The White House has said it will step up coordination with US AI firms in response to what it describes as “industrial-scale campaigns” by foreign actors seeking to extract and replicate advances in the technology.
As first reported by the BBC, in an internal memo, Michael Kratsios, director of Science and Technology Policy, wrote that the US government had obtained new information indicating that “foreign entities, principally based in China” were exploiting American companies.
He said these efforts rely on a process known as “distilling”, in which firms effectively copy AI systems developed by US organisations.
According to the memo, the aim is to “systematically undermine American research and development and access proprietary information”. Distillation campaigns are described as involving thousands of individual accounts interacting with AI chatbots or tools in ways that appear routine. These accounts then attempt to “jailbreak” systems or expose information not intended for public release, which is saved and used to train competing models.
To counter what it termed “malicious exploitation,” the White House outlined a series of measures, including sharing more intelligence with AI companies about “tactics employed and actors involved”, working to “better coordinate” responses, developing “best practices to identify, mitigate, and remediate” such activity, and exploring ways to hold foreign actors accountable.
The memo did not provide details of specific enforcement actions.
Kratsios also warned of the risks associated with such practices saying that “as methods to detect and mitigate industrial-scale distillation grow more sophisticated, foreign entities who build their AI capabilities on such fragile foundations should have little confidence in the integrity and reliability of the models they produce.”
While the memo did not name specific organisations, companies including OpenAI and Anthropic have said they are dealing with similar distillation activity. Earlier this year, Anthropic described distillation “attacks” by three AI laboratories – DeepSeek, Moonshot, and MiniMax – stating it had found them to be attempting to copy its models through such campaigns. OpenAI has also accused DeepSeek of copying its technology.
DeepSeek advances highlight intensifying AI competition
The developments come as Chinese AI firms continue to make rapid progress. DeepSeek has unveiled preview versions of its latest chatbot models, DeepSeek-V4-Pro and DeepSeek-V4-Flash, positioning them as competitive with leading US systems.
The Hangzhou-based startup said DeepSeek-V4-Pro “beats all rival open models for maths and coding,” and trails only Google’s Gemini 3.1-Pro, a closed model, for world knowledge. It added that the model’s performance falls only “marginally short” of OpenAI’s GPT-5.4 and Gemini 3.1-Pro, “suggesting a developmental trajectory that trails state-of-the-art frontier models by approximately 3 to 6 months.”
Recommended reading
- Cybersecurity in 2024 | The High Cost of Innovation
- CISOs Seeing More Impact from AI Cyber Threats
- AI in Cybersecurity | Navigating the Promises and Risks
The “flash” version offers similar reasoning capabilities while delivering faster response times and “highly cost-effective” usage pricing, according to the firm. Like previous releases, both models follow an open-source approach, allowing developers to use and modify the source code.
The launch follows the release of DeepSeek-R1 last year, which drew significant attention for offering capabilities broadly comparable with systems such as ChatGPT and Gemini. Its developers claimed it was built with less than $6m in computing costs, a fraction of the multibillion-dollar investments typical of Silicon Valley firms, though many questioned whether the startup had access to greater resources than disclosed.
DeepSeek’s emergence has also prompted scrutiny from regulators. Multiple US states, along with Australia, Taiwan, South Korea, Denmark and Italy, introduced bans or restrictions on DeepSeek-R1 shortly after its release, citing concerns over data protection and national security.





