The White House says Chinese firms have been systematically recreating US-developed AI by harvesting model outputs. A memo made public this week alleges large‑scale copying and cites Anthropic's findings that three China‑based labs — DeepSeek, Moonshot and MiniMax — ran so‑called 'distillation' campaigns to reproduce advanced systems, a claim that could sharpen calls for export controls and tougher industry safeguards.

What the memo says The White House memo, made public this week, sets out a stark assessment: numerous Chinese firms have been obtaining proprietary AI capabilities through large‑scale copying of models developed overseas. It describes the activity as systematic rather than isolated and warns that the practice is eroding the commercial and security value of US technical work. The memo does not name every company it reviewed. Federal officials framed the matter as both an economic and strategic problem. They say that if firms can reproduce high‑quality models simply by querying them and retraining on the outputs, incentives for expensive, long‑term research decline. That could change which projects receive funding and how companies safeguard their work. Anthropic's findings and the named labs Anthropic — the California‑based AI developer — has been among the firms to flag the practice. Earlier this year Anthropic described what it called distillation attacks by three AI laboratories: DeepSeek, Moonshot and MiniMax. Anthropic said it had found all three labs to be working to copy Anthropic models through distillation campaigns. Anthropic's account, and the White House memo's broader allegations, point to the same technical method as the likely vehicle for copying. The company provided investigators with examples of behaviour it saw as consistent with systematic distillation: large numbers of narrowly framed queries made to a model, followed by the emergence of a rival product whose outputs strongly matched the original. How distillation campaigns work Distillation is a technique used legitimately in research and industry to compress models or transfer knowledge from a large system into a smaller one. But the same technical steps can be used to reconstruct a proprietary model without access to its code or training data. Typical steps described by investigators include: - Sending many prompts to a target system and collecting the responses at scale. - Training a new model to imitate those responses, reproducing behaviour, style and specialised capabilities. - Deploying the new model as a rival product that can reduce the time and expense needed to build similar systems. In the hands of a competitor this can undercut the commercial value of original R&D; in the hands of a state actor it could accelerate capabilities without domestic investment. Implications for companies and policymakers The memo has prompted industry figures to call for sharper defences. Developers must balance openness — the sharing of research that drives progress — with protection of investments that make high‑performance models possible. Defensive options discussed include tighter access controls, watermarking outputs, legal action and technical throttles on high‑volume queries. Policymakers face trade‑offs. Limiting the flow of AI models and tools can slow diffusion to allies and academic researchers, but leaving those flows unchecked risks enabling appropriation of Western R&D. Some legislators have urged measures to restrict exports of advanced chips and other components, while others want new rules on model provenance and accountability. Industry reaction and the limits of current defences Companies say they already use a mix of strategies to guard models, but technical and legal protections each have limits. Watermarking and rate limits can raise costs for would‑be copiers but may not be foolproof against determined distillation campaigns. The memo has renewed discussion about whether stronger export controls or new industry standards are needed.

Related Articles

Anthropic said it detected distillation campaigns by DeepSeek, Moonshot and MiniMax — the allegation at the heart of the White House memo.

This article was created with AI assistance.