In-Depth Analysis: The US Accuses China of AI “Stealing Skills” – What’s Really at Stake?
Hello everyone, I’m your financial journalist and economist. Today, we’re going to discuss a matter that seems purely technical but is actually heavily laden with political implications.
On September 8th, three powerful agencies—the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI)—jointly issued a statement, naming six Chinese AI companies, including DeepSeek, Moonlit Side, and Alibaba, for engaging in “industrial-scale” knowledge distillation. In simple terms, they accused these companies of “stealing” the capabilities of top American AI models on a large scale.
The Chinese Ministry of Commerce responded firmly, stating that the accusations were unfounded and lacked legal basis. The Ministry of Foreign Affairs even went further, claiming that these actions were a result of China’s efforts to achieve technological self-reliance.
Many non-experts might be wondering: What exactly is “knowledge distillation,” and why are the US so upset about this practice? What’s really behind this?
Don’t worry; let’s break down this news and explain it in plain language.
---
What is “Knowledge Distillation,” and Why Does the US Consider It Stealing?
First, let’s understand the core technology in question: knowledge distillation. You can think of it as a teaching process where a teacher explains something to a student:
- Traditional Training: The teacher points to a picture and says, “This is a cat, this is a dog,” and the student memorizes it.
- Knowledge Distillation: The teacher not only tells you what it is but also provides nuanced, probabilistic information, such as “I think it’s 80% a cat, 15% a dog, 5% a fox.” This type of information, which reflects the teacher’s deep understanding of the world, is known as “hidden knowledge.”
The Key Points:
1. It’s a Universal Technology: Knowledge distillation wasn’t invented by China; the concept was proposed by Nobel Prize winner Hinton in 2015. All AI companies around the world, including American giants, use it.
2. Legal vs. Illegal: If you buy my book and read it on your own, that’s legal. However, if you use my API (like an online Q&A service) to ask countless questions and use those answers to train your own model, that would be considered a violation of the service terms.
Why Is the US Concerned?
The US believes that Chinese companies are not just conducting normal research but are “absorbing” the capabilities of top American models (such as Claude and GPT series) through millions of interactions. In their view, this is equivalent to using much less money and computing power to catch up by “copying” their work.
It’s like you spend a lot of money developing a unique recipe, only for your competitor to come to your restaurant every day, taste the food, and then replicate it without actually stealing your recipe. Although they haven’t stolen your cooking methods, they have indeed “stolen” the flavor.
---
Details of the US Accusations: From Physical Restrictions to Knowledge Restrictions
The announcement (AA26-251A) is very specific and can be seen as conclusive evidence. Here’s what the US claims they have:
1. Massive Scale: The accusations suggest that Chinese companies have engaged in millions of model interactions, obtaining billions of tokens (a huge amount of data).
2. Secretive Methods:
- They used not only official APIs but also third-party platforms and proxy channels to access the data.
- They bought large numbers of advanced accounts, shared them among multiple people, and automatically switched channels to avoid detection.
- They were even accused of “contaminating downstream training data” by intentionally providing distorted data to test the models’ reactions.
3. Specific Targets: The models affected include Anthropic’s Claude series, Google’s Gemini series, OpenAI’s GPT series, and xAI’s Grok series.
4. Extracted Capabilities: They not only extracted basic conversational skills but also valuable capabilities such as legal expertise, logical reasoning, and intelligent agent functions.
The Extended Logic of the Restrictions:
- 2022: Restrictions on chips (physical access).
- 2023: Restrictions on lithography machines (manufacturing access).
- 2026 (now): Restrictions on model outputs (knowledge access).
The US believes that even if they block hardware, China can still catch up through open source and algorithm optimization. Now, they want to block the “flow of knowledge.” Chips are the physical components, but model capabilities represent the “soul” of AI. The US doesn’t want Chinese AI to incorporate American technology, or, more precisely, they don’t want China to acquire high-value American technological achievements at a low cost.
---
Chinese Counterarguments: This Isn’t “Stealing,” It’s a “Contract Dispute”
In response to the accusations, China remained calm and argued from three main perspectives:
1. Technological Neutrality: Knowledge distillation is a common practice in the industry, not unique to China. Many American startups also use Chinese open-source models (like Llama or Qwen) for their own development. The US’s accusations are a double standard.
2. Legal Perspective:
- From the US’s viewpoint, this is intellectual property theft and a criminal offense, so they involve national security agencies.
- From China’s and legal perspectives, distillation doesn’t directly copy code or raw training data; it mimics knowledge, which is difficult to classify as copyright or patent infringement. The most likely legal basis is a “breach of service terms” (a contractual violation).
- There’s a big difference: A breach of contract is a civil issue that can be resolved with compensation, while intellectual property theft is a criminal offense. The US is framing it as a crime to justify further sanctions.
3. Business Monopoly: American companies set unfair terms in their service agreements (e.g., prohibiting use for competitive purposes), and then the national security agencies enforce them. This is essentially using state power to protect business monopolies.
In Summary: China believes that the US is using these actions to maintain its market monopoly by turning commercial competition into a national security issue.
---
Timing and the Strategy: “Showing the Knife” Before the Summit
The timing of this incident is very strategic: it’s less than three weeks before the China-US leaders’ summit in Washington. In international negotiations, a common tactic is to “show the knife” before formal talks, stacking up pressure and testing the other party’s boundaries.
- Purpose:
- To test China’s willingness to make concessions in the AI field.
- To create pressure and potentially force China to make trade or geopolitical concessions.
- To demonstrate to the US public and Congress that they are protecting American technological advantages.
China’s response also indicates flexibility: they are open to dialogue but threaten countermeasures if the US takes further actions. This shows that both sides don’t want to completely escalate the conflict, but neither wants to back down first. It’s a game of “fighting while negotiating.”
---
Future Implications: The Impact on the AI Ecosystem
This incident has far-reaching consequences:
1. Impact on the Distillation Approach: For Chinese AI companies that rely on American model APIs for training, this is a red alert. In the future, the US may legislate to control model outputs, making it illegal to use these APIs for training.
2. Accelerated Decoupling and Independent Development: Chinese AI companies will be forced to rely more on domestic computing power (such as Huawei’s Ascend) and domestic models (like Qwen, DeepSeek, GLM) for training.
3. Independent Open Source Ecosystems: China may promote the development of open-source models independent of American technology to avoid being constrained.
4. Data Integrity: The US’s practice of “contaminating downstream training data” means that even if companies can still use APIs, the data might be flawed, potentially affecting model performance. This could force them to completely cut off their dependence on American models.
5. Divided Global AI Ecosystem: If the US truly restricts model capabilities as strategic resources, the global AI landscape could split into two camps:
- US Camp: Closed-source, high barriers, high costs, high profits.
- China Camp: Open-source, low barriers, high cost-effectiveness, rapid iteration.
In Conclusion
The AA26-251A announcement is more than just a cybersecurity document; it marks a shift in the Sino-US AI competition from a technological battle to a battle over rules and ecosystems.
Knowledge distillation is a technical issue, but this incident highlights that in the realm of technology, there are no purely technical issues—only geopolitical ones. For ordinary people, this means that the AI products we use may follow different development paths and face different limitations depending on their origins. For the Chinese AI industry, it’s a painful process of becoming independent, but it’s also a necessary step toward true autonomy.
Remember: When your opponent starts blocking your “knowledge access,” you must learn to generate your own resources.