U.S. intelligence and cybersecurity agencies accuse Chinese AI companies of systematically extracting capabilities from American frontier models. Beijing calls the allegations groundless. Behind the dispute is a larger question: when does learning from an AI model stop being ordinary technological competition and become an issue of national security?
By Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)
The U.S.–China technology competition has entered a new domain.
The strategic asset at the center of the dispute is no longer only a semiconductor, a data center or an advanced manufacturing process.
It is the behavior of an artificial intelligence model.
On September 8, the U.S. National Security Agency, Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency issued an unusual joint cybersecurity advisory accusing China-based artificial intelligence companies of conducting industrial-scale campaigns to extract capabilities from American frontier AI models.
The agencies describe the activity as systematic knowledge distillation: using the outputs of highly capable models to help train other models to reproduce portions of their functionality.
Distillation itself is not new.
It is an established technique in machine learning.
The U.S. advisory explicitly acknowledges that legitimate distinction.
The accusation is instead about scale, intent and access.
According to U.S. officials, Chinese companies have distributed requests across model providers, cloud platforms and other infrastructure in ways designed to avoid detection while systematically extracting restricted capabilities from American systems.
The advisory argues that this allows Chinese developers to reduce some of the enormous research, compute, electricity and engineering costs required to develop frontier models independently.
China rejects that characterization.
On September 9, Beijing described the American allegations as lacking factual and legal foundations, characterized distillation as a widely used neutral technical method, and accused Washington of using technological restrictions to suppress competition.
The disagreement might initially resemble another commercial dispute over intellectual property.
It is becoming something much larger.
Washington is effectively making the argument that certain AI capabilities should be treated as strategic national assets.
And once that principle is accepted, the geopolitics of artificial intelligence changes significantly.
The Strategic Asset Is Moving Up the Stack
For years, U.S. technology policy toward China concentrated heavily on hardware.
Advanced semiconductors mattered.
Semiconductor-manufacturing equipment mattered.
High-performance computing mattered.
Data-center infrastructure mattered.
The underlying strategic logic was straightforward.
Advanced AI requires enormous computational resources. Restricting access to the most sophisticated chips could therefore slow the development of competing frontier systems.
But hardware controls have an inherent limitation.
They protect the inputs required to build advanced AI.
They do not necessarily protect the capabilities produced once the model has been built.
Frontier models increasingly expose those capabilities through commercial interfaces.
A user does not need possession of the model’s training infrastructure to interact with it.
The model can be queried remotely.
Its responses can be analyzed.
Its behavior can be studied.
And, under some conditions, its outputs can become training material for another system.
This moves the strategic competition upward.
The contested resource is no longer simply the chip.
It is the capability encoded in the model.
What Distillation Changes
Knowledge distillation is normally discussed as an engineering technique.
A more capable model can help train a smaller or less expensive model by generating examples, reasoning patterns or other outputs that become useful training material.
There are legitimate reasons to do this.
AI developers use distillation to improve efficiency.
Researchers study it.
Companies use related techniques to produce smaller models capable of performing specialized tasks.
The geopolitical problem begins when the teacher and student belong to competing technological ecosystems and the model provider has not authorized its system to be used for that purpose.
At sufficient scale, distillation creates an unusual form of technological transfer.
The recipient does not steal the semiconductor factory.
It does not necessarily obtain the original source code.
It does not receive the model weights.
It does not reproduce the complete training dataset.
Instead, it learns from the behavior of the finished system.
This is what makes the current dispute strategically difficult.
Existing concepts of technology protection were built primarily around controlling physical goods, software, intellectual property and technical knowledge.
Frontier AI introduces another category:
capability extraction through interaction.
The Economics Matter
The U.S. accusation is important partly because frontier AI is extraordinarily expensive.
Building leading systems requires more than an algorithm.
It requires large quantities of advanced computing hardware.
Electricity.
Data-center infrastructure.
Researchers.
Engineers.
Training data.
Model evaluations.
Security infrastructure.
Repeated experimentation.
And time.
These costs create part of the competitive advantage enjoyed by frontier laboratories.
If another developer can reproduce meaningful portions of a model’s capabilities by extensively querying an already trained system, the economics of technological competition begin to change.
The first company pays the enormous cost of discovery.
The second may obtain some of the resulting capability at a fraction of that cost.
This does not mean distillation can simply reproduce an entire frontier model.
Nor does it eliminate the importance of independent research, engineering or computing infrastructure.
But even partial capability transfer can matter when technological competition is measured in months rather than decades.
The strategic value lies in compression.
The follower may not need to reproduce the leader’s entire research process.
It may need only to shorten it.
From Intellectual Property to National Security
This is where the September 8 advisory becomes particularly significant.
The NSA, FBI and CISA are not intellectual-property regulators.
Their involvement signals how Washington now understands the issue.
The advisory links improvements in Chinese AI capabilities to possible improvements in military and cyber capabilities.
That framing transforms the policy question.
