If one AI system can learn enough from another system’s answers to reproduce valuable capabilities, protecting frontier AI may require securing not only the model itself — but what the model is allowed to reveal.
WHAT’S HAPPENING
The NSA, FBI and CISA issued a joint cybersecurity advisory accusing China-based AI companies of conducting what the agencies describe as industrial-scale distillation campaigns against U.S. frontier AI models.
AI distillation itself is a legitimate and widely used technique. A smaller model can learn from the outputs of a more capable model, potentially gaining useful abilities without recreating the entire development process from scratch.
The U.S. agencies allege that some China-based companies are systematically using that process to extract restricted capabilities and proprietary features from American frontier models while distributing activity across multiple model providers, cloud platforms and infrastructure to make detection more difficult.
Reuters reports the U.S. identified companies including DeepSeek, Moonshot AI and Alibaba, and alleges that American models from companies including OpenAI, Anthropic and Google were targeted.
WHY IT MATTERS
The traditional technology-security problem is protecting the thing that was built.
Protect the chip.
Protect the source code.
Protect the data center.
Protect the model weights.
Distillation introduces a different problem:
A competitor may not need to possess the original AI system if it can repeatedly interact with it and learn enough from its behavior.
That means part of the economic value created by billions of dollars in compute, electricity, researchers and training could potentially be transferred through the model’s answers themselves.
The AI race therefore may not be only about who can build frontier intelligence first.
It may increasingly be about who can prevent that intelligence from being cheaply reproduced once other systems are allowed to interact with it.
WHO BENEFITS
AI developers that can legitimately use distillation can create smaller, cheaper and more specialized models without reproducing every step of frontier-model development.
Countries and companies trying to close an AI capability gap could also reduce the enormous cost and time required to train competitive systems from the ground up.
Cloud providers, cybersecurity companies and AI-model operators may see growing demand for tools capable of detecting unusual querying patterns and coordinated distillation activity.
WHO LOSES
Frontier-model companies face the possibility that some of the capabilities they spent enormous amounts of money developing can be partially replicated by competitors at substantially lower cost.
The U.S. government also views the issue as a national-security concern because increasingly capable models can contribute to cyber, military, scientific and economic capabilities.
But there is an important distinction: distillation is not inherently malicious or equivalent to conventional theft. The dispute centers on how the technique is being used, what access restrictions apply and whether proprietary capabilities are being systematically extracted in violation of those restrictions.
WHAT HAPPENS NEXT
Frontier AI companies are likely to become more aggressive about monitoring how their models are queried, limiting suspicious access patterns and coordinating with cloud and infrastructure providers.
That could create an entirely new security layer around artificial intelligence.
Because the most valuable thing inside a frontier model may no longer need to be physically stolen.
It may only need to be learned.