Us ai giants unite to thwart chinese model extraction

A clandestine collaboration is brewing within the US artificial intelligence landscape. OpenAI, Anthropic, and Google, typically fierce competitors, are sharing information to combat a growing threat: the illicit extraction of data from their leading AI models by Chinese entities seeking to gain an edge in the global AI race. The stakes? Billions of dollars and, increasingly, national security.

The shadowy practice of adversarial distillation

The shadowy practice of adversarial distillation

The core of the issue lies in a technique called adversarial distillation. Essentially, it involves using a sophisticated, proprietary AI model – like OpenAI’s GPT-4 – to train a smaller, less expensive “student” model. While distillation itself isn't inherently malicious – it's often used to create more efficient versions of existing models – its unauthorized application, particularly by rivals in nations like China, is raising serious red flags. These copied models, often open-source, undercut the market, erode the value of Silicon Valley's massive investments, and, worryingly, can lack critical safety protocols.

According to sources within the Frontier Model Forum, a non-profit industry organization established last year by these companies and Microsoft, the exchange of intelligence focuses on identifying and thwarting attempts at this “adversarial distillation.” Officials within the US government have reportedly estimated that this intellectual property theft costs Silicon Valley labs billions of dollars annually – a staggering figure that underscores the gravity of the situation.

OpenAI, while confirming its participation in the data-sharing effort, has publicly accused DeepSeek, a Chinese AI startup, of attempting to exploit its technologies, as detailed in a recent memo sent to Congress. The memo alleges DeepSeek is actively working to create a new version of its chatbot using these illicit methods. Google and Anthropic have declined to comment on the matter, a silence that speaks volumes about the sensitivity of the issue.

The rise of DeepSeek’s R1 model in early 2025 served as the initial catalyst for this concern, prompting investigations into whether the company had improperly harvested data from US models. Now, Anthropic has gone so far as to block access to its Claude chatbot for Chinese-controlled entities, and has identified three Chinese labs engaging in unauthorized model extraction. The threat, they assert, extends beyond individual companies and represents a significant risk to national security, particularly as these copied models often lack the safety measures built into their originals.

This cross-company information sharing mirrors practices common in the cybersecurity industry, where firms routinely exchange data on attacks and vulnerabilities. The US government, echoing sentiments from the Trump administration, is reportedly supportive of such data sharing initiatives to counter malicious data collection.

The current collaboration, however, is hampered by antitrust concerns, leaving companies hesitant to share too much information. Clarity from the US government regarding permissible data sharing practices would be a significant boon. With open-source AI models continuing to proliferate in China—and the possibility of a significant DeepSeek upgrade looming—the pressure on US AI leaders to defend their innovations is only intensifying. The volume of large-scale data requests alone offers a measurable indication of the scope of the problem.