White House Flags China Over AI Distillation Attacks, Rolls Out Four Countermeasures

White House Flags China Over AI Distillation Attacks, Rolls Out Four Countermeasures

N
News Editor 01
2026-07-24 10:45:16
The White House OSTP said Chinese AI firms are conducting industrial-scale distillation attacks on leading U.S. model providers and outlined a four-part response focused on intelligence sharing, defense coordination, stronger safeguards, and potential penalties.
White HouseOSTPAI distillationChina AImodel security

The White House Office of Science and Technology Policy on April 23 issued NSTM-4, formally stating that Chinese AI companies have been conducting “industrial-scale” distillation attacks against major U.S. model developers. The memo says the copied models have had safety protocols systematically stripped away, and it lays out a four-part response now being put in motion.

Distillation is a standard machine learning technique in legitimate settings, where a smaller model learns from a larger one and delivers similar performance at lower cost. The concern described in NSTM-4 is unauthorized, systematic extraction from closed models. Michael J. Kratsios, Assistant to the President and OSTP official, said intelligence indicates foreign entities—primarily in China—have deliberately targeted leading U.S. AI firms for model distillation. In his description, the resulting models may not fully reproduce the original systems, but they can still be launched cheaply and appear competitive on selected benchmarks.

OSTP says copied models had safety controls removed

In a post from its official X account, OSTP added that the distilled copycat models had “stripped away safety protocols” and moved away from neutrality and truth-seeking. The agency said the methods involved tens of thousands of proxy accounts and jailbreaking techniques used to expose proprietary information from closed models at scale.

The White House statement follows earlier allegations already in the open. According to the source material, Anthropic said in February that DeepSeek, Moonshot, and MiniMax used about 24,000 fraudulent accounts to generate more than 16 million conversations with Claude. Anthropic said the effort was designed to extract core capabilities including agentic reasoning, coding and data analysis, rubric grading, and computer vision. The report describes that claim as the largest public allegation of an AI distillation attack on record so far.

Four action items cover intelligence, joint defense, and penalties

NSTM-4 lists four lines of action. The first is proactive intelligence sharing with U.S. AI companies so they can see how large-scale distillation attacks are being carried out. The second is helping the private sector improve defensive coordination. The third is working with private firms to build stronger technical barriers against these attacks. The fourth is exploring ways to make foreign actors bear consequences.

On that last point, retired four-star General Paul Nakasone, former NSA director and former head of U.S. Cyber Command, pointed to several possible tools in an interview: export controls, diplomatic protests, and tailored technology restrictions. The source also notes that NSTM-4 was released weeks before a possible Trump-Xi summit, placing AI distillation on the U.S. government’s formal agenda rather than leaving it as a private copyright dispute.

Token pricing highlights the economic incentive

The article also points to pricing gaps across the market. Claude Opus 4.6 was listed at $5 per million tokens, ChatGPT-5.4 Pro at $30, while DeepSeek V3.2 was priced at $0.26. That spread is presented as the economic driver behind distillation attacks: low API costs can be used to capture capabilities that would otherwise require major research spending and computing resources to build internally.

From OpenAI copyright allegations and a proposed “AI Theft Act” in Congress to the White House now framing the issue through a national security memo, the dispute over AI intellectual property and model security has moved well beyond a commercial fight. The next point of scrutiny is what concrete form those promised consequences for foreign actors will take.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.