China’s Ministry of Commerce on September 9, 2026 formally rejected a fresh US allegation that Chinese artificial intelligence companies are running “industrial-scale” distillation operations against OpenAI, Google and Anthropic’s frontier models, calling the claims groundless and warning Washington that Beijing will respond with “resolute countermeasures” if the accusations are used to justify new restrictions on Chinese AI firms. The rebuttal came a day after a joint US advisory, issued by three federal agencies including the National Security Agency, accused Chinese developers of running “aggressive, industrial-scale distillation activities” designed to extract restricted capabilities from American models and fold them into homegrown systems.
The exchange marks the sharpest escalation yet in a dispute over AI distillation that has been building since February 2026, when OpenAI first told US lawmakers that DeepSeek was running “sophisticated, multi-stage pipelines” to copy its models. What began as a corporate complaint has now become a state-to-state confrontation, with Reuters, ABC News and China’s Global Times all reporting on the September 8-9 clash as a new inflection point in the broader US-China AI rivalry.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What the new US advisory actually alleges
According to Reuters and Global Times reporting, the September 8 advisory names several Chinese large-model developers as subjects of concern, including DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun and Z.AI. The advisory’s core claim is that these companies are “systematically extracting restricted proprietary functionalities and capabilities” of US frontier AI models with the intent of training their own systems on the output. The document does acknowledge that distillation itself is a legitimate and widely used AI training technique, but argues the scale and method used by some Chinese firms crosses into unauthorized extraction rather than ordinary research.
Distillation, in its uncontroversial form, is the practice of training a smaller, cheaper model to imitate the outputs of a larger one, a technique every major AI lab uses internally to compress its own frontier systems into lighter, faster products. TechCrunch has described the method as one that becomes contentious only when a rival company uses it to, in the outlet’s words, copy the homework of another lab rather than compressing its own work. That distinction between internal distillation and cross-company extraction is at the center of the current fight, and it is precisely the line China’s government rejects as arbitrary.
How China’s Ministry of Commerce responded
China’s Ministry of Commerce, or MOFCOM, issued its rebuttal on September 9, arguing the US allegations are “groundless and lacking legal basis.” A ministry spokesperson said model distillation is “essentially a neutral technical approach used by model developers around the world, including US companies,” and accused Washington of politicizing and weaponizing what the ministry called a normal technical and commercial practice within the AI industry. The ministry went further, framing the advisory as evidence of what it called US technological hegemony, an attempt to monopolize computing power and suppress competition from Chinese firms, according to Global Times.
“China will take resolute countermeasures if the United States takes actions to suppress Chinese artificial intelligence companies under the pretext of combating model distillation,” a Ministry of Commerce spokesperson said, according to a report carried by China Daily. The threat of retaliation echoes language Beijing used in July, when MOFCOM accused the US of “AI hegemonism” and warned of countermeasures over a separate round of distillation-related probes, a dispute first reported by Reuters.
Seven months of escalating accusations
The September advisory is not an isolated event. It is the latest step in an escalation that has run through nearly all of 2026, moving from private corporate memos to congressional testimony to a coordinated multi-agency government advisory. Understanding that timeline matters because it shows the dispute has steadily shifted from a technology-industry disagreement into a formal diplomatic standoff between two governments.
It started on February 12, 2026, when OpenAI sent a memo titled “Updated Stakes for American-Led, Democratic AI” to the US House Select Committee on Strategic Competition between the US and the Chinese Communist Party. In that memo, OpenAI accused DeepSeek employees of developing methods to circumvent access restrictions, including the use of “obfuscated third-party routers,” and of writing code specifically to access US AI models and harvest outputs for distillation, according to a Reuters report on the memo. Less than two weeks later, on February 23 and 24, Anthropic went public with similar claims, with TechCrunch and CNN both reporting that Anthropic accused unnamed Chinese labs of “mining Claude.” CNBC’s coverage of the same allegations named three specific companies: DeepSeek, Moonshot and MiniMax.
By April 7, the dispute had industry-wide backing. The Straits Times reported that OpenAI, Anthropic and Google were coordinating through the Frontier Model Forum, an industry body, to share information on what they termed adversarial distillation originating in China. Then on April 24, the US State Department escalated the issue to a formal diplomatic level, issuing a global warning about alleged Chinese AI intellectual-property theft. Reuters reported that the Chinese Embassy in Washington immediately called the claims “groundless” and “deliberate attacks on China’s development and progress in the AI industry,” while Chinese Foreign Ministry spokesperson Guo Jiakun separately told reporters the allegations were “entirely baseless” and a “slanderous smear.”
