U.S. Agencies Accuse Six Chinese AI Firms of Siphoning Claude, GPT, Gemini and Grok
Trending Topics Jakob Steinschaden ● Covered by 3 sources
U.S. agencies say six Chinese AI firms scraped Claude, GPT, Gemini and Grok at scale. Washington is calling China’s model gap theft, not magic.
Based on reporting by Trending Topics, Jakob Steinschaden — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
The NSA, FBI and CISA have accused six Chinese AI companies of systematically extracting the capabilities of U.S. frontier models since at least late 2024. The firms named in the joint advisory are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.ai. The targets are Claude, GPT, Gemini and Grok. Beijing has rejected the allegations.
The charge is not just that these companies copied a few outputs here and there. The advisory says the campaigns were “aggressive, malicious and targeted,” and says they were likely carried out with Chinese government awareness. DeepSeek is accused of harvesting reasoning and domain knowledge for its R1 and V3 models. The agencies also point out that the often-cited 5.6 million dollar training budget for DeepSeek does not include the cost of data obtained this way.
The rest of the picture reads like an industrial pipeline. Moonshot AI is said to have pulled millions of interactions from Claude and GPT-4o for Kimi. Alibaba allegedly used Claude and GPT-5 output to improve software engineering and customer service in Qwen. MiniMax is accused of chasing chain-of-thought and reinforcement learning data, and of trying prompt injection against Claude Code. StepFun is accused of copying reasoning and coding skills, while Z.ai is said to have extracted “billions of tokens” from GPT-5.5 and Claude Opus by the middle of this year.
And the access methods sound as messy as they are deliberate. The advisory describes bulk-created or purchased accounts, shared premium subscriptions, VPNs, cloud providers and API proxies that dodge geographic limits and usage caps. Some of that access is sold on Chinese marketplaces such as Taobao and Xianyu, while aggregators strip metadata to hide where requests come from. The requests themselves were often highly coordinated, sometimes running for days or months and reaching thousands to millions of calls for a single subject area.
The most awkward recommendation is also the most revealing one: instead of just blocking suspected attackers, the advisory suggests making their answers worse and more error-prone. That is a neat little trap until a paying customer gets tagged by mistake. And yes, the whole fight sits inside a familiar contradiction: everyone wants AI progress to be open, until someone else starts training on it.
My take — AI-written commentary, not fact-checked reporting
This is the part of AI everybody pretends is temporary: the strongest models are both products and raw material. Open gets sold as virtue until the bill arrives, then the answer is proxies, countermeasures and quietly broken outputs. Very efficient industry, right up until it has to trust its own gatekeeping.
Read more about this at: Trending Topics