US AI firms flag distillation attacks as China vows retaliation against any restrictions

American AI developers and the government are increasingly worried about distillation attacks that let foreign actors train cheaper models by mimicking frontier AI outputs. China has denied these allegations and threatened countermeasures if the US uses them as a pretext to contain its AI progress. Efforts to block such attacks are complicated by the purchase of third-party conversation logs.
Distillation attacks involve feeding a smaller model the input-output pairs of a frontier system, allowing it to replicate advanced reasoning without equivalent compute investment. Industry observers speculate this method powered rapid Chinese progress with Deepseek in 2025 and Kimi K3 in 2026, which approached Western capability at far lower cost.
Countermeasures are complicated because attackers also purchase legitimate third-party conversation logs, bypassing direct access restrictions. The dispute is further complicated by Western developers' own history of training on scraped or pirated data, and by the contrast between proprietary US models and China's open-weight releases. Major US labs pledged joint defense efforts earlier in 2026.
This dispute could reshape global AI competition, potentially accelerating capability diffusion while straining US-China relations. If restrictions tighten, businesses and consumers worldwide may face fragmented AI ecosystems with divergent standards and availability. Smaller developers might benefit from cheaper distilled models, but security-driven overregulation could slow beneficial innovation. The outcome may determine whether frontier AI remains concentrated in a few firms or becomes broadly accessible across borders.