The dispute simmered through the summer. On July 18, at the World AI Conference in Shanghai, Assistant Chinese Foreign Minister Liu Bin pushed back without directly naming the US, saying at the event that “some countries hype up distillation,” a stance he called “misguided and counterproductive,” per Bloomberg Law’s coverage of the conference. Nine days later, on July 27, MOFCOM issued a formal statement, analyzed in detail by Georgetown’s Center for Security and Emerging Technology, in which the ministry flatly rejected the specific claim that Chinese firms had distilled from US models while simultaneously arguing that distillation itself is common practice in both countries. That set up the September 8-9 exchange, in which a new, more specific multi-agency US advisory produced China’s sharpest rebuttal yet.
Timeline of the US-China distillation dispute
| Date | Event | Key actor |
|---|---|---|
| Feb. 12, 2026 | OpenAI memo to Congress accuses DeepSeek of “distillation attacks” via obfuscated routers | OpenAI |
| Feb. 23-24, 2026 | Anthropic publicly accuses Chinese labs of “mining Claude”; CNBC names DeepSeek, Moonshot, MiniMax | Anthropic |
| Apr. 7, 2026 | OpenAI, Anthropic, Google coordinate via Frontier Model Forum on adversarial distillation | Frontier Model Forum |
| Apr. 24, 2026 | State Department issues global warning on alleged Chinese AI IP theft; China calls claims “baseless” | US State Dept / China |
| Jul. 18, 2026 | Liu Bin calls distillation hype “misguided and counterproductive” at Shanghai AI conference | Chinese Foreign Ministry |
| Jul. 27, 2026 | MOFCOM statement rejects claims, calls distillation a neutral, widespread practice | MOFCOM |
| Sep. 8, 2026 | Three US agencies, including NSA, issue advisory naming six Chinese AI firms | NSA and two other US agencies |
| Sep. 9, 2026 | MOFCOM rejects advisory, warns of “resolute countermeasures” | MOFCOM |
The companies and models named on both sides
The dispute names specific companies on both sides of the Pacific, which is part of why it reads more like an industrial policy fight than an abstract technical debate. On the Chinese side, the September advisory and prior US statements have named DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun and Z.AI as developers allegedly engaged in unauthorized distillation of US models. DeepSeek has been the most consistently named company across the entire year-long dispute, going back to OpenAI’s original February memo. On the US side, the models and companies described as targets include OpenAI’s ChatGPT and other frontier systems, Anthropic’s Claude family, Google’s proprietary frontier models, and xAI, which was also cited in congressional testimony as reporting distillation attempts against its systems. The frontier-model race those three companies are running, most recently visible in the head-to-head between GPT-6 Astra, Claude Opus 5 and Gemini 3.8 Flash, is exactly the kind of capability gap that makes unauthorized distillation such a sensitive issue for US labs.
None of the named Chinese companies has issued a detailed technical rebuttal of the specific distillation methods described in the US advisory as of this writing. Beijing’s response has instead come through official government channels, MOFCOM and the Foreign Ministry, rather than from the companies themselves, a pattern that has held throughout 2026 and that distinguishes this dispute from a typical corporate IP fight.
Distillation: legitimate technique or extraction attack
The disagreement at the heart of this story is partly definitional. Every major AI lab, American and Chinese, uses knowledge distillation on its own models to produce smaller, cheaper variants that retain most of a flagship model’s capability at a fraction of the compute cost. That is not in dispute. What is in dispute is whether a company can ethically or legally use a competitor’s outputs, obtained through an API or a chat interface, as training data for its own model. TechCrunch’s reporting on the Anthropic allegations noted that most major proprietary developers, including Anthropic, explicitly prohibit that kind of cross-company use in their terms of service, meaning the argument on the US side is as much about contract violations and access-restriction circumvention as it is about the distillation technique itself.
China’s position, as laid out in MOFCOM’s July and September statements, does not engage much with that terms-of-service framing. Instead, the ministry has consistently argued that distillation as a category of technique cannot be singled out as misconduct because it is universally practiced, including by American firms distilling from other American firms’ models or from open releases. Georgetown’s CSET, in its analysis of MOFCOM’s July statement, characterized this as a strategic move: China is not denying that distillation happens, it is denying that distillation is inherently wrongful, which shifts the debate away from questions of legality and toward questions of industry norms.
Why this matters beyond the distillation debate
The distillation fight is unfolding against a backdrop of broader US-China technology tension that includes chip export controls, entity-list additions and data-security rules. Coverage from CNBC and CNN has consistently framed the distillation allegations alongside ongoing debates over restricting AI chip sales to China, suggesting the two issues are politically linked even when discussed separately. A New York Post report from July characterized the stakes in national-security terms, describing the practice, when used against a rival lab without authorization, as a form of plagiarism that can carry consequences for US technology leadership if left unaddressed. It also sits alongside separate scrutiny of how Chinese firms obtain US-made AI hardware in the first place, including reporting on how Inspur used its Aivres subsidiary to buy $5.6 billion in Nvidia chips and how Samsung and SK Hynix have been tied to China chip-tool access after losing Verified End User status at four fabs, underscoring that compute access and model-capability access are now being treated as two sides of the same export-control problem.
