The White House has accused China-linked actors and other foreign entities of running industrial-scale AI model extraction and distillation campaigns against U.S. frontier AI companies, saying the operations use tens of thousands of proxy or fraudulent accounts, jailbreaking techniques, distributed probing, and iterative prompt engineering to copy proprietary model behavior at scale. A memorandum from Office of Science and Technology Policy Director Michael Kratsios said the activity targets American AI innovation without requiring a traditional network breach, and warned that derivative systems may reproduce benchmark performance while stripping away safety controls, neutrality safeguards, and other protections built into the original models.
Federal agencies have been directed to expand information sharing with AI firms and develop best practices for detecting, mitigating, and remediating the campaigns, with officials pointing to stronger telemetry, logging, identity controls, and real-time detection of distributed abuse as likely defenses. The administration is also weighing accountability measures, including possible sanctions and legal or export-control actions, while lawmakers advance legislation to identify and punish foreign actors targeting U.S.-owned AI models; China has rejected the allegations as "slander" and unjustified suppression, even as prior claims from OpenAI and Anthropic tied Chinese firms including DeepSeek, Moonshot, and MiniMax to large-scale distillation efforts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
By 2026-04-27, Americans for Responsible Innovation called on OSTP Director Michael Kratsios to block exports of advanced AI chips including Nvidia's H200 to China. The group argued that limiting compute access would make it harder for Chinese firms to train and deploy models derived from U.S. frontier AI systems.
On 2026-04-26, DeepSeek released a preview of its V4 large language model, describing it as its most powerful system yet with 1.6 trillion parameters and a 1 million-token context window. The model was optimized for Huawei Ascend AI processors rather than Nvidia hardware, signaling reduced reliance on export-restricted U.S. chips.
On or before April 24, 2026, Van Dyke was arrested in connection with the prediction-market case and then released on a $250,000 bond. The case was described as the DOJ's first public filing alleging insider trading through prediction markets.
By April 24, 2026, the Justice Department charged Master Sgt. Gannon Ken Van Dyke with using classified information from a January raid involving Nicolas Maduro to place roughly $33,000 in prediction-market bets that allegedly yielded nearly $410,000. Prosecutors said he also tried to conceal the proceeds and his identity through account deletion requests, cryptocurrency transfers, and a new brokerage account.
The House Foreign Affairs Committee unanimously advanced legislation to create a mechanism for identifying and punishing foreign actors that target U.S.-owned AI models. The move signaled growing congressional interest in penalties for AI model extraction.
After the White House accusations became public, China's embassy in Washington denied the claims, calling them slander or unjustified suppression of Chinese companies. The response marked Beijing's formal rejection of the U.S. allegations.
On April 23, 2026, the White House publicly said China-linked actors were trying to steal American AI through large-scale distillation and extraction campaigns. Officials framed the activity as an intellectual property and national security threat ahead of a planned Trump-Xi summit.
On or before April 23, 2026, OSTP Director Michael Kratsios issued a memorandum warning that China and other foreign actors were conducting industrial-scale campaigns to extract U.S. AI model capabilities using proxies, jailbreaking, and distributed accounts. The memo directed federal agencies to coordinate with industry on detection, mitigation, and possible accountability measures.
In April 2026, Anthropic introduced selective biometric identity verification as part of stronger access controls for its models. The move was aimed at restricting abuse and unauthorized access, and reportedly triggered parallel evasion services involving fake IDs, deepfake verification, and outsourced KYC completion.
In January 2025, OpenAI publicly accused DeepSeek of using model distillation to extract capabilities from U.S. AI systems. The allegation became an early public marker of concerns about Chinese-linked AI model extraction.
Before charges were filed, Polymarket identified suspicious trading tied to bets on Nicolas Maduro's capture and referred the matter to the Department of Justice. The company also cooperated with investigators during the case.
Before April 2026, the House Judiciary Committee held a hearing on China's theft of U.S. innovation, where evidence was presented about the economic impact of Chinese technology theft. The hearing helped elevate AI-related theft concerns in Congress.
At a later, unspecified date after OpenAI's allegation, Anthropic said DeepSeek, Moonshot, and MiniMax were involved in large-scale distillation activity targeting Claude, including use of mass-proxy methods. This expanded the list of accused firms and reinforced claims that the activity was systematic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
thediplomat.com
Open sourcechinatalk.media
Open sourcecfr.org
Open sourcescworld.com
Open sourcearstechnica.com
Open sourcenextgov.com
Open sourcetechrepublic.com
Open sourcefoxbusiness.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.