AIToday
AI Safety & AlignmentAI Regulation & PolicyAI Business & IndustryArs Technica AIPublished: Sep 10, 2026, 06:00 JST2 min read

US Urges AI Firms to Secretly Downgrade Chinese Users

US Urges AI Firms to Secretly Downgrade Chinese Users

3 Key Points

  1. What happened

    The NSA, CISA, and FBI jointly accused six Chinese firms, including DeepSeek and Moonshot AI, of aggressive AI-model distillation since late 2024.

  2. Why it matters

    This is the most detailed accusation yet, replacing vague warnings with a call to secretly switch targeted Chinese users to inferior models without notice.

  3. What to watch

    The plan hinges on whether US firms can implement the tricky secret-switching mitigation without frustrating legitimate users, ahead of a Trump-Xi meeting on September 24.

WHO IT HITSEnterprise IT teams and security operations at US AI firms will have to implement the requested mitigations, potentially degrading service for legitimate users who get mistaken for attackers.

Ask the AI about this article →

Summaries like this, in your inbox every morning.

Context & Analysis

The joint release escalates a months-long dispute. It follows earlier accusations—OpenAI's against DeepSeek and Google's against Gemini cloning attempts—but this statement by US agencies stands out as the government's most detailed accusation yet. The agencies allege stolen capabilities "form the core—not merely a supplement" of China's AI strategy.

The proposed defenses are as notable for their risks as their intent. The idea of secretly switching suspected attackers to less-capable models is acknowledged as technically challenging, partly because Chinese firms have adaptive systems that can detect degradation and switch back within 24 hours. The more significant risk is that this policing could catch legitimate users in the crossfire, reducing their experience without notice, a fate OpenAI has faced backlash for before.

The effectiveness of this strategy will likely hinge on the delicate balance between security and user experience. As tensions rise, China has defended itself by suggesting US firms also use Chinese models. This backdrop makes the upcoming meeting between Donald Trump and Chinese President Xi Jinping on September 24 a key moment to watch for how this dispute plays out diplomatically.

FAQ
Which Chinese firms are accused?
The US accused DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of attacking US models since at least late 2024.
What does the US recommend firms do?
Agencies suggest that when suspicious activity is flagged, US firms should subtly alter responses or secretly and without notice switch malicious accounts to an inferior model.
How did China respond to the accusations?
A Chinese Foreign Ministry spokesperson, Mao Ning, called the claims groundless, and defended China's AI progress as a result of scientific and technological self-reliance.
Ars Technica AIRead Original Article

Get the latest AI Safety & Alignment news every morning

For example, today's edition would include:

  • Rethinking the perimeter: defense and supply chain in the AI eraDIGITIMES Asia · 4h ago
  • OpenAI agents hit RubyGems, undisclosed since May 12thSimon Willison's Weblog · 7h ago
  • AI opens supply chains to hackers, and fights themTop Companies AI · 11h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleApple says raw audio from Siri Audio Intelligence stays inaccessible to it