Artificial intelligence companies in the United States are increasingly worried about a technique known as “distillation,” which can allow a smaller AI model to learn from the answers produced by a much larger and more expensive system. The technology itself is not new or inherently illegal, but Washington and leading US AI companies now argue that its large-scale use by Chinese firms could undermine America’s advantage in frontier artificial intelligence.
The issue has moved sharply into the geopolitical spotlight. On September 8, US cybersecurity agencies accused six Chinese AI companies, including DeepSeek, Moonshot AI and Alibaba, of conducting industrial-scale efforts to extract capabilities from advanced American AI models. The allegations involve models developed by companies including Anthropic, OpenAI, Google and SpaceX. China has rejected the accusations as unfounded.
So what exactly is AI distillation?
In simple terms, distillation is a way of transferring some of the behavior or knowledge of a powerful “teacher” model into a smaller “student” model. Instead of spending enormous amounts of money and computing power to train a frontier model from scratch, developers can ask a stronger system thousands or millions of questions and use its responses as training material for another model.
The approach can have legitimate uses. AI companies themselves use distillation to create smaller, faster and cheaper versions of their own models. A large model can act as a teacher while a smaller model learns to reproduce useful patterns without requiring the same level of computing resources.
The controversy begins when a company uses another firm’s proprietary model without permission to obtain those benefits.
Anthropic has alleged that DeepSeek, Moonshot and MiniMax generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts in campaigns designed to extract the model’s capabilities. Anthropic has described distillation as a legitimate technique when used appropriately, while arguing that competitors can abuse it to obtain sophisticated capabilities at a fraction of the cost and time required to develop them independently.
The US government’s latest allegations suggest the scale may be far larger than isolated experimentation. American agencies say Chinese companies have extracted billions of tokens through millions of interactions with US frontier models since at least late 2024. The agencies also alleged that some firms used bulk purchases of premium subscriptions to reduce the cost of these campaigns.
That matters because the economics of AI are changing rapidly.
Building a frontier model can require enormous investments in chips, data centers, electricity, engineers and research. US technology companies have spent hundreds of billions of dollars building AI infrastructure and developing increasingly powerful models. If competitors can reproduce a significant portion of those capabilities by querying an existing model, the financial advantage of being the original developer becomes less secure.
The concern is particularly significant for companies such as OpenAI and Anthropic, which are spending heavily to remain at the technological frontier. Their business models depend partly on converting expensive research and computing investments into commercial products. If competitors can cheaply approximate those capabilities, pricing pressure could increase while the incentive to spend billions on original research could weaken.
China’s response is that the United States is portraying a widely used AI development method as inherently illegitimate. Beijing has rejected the accusations and argued that Chinese progress is based on its own innovation. The distinction is important because distillation itself is not prohibited technology. The dispute is primarily about whether companies crossed contractual, legal or ethical boundaries while using proprietary systems.
The problem for US policymakers is proving exactly where that line has been crossed. Unlike copying a computer file, distillation does not necessarily involve obtaining the original model’s source code or internal parameters. A developer can potentially learn from outputs generated through ordinary interactions. Establishing that the activity involved prohibited access, fraudulent accounts or deliberate circumvention can therefore be difficult.
There is also a risk that Washington could respond too broadly. Restrictions that make it difficult for legitimate researchers to study or build smaller models could slow innovation in the United States as well. Open-source and open-weight models are becoming increasingly important precisely because companies want cheaper, customizable alternatives to expensive proprietary systems.
The dispute therefore represents more than another accusation of Chinese technology theft. It raises a fundamental question about who should benefit from knowledge generated by AI systems and how much of that knowledge can legally or commercially be transferred through model outputs.
With Trump and Chinese President Xi Jinping expected to discuss broader technology and trade tensions, AI distillation could become another pressure point in US-China relations. The debate may ultimately lead to tighter controls, stronger safeguards around commercial AI services and new rules governing how models can be queried for training purposes.
For American AI companies, the stakes are clear. Their biggest competitive advantage may no longer depend only on building the best model. It may also depend on preventing competitors from learning too much from it.






