THE NEW AI CYBER WAR

AI Becomes the New Battleground
The US-China technology rivalry is moving into a new phase. On September 8, 2026, US intelligence and law-enforcement agencies accused six China-based artificial intelligence companies of conducting what they described as “aggressive, malicious and targeted” distillation of US frontier AI models at industrial scale. The companies identified include DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The allegations add a new dimension to wider competition over artificial intelligence. Unlike conventional cyber espionage, the issue is not necessarily about obtaining confidential files or stealing an entire model. Instead, the U.S. says Chinese companies used repeated interactions with advanced American models to extract useful capabilities and incorporate them into their own systems. This makes AI model security an increasingly important part of the broader technology rivalry.

What Is AI Distillation?
Distillation itself is not an inherently malicious technique. It is a legitimate machine-learning method in which outputs of a larger and more capable model are used to train a smaller or more specialized model. The concern raised by Washington is the scale and purpose of the alleged activity.
According to US officials, Chinese companies used variants of models developed by American firms including Anthropic, OpenAI, Google and SpaceX. The objective, according to allegations, was to obtain capabilities such as reasoning, coding and other advanced functions without having to reproduce the entire research and development process independently.
The approach could potentially reduce the time and resources required to develop competitive systems. Rather than building every capability from the ground up, developers can learn from the behaviour of an already advanced model.
Beyond Conventional Cyber Espionage
The development is significant because it changes the traditional understanding of cyber espionage. For decades, cyber operations have focused heavily on obtaining documents, credentials, communications and intellectual property. AI introduces another target: capability itself.
A model can contain valuable knowledge even when its underlying weights are never directly accessed. Repeated queries can reveal how a system reasons, writes code, solves technical problems or responds to specialised tasks. If those outputs are collected systematically and used for training, they can become a resource for developing another model.
This creates a difficult security problem. Protecting an AI system is therefore no longer simply a matter of securing servers and preventing unauthorised access. Companies must also consider how their models are being queried and whether unusual patterns of interaction indicate attempts to reproduce their capabilities.
Why It Matters to National Security
Washington's concern extends beyond commercial competition.
US officials argue that advanced AI capabilities could contribute to military applications, cyber operations and other national-security capabilities. The alleged distillation activity therefore forms part of a larger US effort to prevent sensitive technologies from accelerating China's technological and military development. The issue is particularly important because AI development
increasingly depends on access to computing power, advanced semiconductors, data and specialized research. Washington has already imposed extensive controls aimed at limiting China's access to some advanced chips and related technologies. If sophisticated AI capabilities can instead be acquired indirectly through interaction with existing models, those controls become more complicated.
The emerging challenge is therefore not simply who has the best AI model, but how easily that advantage can be transferred to another system.
A New Layer of US-China Competition
The accusations come at a sensitive moment in relations between Washington and Beijing. The two countries are preparing discussions on AI safety, while their broader technology competition continues across semiconductors, cloud computing, telecommunications and advanced computing.
The timing gives the latest allegations additional significance. AI is simultaneously becoming an area of confrontation and one in which both sides recognise the need for some form of dialogue.
That creates an unusual balance. Washington wants to protect the technological advantage of its leading AI companies, while Beijing has strong incentives to accelerate domestic AI development. At the same time, both countries face risks from increasingly capable systems, including their potential use in cyber operations.
The Next AI Security Challenge
The latest dispute suggests that the future of AI cybersecurity may not be limited to protecting models from conventional hacking.
Companies may increasingly have to defend against attempts to systematically reproduce the behaviour and capabilities of their systems. That could involve stronger API monitoring, limits on automated querying, detection of unusual usage patterns and greater controls over access to high-end models.
But technical measures alone may not resolve the problem. As AI systems become more capable and widely accessible, the boundary between legitimate research, competitive development and technological extraction could become increasingly difficult to define.
The U.S. allegations against Chinese AI companies therefore point to a broader transformation in the global technology competition. The next generation of strategic advantage may depend not only on who develops the most capable artificial intelligence, but also on who can protect, reproduce and control access to that capability.
The emerging AI race is no longer only about building bigger models. It is increasingly about controlling the knowledge and capabilities that those models represent.
Comments
Login to comment
No comments yet. Start the conversation.