For Chinese AI companies, being formally named in a US government advisory carries its own risk independent of whatever legal action follows. StepFun, Z.AI, Moonshot AI and MiniMax are smaller, less internationally known firms than DeepSeek or Alibaba, and a US national-security advisory naming them could complicate their ability to attract foreign partnerships, cloud-hosting deals or investment from outside China, even absent formal sanctions. Alibaba, as the most established company on the list, likely faces a different calculus, since its AI division already operates under close scrutiny from both US and Chinese regulators.
Market and industry reaction so far
As of this writing, there is no widely reported evidence of an immediate, quantifiable stock-price reaction tied specifically to the September 8-9 exchange. Reuters and ABC News both framed the story primarily in diplomatic and regulatory terms rather than market terms. That said, the distillation dispute sits inside a wider conversation about AI chip export controls that has moved markets before, and the six Chinese companies named in the advisory could face secondary effects if the accusations translate into new restrictions on their access to US-origin compute, cloud infrastructure or software tooling. None of the named companies are US-listed, which limits the direct read-through to American equity markets, though Nasdaq-listed AI infrastructure and chip names have shown sensitivity to China-related AI headlines throughout 2026.
The US case: a pattern building since February
US lawmakers and agencies have steadily built a paper trail over the year. A House committee document tied to an April 16 hearing describes what it calls China’s “illicit campaign to steal and subvert American AI,” stating that OpenAI, Google, Anthropic and xAI have all separately reported Chinese companies using multi-stage pipelines involving fraudulent accounts and mass querying to generate synthetic training data at scale. That document, along with OpenAI’s original February memo, forms the evidentiary basis that the September multi-agency advisory appears to build on, moving from individual company complaints to a coordinated federal assessment involving the National Security Agency.
That concern has only grown since OpenAI’s Astra model launched, a rollout that prompted an OpenAI safety researcher to publicly warn about AI risk within days of release and fed a broader narrative, covered separately when the Wall Street Journal argued the AGI era had effectively arrived, that frontier capability gaps are now large enough to matter strategically, not just commercially. The involvement of the NSA in the September advisory is itself notable. Earlier statements in this dispute, including the April 24 State Department warning, came from agencies with a diplomatic or trade mandate. The NSA’s direct participation signals that US officials are now treating the distillation issue as a national-security matter rather than purely a commercial-IP dispute, a shift that raises the stakes for any Chinese company named going forward.
China’s counter-narrative: technological hegemony
Beijing’s rhetorical strategy has stayed consistent across the year: agree that distillation exists, reject that it constitutes theft, and reframe US pressure as an attempt to entrench American dominance in AI. The Chinese Embassy in Washington used this framing as early as April, and MOFCOM used nearly identical language in July and again in September. The consistency suggests a coordinated messaging strategy across multiple Chinese government bodies rather than ad hoc responses to individual incidents.
Liu Chang, a spokesperson for the Chinese Embassy in Washington, put it directly in a statement carried by TASS: “The US side’s hyping of the so-called ‘distillation’ concept is a deliberate attack on China’s development and progress in the AI industry. China firmly rejects it.” That statement, along with Guo Jiakun’s April remarks and Liu Bin’s July comments in Shanghai, form a consistent three-agency chorus, the Foreign Ministry, the Embassy and MOFCOM, all using similar language to reject the US framing without offering a detailed technical rebuttal of the specific extraction methods described in US advisories.
Historical context: from open-weight shock to state confrontation
The distillation dispute did not appear from nowhere. It traces back to DeepSeek’s early 2025 release, which briefly wiped hundreds of billions of dollars off US AI and chip-stock valuations after the company claimed to have trained a competitive frontier model at a fraction of the cost of its US rivals. That event triggered immediate questions in Washington about how a Chinese lab with restricted access to top-tier GPUs had matched Western capability so quickly, and distillation from US models was floated as one possible explanation almost immediately. What has changed since then is the formality of the accusations: what started as speculation and informal industry chatter in 2025 has, by September 2026, become a matter of congressional testimony, State Department warnings and now a joint NSA advisory.
That progression mirrors earlier US-China technology disputes over telecom equipment and semiconductor manufacturing tools, where initial corporate complaints about intellectual-property practices eventually hardened into formal export controls and entity-list restrictions. Whether the distillation dispute follows that same trajectory toward hard restrictions, or stays at the level of dueling statements, is the central open question raised by this week’s exchange.
