The U.S. National Security Agency, the Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Administration recently jointly warned that some Chinese artificial intelligence companies are "industrialized scale" to evaporate knowledge on the U.S. front-end large models, through a large number of queries, model output and automation process extraction capabilities, and then used to train their own systems. U.S. side-named companies include DeepSeek, the dark side of the moon and Alibaba, etc. The Chinese side rejected the allegations, stressing that knowledge evaporation is a technology method widely adopted by the AI industry. The core of this dispute is no longer whether a company has "learned" another company, but who has the right to decide how artificial intelligence capabilities spread across borders, which training

"Devaporation" was originally a technical term and is now becoming a national security term.

In the field of machine learning, knowledge evaporation is not a mystery: smaller models improve their abilities by learning the output rules of stronger models. What really arouses the US government’s alertness is automated, scaled access to the business cutting-edge models and building training data with a lot of hints and outputs. If this process bypasses service terms, identity restrictions or access control, the US believes it will no longer be just normal research, but may become a pathway to systematic acquisition of technical capabilities.

The "technology transfer" of the AI era does not necessarily require theft of source code.As long as it is possible to observe on a large scale how models respond, reason, and handle complex tasks, the model itself can become a mine of knowledge that can be reversed.

The U.S. National Security Agency, a joint statement by the FBI and CISA, stated that the issue has gone from the intellectual property dispute between companies into the national security system.In the past, Washington restricted China's access to advanced GPUs, chip-making equipment and high-performance computing capabilities; now the focus is further extended to whether the model output itself constitutes a strategic resource that needs protection.

原始来源 · nsa.gov美国国家安全局等机构:警告中国AI企业大规模蒸馏美国前沿模型nsa.gov ↗

From chip blocking to “capability blocking,” the U.S. is raising a second wall

DeepSeek标志资料图|来源:Wikimedia Commons;RoadMaster19
DeepSeek标志资料图|来源:Wikimedia Commons;RoadMaster19 · 查看图片来源 ↗

The U.S. AI policy over the past few years has focused mainly on computing: limiting high-end chip exports, strengthening cloud computing censorship, and preventing advanced semiconductor equipment from flowing to China. But rapid progress in Chinese models such as DeepSeek reminded Washington that computing limitations cannot completely stop capability pursuit.

So the U.S. line of defense is expanding from “don’t give you the most advanced chip” to “neither can you afford cheap modeling capabilities”.This will directly impact the global AI ecosystem, as many developers have long relied on APIs, model output, and open research to iterate. If national security logic expanded unlimited, the former highly open software and research culture could gradually be camped off.

原始来源 · reuters.com路透社:美国指控中国AI企业工业化获取前沿模型能力reuters.com ↗

Chinese companies have a strong impetus to use the most advanced models in the U.S. to shorten their research and development cycles, but U.S. companies have also long benefited from academic papers, open source communities and global data. How to distinguish between normal imitation, legal evaporation, breach of service agreements and real business secret theft will become one of the most controversial legal boundaries for AI governance in the future.

Beijing’s advantage is precisely in “scale engineering capabilities”

The strengths of Chinese AI companies are not necessarily the first to propose original architecture, but to quickly engineer, reduce costs, and expand the scale of deployment.When an enterprise can mobilize a large number of accounts, computing, automation processes and engineers to continuously test American models and generate data, knowledge distillation can turn from laboratory technology to industrial processes.

数据中心服务器机房资料图|来源:Wikimedia Commons
数据中心服务器机房资料图|来源:Wikimedia Commons · 查看图片来源 ↗

This model has three strategic values:

Reduces tracking cycles: build high-quality training data quickly with the output of leading models; reduces test error costs: reduces the training resources needed to explore complexity from scratch; bypasses some hardware constraints: bridges some gaps with data and engineering optimization when computational power is insufficient.

That’s why U.S. security agencies are focusing on “industrialized scale” as a warning.It’s not about a graduate student doing experiments, it’s about Chinese companies taking the world’s strongest model as a sustainable data supply.

The controversy also exposes the contradictions of the U.S. AI business model.

The leading U.S. AI companies, on the one hand, want to open the model to global users to earn revenue through APIs, subscriptions and cloud services; on the other hand, they want to prevent potential competitors from using the same service to learn their capabilities.

If enterprises severely restrict access to Chinese developers, they will lose markets and may push China to accelerate the construction of a fully independent model ecosystem; if they continue to be open, they will have to accept the reality of capabilities being studied, mimicked and compressed. The stronger the model and the more users it has, the more likely it leaks out the capacity structure itself.

If Beijing had the world’s leading model in the future, would it allow unlimited access and distillation for U.S. companies?The answer is not necessarily more open than Washington, given China’s trend to strengthen control over data, algorithms and key technology exports in recent years.

Focus China believes that this argument suggests that AI competition is entering the phase of “technology sovereignty.” chips, data, model weights, API outputs, cloud services and talents could all be rolled back into the national security boundaries. The real future AI iron curtain is not necessarily a physical boundary, but a layer of account permissions, service terms, chip ban, data rules and model access restrictions.

The United States needs to come up with more specific technical and legal standards to explain what behavior constitutes irregular distortion, and not to attribute all Chinese model progress to “theft”; nor can Chinese enterprises emphasize technology autonomy, while viewing large-scale calls of overseas models as a shortcut without the need to explain the source.

When model output itself became a strategic asset, the Chinese-US competition has gone from “who can make better chips” into a new phase of “who can protect and replicate intelligence capabilities”.

MEMBER DISCUSSION

Article discussion

Verified members can discuss this report publicly and manage their own content.