If the issue were simply unauthorized commercial copying, the primary response would involve contracts, intellectual-property law and platform enforcement.
If model capabilities are national-security assets, an entirely different policy architecture becomes possible.
Export controls.
Identity verification.
API restrictions.
Cloud-provider monitoring.
Know-your-customer requirements.
Access controls.
Intelligence collection.
International coordination.
And potentially sanctions.
The policy boundary between cybersecurity and economic security consequently begins to disappear.
Protecting the model becomes part of protecting national technological power.
The Model Is Becoming Dual-Use Infrastructure
Frontier AI is increasingly difficult to classify as an ordinary commercial product.
The same model can assist with software development and vulnerability research.
It can analyze scientific literature.
It can support intelligence analysis.
It can improve industrial design.
It can accelerate research.
It can help automate administrative tasks.
And increasingly capable models may also assist offensive cyber operations.
This dual-use character explains why the American government is concerned about capability extraction.
A model does not need to contain a classified weapons design to possess national-security relevance.
General capability itself can become strategically valuable.
The better a system becomes at coding, reasoning, scientific analysis and autonomous task execution, the greater its potential utility across civilian and military domains.
That creates a policy problem familiar from other dual-use technologies but much harder to regulate.
A jet engine can be physically inspected.
A semiconductor can be tracked through supply chains.
An AI capability may be accessible through an API from another continent.
Strategic technology has become remotely queryable.
A New Form of Cybersecurity
The U.S. advisory also expands the meaning of AI cybersecurity.
Traditionally, securing an AI company meant protecting its internal networks.
Preventing intrusion.
Protecting model weights.
Securing training infrastructure.
Defending employees against espionage.
Preventing data theft.
Those protections remain essential.
But industrial-scale distillation creates a different security problem.
The attacker may not need to breach the network.
It may interact with the product exactly where legitimate customers do.
The security challenge moves to the interface.
Providers must detect unusual patterns across accounts, subscriptions, APIs, cloud services and intermediaries.
The distinction between customer behavior and capability extraction becomes a security boundary.
This resembles abuse detection more than traditional perimeter defense.
And because sophisticated actors can distribute activity across accounts, companies and jurisdictions, no single provider necessarily sees the entire operation.
The September 8 advisory therefore emphasizes coordination across the AI ecosystem.
That is strategically important.
Frontier-model security may increasingly require collective defense.
The Attribution Problem Is Different Here
Traditional cyber attribution asks:
Who penetrated the network?
Model extraction asks something more complicated:
Who is behind apparently legitimate access?
A developer can create multiple accounts.
Intermediaries can purchase subscriptions.
Requests can move through cloud platforms.
API aggregators can obscure the original customer.
Activity can be distributed geographically.
Individual interactions may appear ordinary.
Only when they are analyzed collectively does the pattern become visible.
This creates an intelligence problem.
Detection requires providers to compare signals.
Cloud companies may possess one part of the evidence.
Model providers another.
Payment systems another.
Government agencies may possess intelligence unavailable to industry.
The resulting defense architecture therefore resembles the public-private structures developed for sophisticated cyber threats.
But the protected object is different.
The target is not merely a network.
It is knowledge encoded in model behavior.
China’s Response Reveals the Diplomatic Fault Line
Beijing’s September 9 response is as important as the American accusation.
China argues that distillation is a normal technical method and accuses the United States of attempting to monopolize AI development.
That position exposes the international governance problem.
Both sides can begin with technically plausible propositions.
Distillation is a legitimate machine-learning technique.
And unauthorized extraction of proprietary capabilities can create legitimate security concerns.
The disagreement lies in determining when one becomes the other.
That boundary currently lacks a widely accepted international definition.
How many model queries constitute extraction?
Does intent matter?
Does violating commercial terms transform research into malicious activity?
Should governments treat model outputs as controlled technology?
Can a state restrict foreign developers from learning from publicly accessible commercial systems?
What happens when companies in multiple countries use similar techniques?
And how should restrictions distinguish commercial competition from activity conducted for military purposes?
These questions will become increasingly difficult as AI systems spread internationally.
The Risk of a Global AI Access Regime
Washington may eventually conclude that protecting frontier models requires controlling not merely chips but access.
That would have major international consequences.
Advanced AI services could increasingly resemble controlled technological infrastructure.
Access might depend on identity.
Nationality.
Organization.
Location.
Intended use.
Security vetting.
Or relationships with particular governments.
This would represent a fundamental change in the internet-era model of software distribution.
For decades, the dominant assumption was that software could be made globally accessible while sensitive physical technologies were controlled separately.
Frontier AI challenges that distinction.
The software itself may embody the strategically sensitive capability.
The result could be an emerging geography of AI access.
Trusted countries receive broad access.
Strategic competitors receive restricted access.
Unknown users receive limited capabilities.
Sensitive functions require verification.
Allied governments negotiate privileged arrangements.
The global AI ecosystem could gradually divide into security blocs.
AI Sovereignty Will Accelerate
Restrictions can also produce the opposite of their intended effect.
