China’s AI Labs Ran Industrial-Scale Operations to Extract Capabilities from American Models, CNAS Finds

A major new report from the Center for a New American Security (CNAS) has concluded that Chinese AI laboratories conducted systematic, industrial-scale campaigns to extract capabilities from leading American AI models, and that the operations were far larger and more coordinated than previously understood.

The report, titled “Adversarial Distillation: China’s Campaign to Extract American AI Capabilities” and authored by CNAS researchers Daniel Remler and Ben Hayum, was published on June 2, 2026. It presents what may be the most detailed public accounting to date of how Chinese AI developers have systematically exploited API access to frontier Western models to train their own systems, at a scale suggesting coordinated institutional effort rather than opportunistic individual behavior.

What Distillation Actually Means and Why It Matters

To understand the significance of the CNAS findings, it helps to be precise about what distillation is and is not. Distillation, in the AI context, refers to the process of using the outputs of a more powerful model to train a smaller, cheaper model. The student model learns to mimic the teacher model’s reasoning, tone, and problem-solving patterns without ever directly accessing the underlying weights or architecture of the original system.

This makes distillation categorically different from conventional model theft. There is no server breach, no stolen code, no exfiltrated file. Instead, the operation works through the very access mechanisms that API providers make available commercially. The extraction happens in plain sight, embedded in what looks like ordinary usage, until the volume and pattern reveal something else entirely.

According to the CNAS report, DeepSeek, Moonshot AI, and MiniMax collectively generated more than 16 million exchanges with Anthropic’s Claude model. The estimated token volume from these interactions ranged between 150 and 400 billion tokens, a figure that speaks to the industrial character of the campaign. To put that in context, large-scale pretraining runs for frontier models are often measured in the trillions of tokens drawn from the entire open internet. Generating hundreds of billions of tokens through deliberate API queries, focused on specific capability domains, represents a highly targeted extraction effort.

Proxy Networks and Fraudulent Accounts at Scale

The report goes further than documenting sheer volume. It details the operational infrastructure that enabled these campaigns. In one documented case, a single proxy network operated more than 20,000 fraudulent accounts in parallel. This points to a deliberate effort to circumvent usage monitoring, rate limits, and the terms-of-service enforcement mechanisms that API providers rely on to detect anomalous behavior.

This is not the profile of a research team or a handful of engineers pushing the boundaries of what an API allows. It describes an organized, resourced operation with the sophistication to build and manage large-scale account infrastructure specifically designed to avoid detection. The report characterizes the overall pattern as systematic and institutional rather than the work of individual bad actors acting without coordination.

The three companies named (DeepSeek, Moonshot AI, and MiniMax) are among the most prominent names in China’s current AI wave. DeepSeek, in particular, has attracted enormous international attention following the release of its R1 and subsequent models, with analysts debating the extent to which its capabilities reflect genuine algorithmic innovation, efficient training, or access to high-quality synthetic data generated by more powerful external systems. The CNAS report adds significant texture to that debate.

Legislative Response Takes Shape

The findings arrive as Congress has already begun moving on the issue. The Deterring American AI Model Theft Act (H.R. 8283) passed the House Foreign Affairs Committee unanimously on April 22, 2026, a bipartisan signal that legislators view API-based extraction as a genuine national security concern warranting a legal response. The unanimous vote across party lines is notable in a polarized environment and suggests the issue has achieved a rare degree of cross-aisle consensus.

The broader policy backdrop matters here. The United States has already pursued aggressive export controls on advanced semiconductors and chipmaking equipment flowing to China, an effort that EastFrontier has covered extensively. The CNAS report highlights that hardware controls, while consequential, address only one dimension of the technology transfer challenge. If the outputs of frontier AI models, trained on enormous compute budgets using restricted hardware, can be systematically harvested through API access and used to bootstrap competitive systems, then chip controls alone cannot secure the capability gap that policymakers are trying to preserve.

This tension between open API access, which underpins the commercial business models of companies like Anthropic and OpenAI, and the national security imperative to limit capability transfer, is one the industry has not yet resolved. Restricting API access too aggressively risks fragmenting the global AI ecosystem and disadvantaging American developers in international markets. But maintaining unrestricted access, the CNAS report argues, effectively subsidizes the development of competitor systems at an industrial scale.

Context Within China’s Broader AI Acceleration

The report lands at a moment when China’s AI sector is expanding rapidly across nearly every dimension. Chinese AI companies aggressively presented at international forums this year, and domestic AI deployment across industry and manufacturing has accelerated considerably. The 9th Digital China Summit held earlier this year showcased 120 AI innovations and outlined a new national digital roadmap through 2030.

Within that context, the CNAS report raises uncomfortable questions about how much of China’s rapid AI progress has been organically developed versus strategically extracted from frontier Western systems that Chinese developers accessed through commercial channels. The answer, the report suggests, is that the two are not cleanly separable, and that the current regulatory framework was not designed to handle operations at the scale that has apparently been underway.

The geopolitical dimensions of AI competition between the United States and China have become a defining feature of the current technological era. The CNAS report argues that adversarial distillation represents a third vector of capability transfer, alongside hardware smuggling and talent recruitment, that has until now received insufficient attention from policymakers, platform operators, and the public alike.

Whether the legislative response now advancing through Congress will prove adequate to the scale of what the report documents remains an open question. What the CNAS findings make clear is that the boundary between commercial AI infrastructure and national security infrastructure is considerably more porous than the architecture of today’s AI industry was built to acknowledge.