesperson Guo Jiakun has been the most direct public voice rejecting the claims. Asked about the U.S. theft allegations at a regular press briefing, Guo said “The U.S. claims are entirely baseless.” He went further, calling them “They are a slanderous smear against the achievements of China’s artificial intelligence industry,” and added “China firmly opposes this.” (Straits Times)
Assistant Chinese Foreign Minister Liu Bin made the government’s most detailed technical rebuttal at the World AI Conference in Shanghai. He said “Some countries hype up distillation,” and characterized the U.S. position as “This is misguided and counterproductive.” (Bloomberg Law)
Neither Anthropic, OpenAI, nor Google has issued a fresh named-executive statement specific to the September 8-9 exchange as of this writing; their positions on the record come from the companies’ own prior blog posts and statements to reporters cited above, not from a new quote tied to this week’s news.
How this compares with prior US-China AI flashpoints
Distillation is now one of at least three active fronts in the broader U.S.-China AI competition, alongside chip export controls and model safety evaluation disputes. Chip controls target hardware access directly and have measurable effects, like the memory and GPU shortages already rippling through both markets. Model safety disputes, by contrast, tend to stay academic and diplomatic, showing up in joint statements rather than trade actions.
Distillation sits in between. It has the diplomatic visibility of a safety dispute (public statements, ministry-level rebuttals) but carries the same enforcement ambition as a chip control fight, with sanctions threats against specific companies like Moonshot AI. That combination is why it’s likely to be one of the harder items on the mid-September AI safety talks agenda CNBC reported on, since neither side has an existing legal or technical framework to resolve it cleanly.
Predictions: where this goes next
- The mid-September 2026 US-China AI safety talks reported by CNBC will almost certainly include a direct exchange over distillation, but expect a joint statement of “continued dialogue” rather than any binding agreement on enforcement.
- Watch for additional named Chinese models beyond Kimi K3 to get pulled into sanctions-threat territory if Anthropic or OpenAI publish further technical evidence of API abuse patterns.
- U.S. AI labs are likely to tighten API rate limits, account verification, and anomaly detection specifically aimed at high-volume automated querying patterns, regardless of how the diplomatic dispute resolves.
- China’s Commerce Ministry will likely continue pairing rejection of the distillation claims with counter-accusations of “AI hegemonism,” using the dispute as leverage in broader trade and chip-export negotiations rather than treating it as a standalone IP issue.
- Expect at least one more publicized case study, similar to the Anthropic-Qwen 28.8 million query allegation, to surface before the end of 2026, as U.S. labs use public disclosure as their primary enforcement tool in the absence of a legal remedy.
What this means for developers and enterprise buyers
For engineering teams evaluating which models to build on, the distillation fight is mostly a background risk rather than an immediate technical concern. Chinese open-weight models like DeepSeek’s and MiniMax’s releases remain widely used precisely because of their cost efficiency, and nothing in this dispute has resulted in a court order, an app store removal, or an API access ban as of September 10, 2026.
What teams should actually watch for is tightened API terms of service from U.S. labs. If Anthropic, OpenAI, or Google roll out stricter rate limits, mandatory business verification, or usage-pattern monitoring in response to these allegations, that will affect legitimate high-volume users too, not just the accused actors. Enterprise buyers relying on Chinese models for cost reasons should also track whether sanctions threats tied to specific products, like the one aimed at Moonshot AI’s Kimi K3, ever convert into actual export restrictions that could affect cloud availability or chip access for those labs.
Frequently asked questions
What is AI model distillation?
Distillation is a machine learning technique where a smaller or newer “student” model is trained to replicate the outputs of a larger, more capable “teacher” model, typically to cut costs while retaining much of the original capability. It’s used throughout the AI industry, including by U.S. labs on their own models.
Which companies has the US accused of illicit AI distillation?
Named Chinese firms include DeepSeek, MiniMax, and Moonshot AI, along with a lab linked to Alibaba’s Qwen project, according to Anthropic’s public statements and reporting from CNN, Reuters, and AIWeekly.
Which US AI companies say their models were targeted?
Anthropic (Claude), OpenAI, and Google have all been named as the U.S. companies whose systems were allegedly queried at scale for distillation purposes, per India Today and Reuters.
How has China responded to the accusations?
China’s Ministry of Commerce and Foreign Ministry have both rejected the claims. Foreign Ministry spokesperson Guo Jiakun called the allegations “entirely baseless,” and Assistant Foreign Minister Liu Bin called the U.S. framing “misguided and counterproductive,” according to the Straits Times and Bloomberg Law.
Is there a link between this dispute and China’s military AI use?
Reuters reported on July 31, 2026 that a review of more than 80 Chinese academic papers found Chinese military researchers had used outputs from OpenAI and Anthropic models to train domestic defense-related AI systems. That finding is separate from, but connected to, the broader distillation dispute.
What happens at the upcoming US-China AI safety talks?
CNBC reported on September 5, 2026, citing Reuters sources, that the U.S. and China are preparing for AI safety talks planned for mid-September 2026, and that Washington intends to raise the distillation allegations directly during those discussions.
Has any Chinese AI company been sanctioned over distillation claims?
As of September 10, 2026, no formal sanctions have been confirmed. Moonshot AI has been the subject of sanctions threats tied to its Kimi K3 model, according to Tech Times, but no enforcement action has been publicly finalized.
Does this affect access to Chinese AI models like DeepSeek for developers outside China?
Not directly, as of this writing. No API bans or export restrictions tied specifically to the distillation allegations have taken effect. Developers should watch for changes to U.S. labs’ own API terms of service as the more immediate practical impact.