The more the United States treats frontier AI as a strategic asset, the stronger the incentive for China and other countries to build independent AI ecosystems.
This is already visible in semiconductor policy.
Export restrictions encouraged China to invest heavily in domestic chip production and alternative technology stacks.
AI access controls could produce similar pressure.
Countries may seek domestic models.
Domestic cloud infrastructure.
Domestic training data.
Domestic accelerators.
Domestic safety frameworks.
And domestic standards.
This is the emerging politics of AI sovereignty.
Governments increasingly want access to advanced AI without becoming strategically dependent on another country’s companies.
The U.S.–China distillation dispute may accelerate that trend.
The Alliance Question
The American position also creates questions for allies.
If frontier AI capabilities are national-security assets, Washington will likely need international cooperation to protect them effectively.
Distillation campaigns can move through foreign cloud providers and third-country infrastructure.
Accounts can be purchased internationally.
Companies can establish subsidiaries.
Intermediaries can operate from jurisdictions with different rules.
Unilateral restrictions therefore have limits.
The United States may increasingly ask allies to participate in AI capability protection in much the same way that it has sought cooperation on semiconductor export controls.
That could make AI model access another subject of alliance diplomacy.
Countries may face pressure to choose between open access and coordinated technology controls.
For Europe, Japan, South Korea, Australia and other advanced economies, the issue could become particularly important.
AI security policy would no longer concern only domestic regulation.
It would become part of foreign policy.
Distillation Could Become the Next Export-Control Battlefield
The semiconductor competition established one model of technological containment.
Identify strategic technology.
Restrict access.
Coordinate with allies.
Monitor circumvention.
Update controls as technology changes.
Model capability protection may now be moving toward a similar structure.
But controlling AI outputs will be substantially harder than controlling semiconductor-manufacturing equipment.
A chipmaking machine is physical.
Model interaction is digital.
It can happen millions of times across global networks.
The technology being protected can simultaneously be a commercial service used by ordinary customers.
This creates an enforcement challenge that export-control institutions were not designed to solve.
The future system may therefore combine cybersecurity monitoring with trade controls.
AI companies detect suspicious extraction.
Cloud providers identify infrastructure.
Intelligence agencies connect activity to foreign actors.
Governments determine whether restrictions or sanctions are justified.
The architecture of technological security becomes increasingly integrated.
The Danger of Overreach
There is also a risk in expanding the national-security definition too far.
If every instance of learning from another model becomes characterized as malicious extraction, legitimate research and competition could suffer.
AI development has always involved learning from existing work.
Academic papers circulate internationally.
Open-source models are studied and modified.
Researchers reproduce techniques.
Companies benchmark against competitors.
Knowledge diffusion is part of technological progress.
The policy challenge is therefore not to prevent learning.
It is to distinguish legitimate learning from systematic unauthorized capability extraction.
That distinction must be technically credible.
Otherwise, national-security policy can become indistinguishable from technological protectionism.
China is already making precisely that argument.
For Washington to maintain international credibility, it will need more than accusations.
It will need clear standards explaining what behavior crosses the line and why.
Cyber Diplomacy Now Has a Model Problem
This dispute illustrates how rapidly the agenda of cyber diplomacy is expanding.
Cyber diplomacy once concentrated largely on malicious state behavior in networks.
Then it expanded toward ransomware, supply chains, critical infrastructure, surveillance technologies and cyber mercenaries.
Frontier AI introduces another category.
Governments must now negotiate expectations around the security and cross-border use of advanced computational capabilities themselves.
This could eventually require international understandings on model access, capability extraction, military use, safety testing and state responsibility for commercial AI actors.
The negotiations will be difficult.
The United States and China have fundamentally different strategic incentives.
Yet complete absence of rules carries its own risks.
If every major power treats foreign AI systems simultaneously as commercial products, intelligence targets and strategic assets, technological competition can increasingly resemble cyber conflict.
That is not a stable equilibrium.
Bottom Line Assessment
The September 8 U.S. advisory and China’s September 9 response mark a potentially important transition in the geopolitics of artificial intelligence.
The dispute is not really about whether knowledge distillation exists.
Everyone agrees that it does.
The strategic disagreement concerns what distillation means when it occurs between technological competitors at industrial scale.
Washington increasingly views frontier-model capabilities as national-security assets.
Beijing argues that restrictions on learning from those systems amount to technological containment.
Both positions point toward the same larger reality.
AI competition is moving beyond control of physical infrastructure.
The semiconductor remains strategic.
The data center remains strategic.
The cloud remains strategic.
But the model itself is becoming strategic infrastructure.
That changes cybersecurity.
It changes export controls.
It changes alliance politics.
And it changes cyber diplomacy.
The central question of the next phase of AI competition may therefore not be simply who can build the most capable model.
It may be:
Who is allowed to learn from it?
The answer will help determine whether frontier AI remains part of a globally interconnected technology ecosystem—or becomes one of the most tightly contested strategic resources of the emerging international order.
Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)


Leave a comment