The U.S. Is Weaponizing IP Enforcement Against Chinese AI
A joint FBI-NSA-CISA alert accuses six Chinese AI firms of systematically distilling American models to build their own systems. The pivot from export controls to IP enforcement reshapes how Silicon Valley operates abroad and raises the stakes before the Trump-Xi summit.
The Real Escalation Isn’t What It Sounds Like
The joint FBI-NSA-CISA alert released Tuesday didn’t just name names. It reframed the entire US approach to China’s AI rise.
For years, Washington’s primary weapon has been export controls — blocking chips, restricting hardware, trying to starve Chinese AI of compute. The new posture is different. It treats intellectual property theft as the central threat. That’s a louder, more personal accusation, and one that changes how every American AI company must think about its Chinese operations.
The report accuses six firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — of systematically distilling American models since 2024. Distillation itself is a legitimate technique in the AI industry: training a smaller model on the outputs of a larger one to create something more efficient. But the US government says what China is doing goes far beyond that. It is, in the words of the report, “the critical core” of these companies’ development — not a supplement, but the foundation.
Specific allegations include Chinese models mining American systems for “legal specialization optimization,” “agentic functions” and “coach/assistant capabilities.” The scope suggests this isn’t a handful of rogue engineers. It’s an industrial strategy.
The Pivot From Hardware to Code
The shift from export controls to IP enforcement carries enormous second-order consequences. Export controls target physical goods and can be enforced at borders. IP enforcement targets code, behavior and business relationships — and it lands directly on the companies that built the models in the first place.
This means American AI firms now face a new class of risk: their products, sold legally around the world, being used as raw material for Chinese competition. OpenAI already flagged DeepSeek last year for inappropriately basing its model on ChatGPT. Google said in February it was inundated with attempts to clone Gemini.
The government alert effectively tells these companies they are on their own to fight back. Recommendations include stricter verification of paying users, sharing intelligence with each other about suspicious behavior, and in some cases deliberately downgrading or altering responses to queries that appear malicious. That last point is quietly significant. It asks American companies to consider deliberately poisoning their own products when they suspect bad-faith actors are using them — a standard no company has had to follow before.
Michael Kratsios, director of the White House Office of Science and Technology Policy, has been circling this issue for months. In April he circulated a memorandum calling Chinese distillation a “critical issue.” By July he was publicly naming Moonshot AI’s Kimi K3 system as distilled from Anthropic’s Fable model. His language carefully distinguishes between “legitimate AI distillation” and what he called “large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology.” The line he drew is real but impossibly thin — and placing that burden on private companies to police their own users is a massive ask.
Who Wins, Who Loses
American AI companies win one thing: political cover. The government has now officially validated what they’ve been saying privately for a year. They can point to the alert when negotiating with enterprise customers, investors and regulators about the risks of their technology reaching Chinese hands.
But they also lose something important: operational simplicity. Every American AI firm that operates globally now faces the question of how to differentiate between a legitimate researcher in Beijing using ChatGPT to write code and a Chinese state-aligned company using it to reverse-engineer their model. The answer, implied by the alert, is that you don’t know — and you should act as if you can’t trust anyone paying for access.
Chinese firms named in the report lose whatever plausible deniability they previously had. Distillation was always a grey area. After this, it’s an allegation. Any further accusations from US authorities won’t need to establish the practice — they’ll only need to point to Tuesday’s document.
The six companies named — particularly DeepSeek, which has already drawn scrutiny for its cost-effective models — now carry a government label that could affect their ability to raise capital, attract Western partnerships or operate in any jurisdiction that takes US IP enforcement seriously.
What Happens Next
The timing is deliberate. President Donald Trump is scheduled to meet Chinese President Xi Jinping on September 24. The alert arrives weeks before that meeting, after months of public friction over AI trade secrets. This isn’t random. It’s a positioning move.
Washington is signaling that export controls alone won’t contain China’s AI ambitions. The message to Silicon Valley is equally clear: if you want US government protection for your IP, you need to invest in the defensive infrastructure the government is now asking you to build. That means better authentication, better anomaly detection, better cross-company intelligence sharing. It also means accepting that the era of open global access to frontier American AI models may be ending — not through regulation, but through self-imposed restriction.
China’s embassy in Washington did not respond to a request for comment. The report stopped short of accusing Chinese intelligence of direct involvement, saying the campaign came “likely with Chinese government awareness” rather than direction. That distinction matters. It leaves room for denial while making the accusation stick.
The most consequential detail in the alert may be the smallest one. The government is asking American companies to share data about suspicious users with each other. If that happens, it creates an informal but powerful surveillance network across the AI industry — one that could identify patterns no single company would see alone, and one that could eventually be compelled into formal cooperation with law enforcement. The infrastructure for a new kind of AI IP enforcement regime is being built right now, one flagged query at a time.
The AI race between the US and China was always going to involve more than chips and data centers. Tuesday’s alert makes clear it will also involve the terms of service, the payment records, the access logs — every trace of how a model is used once it leaves the lab. That’s a longer, messier battleground. And both sides are just now learning how to fight on it.