Comparing the US and Chinese positions
| Point of dispute | US position | Chinese position |
|---|---|---|
| Nature of distillation | Legitimate technique when used internally; unauthorized extraction when used on a rival’s model | A single neutral technical practice used worldwide, no legal distinction drawn |
| Companies named | DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI | Disputes that any of these firms engaged in wrongdoing |
| Lead agencies/voices | OpenAI, Anthropic, Google, xAI, State Dept, NSA | MOFCOM, Foreign Ministry, Washington Embassy |
| Framing of motive | National-security and IP-protection concern | US “technological hegemony” and competitive suppression |
| Proposed response | Multi-agency advisory, information-sharing via Frontier Model Forum | Threatened “resolute countermeasures” if restrictions follow |
| Public evidence offered | Descriptions of obfuscated routers, mass querying, synthetic data pipelines | General neutrality argument, no company-specific rebuttal published |
What could happen next
Based on the year-long pattern of escalation, several outcomes look plausible in the coming months, though none is confirmed and all should be read as informed projection rather than reporting.
- Additional US agencies could join future advisories, following the pattern of the State Department’s April warning expanding into the NSA’s September involvement, which would further formalize the national-security framing of the dispute.
- China’s threatened “resolute countermeasures” could take the form of retaliatory restrictions on US company operations in China or additional scrutiny of US AI products sold into the Chinese market, mirroring past trade-dispute playbooks.
- US labs including OpenAI, Anthropic and Google are likely to keep tightening API access restrictions and rate limits aimed at detecting mass-querying patterns consistent with distillation attempts, building on the Frontier Model Forum information-sharing effort already underway.
- Congressional pressure could push for legislation specifically addressing AI model distillation as an IP-protection issue, building on the House Select Committee’s existing work on China-related AI competition.
- The dispute is likely to remain rhetorical in the near term rather than escalate to hard sanctions against the six named Chinese companies, given that neither side has moved from formal statements to concrete enforcement action across seven months of escalating claims.
The bigger picture for AI competition
What makes this dispute distinct from earlier US-China tech fights is that it centers on a technique, not a product or a chip. Export controls target physical hardware that can be inspected, counted and restricted at a border. Distillation targets an intangible transfer of capability through API queries, which is far harder to prove, measure or block without also restricting legitimate research use. That enforcement difficulty may be part of why, seven months into the dispute, neither government has moved past strongly worded statements: proving that a specific Chinese model was trained on unauthorized extraction from a specific US model, rather than on independently collected data, is a technically difficult claim to substantiate publicly.
For US AI labs, the practical response so far has been defensive rather than legal: tighter API monitoring, stricter enforcement of terms-of-service violations, and coordinated information-sharing through the Frontier Model Forum rather than lawsuits against named Chinese firms. That suggests the companies themselves may see limited value in formal legal action against entities with no US assets to pursue, leaving the state-level advisory and diplomatic-statement track as the primary venue for this fight going forward.
Frequently asked questions
What is AI model distillation?
Distillation is a training technique in which a smaller “student” model is trained to replicate the outputs of a larger “teacher” model, letting developers produce cheaper, faster versions of a flagship system. It is a standard practice across the AI industry when applied to a company’s own models.
Why did China reject the latest US claims?
China’s Ministry of Commerce said the September 8 US advisory lacked factual and legal grounds, and it argued that distillation is a neutral technique practiced by companies in both countries, not a form of theft unique to Chinese firms.
Which Chinese companies were named in the advisory?
Reporting on the advisory names DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun and Z.AI as Chinese large-model developers referenced in the US government’s assessment.
Which US companies say they were targeted?
OpenAI, Anthropic, Google and xAI have all made separate statements or provided testimony describing attempts by Chinese firms to extract outputs from their frontier models.
Is this the first time China has responded to distillation claims?
No. China’s Foreign Ministry, its Washington Embassy and MOFCOM have all issued rejections of similar claims at multiple points in 2026, including in April and July, before the latest September rebuttal.
What countermeasures has China threatened?
MOFCOM said China would take “resolute countermeasures” if the US uses distillation allegations as a pretext to suppress Chinese AI companies, without specifying what form those countermeasures would take.
Has this affected AI company stock prices?
No widely reported, quantified stock-price movement has been tied directly to the September 8-9 exchange as of this writing. Coverage has focused on the diplomatic and regulatory dimensions rather than market impact.
Does this relate to the DeepSeek disruption of early 2025?
Yes. Questions about how DeepSeek trained a competitive model despite restricted chip access first surfaced after its early 2025 release, and distillation from US models has been floated as a possible factor since that time, feeding into the escalating claims seen throughout 2026.