This time, the speaker is not a member of Congress or a lawyer from an AI company.
It is Michael Kratsios. Trump's science advisor, director of the White House Office of Science and Technology Policy.
He said publicly on April 23:
"Systematically extracting and replicating the innovations of American industry — there is nothing innovative about that."
The target is clear — the U.S. government has officially documented that China is industrializing the copying of American AI.
How the copying works
This is not a vague claim of "data theft." Kratsios described a complete system:
Step one: Build a matrix of proxy accounts. Tens of thousands of proxy accounts, distributed IP addresses, querying OpenAI, Anthropic, and Google models at scale while bypassing access restrictions.
Step two: Model distillation. The responses obtained — including chain-of-thought reasoning and internal inference steps — are used to train smaller models.
The logic: you don't need to repeat a hundred years of experiments. Just ask for the answers from those who already did the experiments, then learn their approach. Training cost is a fraction of the original.
Step three: Break safety guardrails. In some scenarios, this involves cracking the original model's safety restrictions to extract information that would normally be inaccessible.
Kratsios's conclusion: these distilled models can approach the performance of top-tier American large models on certain benchmarks, while the training cost is just a fraction of the original.
Not the first time, but different this time
Anthropic, OpenAI, and Google have each previously reported similar attacks.
Last year, a widely circulated report alleged that DeepSeek, Kimi, and MiniMax had extracted 16 million conversations from Claude and ChatGPT for training. All three denied it.
That incident remained at the level of "corporate complaints against competitors."
This time is different: it is the President's science advisor speaking from the government's position. It means:
- This matter has entered formal intelligence assessment
- The U.S. government intends to treat it as a policy issue, not a private legal dispute
Kratsios added that the White House plans to strengthen intelligence sharing with tech companies and jointly design countermeasures.
A subtle point
Model distillation itself is a completely legal technique.
Using outputs from open-source models to train smaller models is standard practice in academia, and a large amount of open-source research has been done this way.
What Kratsios is accusing is a combination of three things: bypassing access restrictions + industrial scale + breaking safety guardrails.
Together, these three are not "technical learning" — they are organized intellectual property theft.
China has not directly responded. There will never be a "yes, we are copying" answer to such accusations, but subsequent policy and diplomatic reactions will indicate the stance.
Where the actual impact will go
In the short term, major AI model companies will likely tighten API access review — stricter identity verification, more complex anomaly traffic detection, and possible regional access restrictions.
Anthropic has already invested in Constitutional Classifiers, using AI to detect AI abuse. OpenAI and Microsoft signed a security cooperation agreement to share cybersecurity capabilities. These moves align with what Kratsios described as "intelligence sharing with industry."
But the more fundamental question is: if distillation technology itself can compress a model that cost tens of billions of dollars to train into a version replicable for a few million dollars, then the technical moat itself is fragile.
Guardrails, countermeasures, and intelligence sharing all have their uses, but the rules of this game have already changed.
"There is nothing innovative about that" — Kratsios's words sound more like the opening line of a long game, not the final chapter.
Source: CocoLoop, Trump science advisor says Chinese actors are copying American AI at massive scale (The Decoder)