Restoring America

Conservative values, National renewal

Menu

Trump should crack down on Chinese AI distillation

Published October 9, 2026 11:29am ET | Updated October 9, 2026 11:29am ET



President Donald Trump’s pair of September summits addressed two of his administration’s most consequential legacies: a steadier relationship with China and continued American leadership in artificial intelligence. Trump’s meeting with Xi Jinping opened a channel to discuss risks posed by powerful AI systems, while his “superintelligence summit” with technology executives produced a landmark set of commitments on AI safety.

With the dust now settled from high-level diplomacy, the administration can turn its attention to Trump’s upcoming meetings with Xi in Shenzhen and Miami. On AI, one question should guide American priorities: What is to be done about the Chinese labs accused by the U.S. government of systematically extracting and replicating American technology?

Since at least 2025, Chinese AI labs have relied on “distillation” — training one AI system using another model’s answers — to closely mirror the capabilities of American frontier models. Distillation is a scientific technique with many legitimate uses across the AI industry. But the campaigns waged by Chinese AI labs against their American competitors have involved organized deception to acquire restricted and proprietary capabilities.

On Sept. 8, the FBI, NSA, and Cybersecurity and Infrastructure Security Agency formally accused six Chinese AI developers — DeepSeek, Moonshot, Alibaba, MiniMax, StepFun, and Z.ai — of waging industrial-scale extraction campaigns against OpenAI, Anthropic, and Google. To do so, Chinese labs have propped up tens of thousands of fraudulent accounts and attempted to conceal their behavior by relying on intermediaries to evade American companies’ access controls. OpenAI added to the record on Sept. 30 when it disclosed a campaign by its Chinese competitor, Moonshot, to extract its proprietary model reasoning.

China has responded by claiming distillation is a legitimate training technique and maintains that nothing untoward has happened. Its Ministry of Commerce has called American allegations “groundless,” argued that distillation is a neutral and widely used technique employed by firms around the world, and accused Washington of using the issue to “contain” Chinese competitors. This position ignores the fact that Chinese firms systematically violated American companies’ terms of service to evade access restrictions and extract proprietary capabilities at scale.

The Trump administration has several tools at its disposal to counter China’s AI extraction. When Moonshot released its Kimi K3 model in July, for example, Treasury Secretary Scott Bessent warned the company could be subject to blacklisting or financial sanctions. For example, the Commerce Department’s Entity List could be used to block foreign companies from importing certain American technology. Likewise, the Treasury’s existing cyber authorities can be deployed against malicious activities that threaten American national security or economic interests, denying access to American cloud computing and paid-model APIs. Restricting Chinese AI labs from dealing with American customers could also put at risk valuable sources of revenue ahead of their vaunted IPOs.

Now is the time to deploy this leverage. The administration could begin by directing Treasury and Commerce to prepare sanctions packages for Chinese firms the government has evidence are engaged in industrial-scale extraction. These measures should extend beyond six named PRC labs to include their proxy networks and cloud intermediaries that knowingly enable them. The objective should be to deter illicit distillation by making it sufficiently expensive to become unattractive as a commercial strategy.

The administration should also make clear what would be required for relief. Chinese firms seeking removal or exemption from American blacklisting should commit to complying with U.S. law and submit to regular compliance reviews modeled on existing end-use checks. This would give Washington something concrete to ask from across the table in Shenzhen and Miami: not a vague demand that Beijing “stop stealing AI,” but enforcement actions pegged to specific changes in Chinese conduct.

Congress is considering a parallel approach designed to strengthen Trump’s hand. The bipartisan BLADE Act, introduced by Sen. Bill Hagerty (R-TN) and colleagues, would require Commerce to coordinate with industry to identify and sanction foreign model extraction operations and suppliers of fraudulent API accounts.

CHINA’S ‘OPEN SOURCE’ AI ISN’T A GIFT — IT’S A TROJAN HORSE

To be clear, the United States is not going to sanction China from building competitive AI. Chinese labs are conducting breakthrough AI research in their own right and will continue making leaps in capability even without fraudulently skimming U.S. reasoning. What Trump can do is decide whether the Chinese companies his administration has accused of rampant IP theft should continue enjoying unrestricted access to American technology, infrastructure, and markets.

Trump is right to seek a more stable relationship with Beijing. His meetings with Xi in Shenzhen and Miami offer an opportunity to anchor that stability in one of the relationship’s most consequential areas. It is possible — necessary, in fact — to continue discussing shared AI risks with China while making clear that organized efforts to steal American technology carry meaningful consequences.

Ryan Fedasiuk is an AEI fellow.