
What happened
The NSA, CISA, and FBI jointly accused six Chinese firms, including DeepSeek and Moonshot AI, of aggressive AI-model distillation since late 2024.
Why it matters
This is the most detailed accusation yet, replacing vague warnings with a call to secretly switch targeted Chinese users to inferior models without notice.
What to watch
The plan hinges on whether US firms can implement the tricky secret-switching mitigation without frustrating legitimate users, ahead of a Trump-Xi meeting on September 24.
WHO IT HITSEnterprise IT teams and security operations at US AI firms will have to implement the requested mitigations, potentially degrading service for legitimate users who get mistaken for attackers.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
The joint release escalates a months-long dispute. It follows earlier accusations—OpenAI's against DeepSeek and Google's against Gemini cloning attempts—but this statement by US agencies stands out as the government's most detailed accusation yet. The agencies allege stolen capabilities "form the core—not merely a supplement" of China's AI strategy.
The proposed defenses are as notable for their risks as their intent. The idea of secretly switching suspected attackers to less-capable models is acknowledged as technically challenging, partly because Chinese firms have adaptive systems that can detect degradation and switch back within 24 hours. The more significant risk is that this policing could catch legitimate users in the crossfire, reducing their experience without notice, a fate OpenAI has faced backlash for before.
The effectiveness of this strategy will likely hinge on the delicate balance between security and user experience. As tensions rise, China has defended itself by suggesting US firms also use Chinese models. This backdrop makes the upcoming meeting between Donald Trump and Chinese President Xi Jinping on September 24 a key moment to watch for how this dispute plays out diplomatically.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Michael Burry, famous for The Big Short, is short Nvidia, Palantir and Tesla, and in his Substack newsletter s…

Investors have three creative routes to Anthropic exposure before its expected IPO: buying Alphabet, Amazon, o…

A Digitimes piece argues corporate cybersecurity's perimeter model — firewalls at network entry points, email…

Much of the attention on AI infrastructure buildouts is now tied to sheer compute power, with dominance define…

Barron's reported September 10 that Kepler Computing emerged from stealth with a memory architecture using fer…

Dynatrace acquired Arize AI, adding AI observability, evaluation and agent monitoring to its application obser…