"AI Makes It to the Summit Table" Intensifying U.S.-China AI Supremacy Battle Poised for Head-On Clash Over 'Unauthorized Distillation vs. Semiconductor Export Controls'
Authored On
Modified
U.S.-China technology rivalry continues as AI emerges as a core summit agenda item China protests semiconductor export controls; U.S. denounces unauthorized technology appropriation Little prospect of progress on core issues, leaving clearer competitive rules as a realistic compromise

Artificial intelligence (AI) has rapidly emerged as a central agenda item for the U.S.-China summit in Washington. China is demanding that the United States ease its export controls on advanced AI semiconductors and subject U.S. AI companies to equivalent safety and audit standards, while Washington is maintaining a hard-line stance over issues including unauthorized distillation by Chinese companies. Experts say the summit is highly unlikely to ease the two countries’ struggle for technological supremacy itself, with any agreement more likely to be limited to establishing the “rules” governing their competition.
AI Emerges as a Major U.S.-China Flashpoint
According to a Nikkei Asia report on September 7, local time, U.S. President Donald Trump and Chinese President Xi Jinping are scheduled to hold a summit at the White House on September 24, with AI set to feature prominently on the agenda. China is first expected to call for a reassessment of Washington’s export controls on advanced AI semiconductors. The United States began imposing sweeping restrictions on China’s access to advanced AI semiconductor supply chains in October 2022 and subsequently tightened the rules repeatedly from 2023 through 2025, expanding their scope to cover indirect exports, high-bandwidth memory (HBM), and advanced semiconductor manufacturing equipment.
China is also demanding prior scrutiny of U.S. AI companies. Yuyuan Tantian, a policy-oriented social media account affiliated with Chinese state broadcaster CCTV, argued on August 30 that “before the United States begins ‘substantive’ AI discussions with China, it must demonstrate that U.S. AI companies are subject to the same safety regulations, disclosure requirements, and audit standards.” The account also accused Anthropic’s Claude of engaging in improper practices, including conducting covert monitoring beyond the boundaries of user data and transmitting website domain information without authorization. In July, the Chinese government likewise warned that Anthropic’s AI coding tool Claude Code contained monitoring capabilities that could transmit sensitive information to remote servers without user consent, potentially creating a serious security backdoor risk.
U.S. Angered by Unauthorized Distillation
The U.S. administration is also expected to counter China’s demands by maintaining its hard-line posture. AI itself has become a central battleground as the two countries’ struggle for technological supremacy intensifies by the day. In an interview with U.S. political news outlet Punchbowl News on August 7, Trump said, “I don’t want to see China take over cryptocurrency,” adding, “I don’t want China to win on AI either.” He stressed that “the winner of the AI race takes everything,” describing AI as a technology with far greater ramifications than the internet revolution, and said he would “also discuss AI issues with President Xi when he visits the United States next month.”
Washington is also likely to raise its objections to the Chinese AI industry’s distillation strategies. In a statement issued in April, White House Office of Science and Technology Policy (OSTP) Director Michael Kratsios criticized the Chinese AI industry, saying, “Systematically extracting and copying the innovations of American industry is not innovation.” U.S. officials allege that Chinese actors have deployed tens of thousands of proxy accounts and jailbreaking techniques to extract critical information from proprietary U.S. AI models, effectively appropriating American research at negligible cost through distillation. Kratsios said such replication “deliberately strips security protocols from the resulting models and even disables the mechanisms designed to preserve the models’ neutrality and pursuit of truth.” He added, “We cannot tolerate activities intended to systematically undermine U.S. research and development and steal proprietary information,” warning that Washington was considering a range of measures to hold those responsible accountable.
Mounting Evidence of 'Technology Theft'
U.S. Treasury Secretary Scott Bessent also said in a July interview with Fox Business that the government was “investigating whether open-source AI models developed by Chinese companies stole the intellectual property of U.S. competitors.” In a social media post that same month, Bessent stressed, “We support open-source AI and the innovation it enables,” but added that “open source is not an unrestricted hunting ground for American intellectual property.” He warned, “If Chinese companies conduct covert, large-scale distillation attacks amounting to intellectual property infringement, the United States will consider sanctions and export-control designations.” He continued, “The technical term in AI is distillation, but we will call it ‘theft,’ and we will not tolerate companies developing products on the back of stolen intellectual property.”
The U.S. government’s sensitivity to Chinese companies’ distillation strategies reflects the repeated emergence of evidence supporting such allegations. In separate security threat reports published in February, OpenAI, Anthropic, and Google said they had detected indications that Chinese AI companies—including DeepSeek, Moonshot AI, and MiniMax—had effectively appropriated their AI research through large-scale distillation and model extraction. In July, Anthropic also submitted a formal complaint to the U.S. Senate and the Department of Defense alleging that an AI research laboratory affiliated with China’s Alibaba had launched a large-scale, unauthorized knowledge-distillation attack targeting Claude, Anthropic’s latest AI model. Alibaba allegedly used approximately 25,000 fraudulent accounts and automated macro programs, or botnets, to conduct 28.8 million exchanges with Claude in just 44 days, thereby stealing the model’s entire data lineage. Moonshot AI, DeepSeek, and MiniMax were also reported to have used approximately 24,000 fraudulent accounts to conduct more than 16 million question-and-answer exchanges with Claude. Their collection efforts focused on information related to advanced capabilities such as agentic reasoning, coding, tool use, and computer control.
Table 1. Evidence Cited by the United States of Chinese AI Technology Theft
| Entity | Allegations Raised by the United States |
|---|---|
| Alibaba | Unauthorized collection of data related to Anthropic Claude’s advanced capabilities through large numbers of fraudulent accounts and automated programs |
| Moonshot AI | Participation in large-scale model extraction and unauthorized distillation of Anthropic models during the development of Kimi K3 |
| DeepSeek | Large-scale distillation and model extraction targeting U.S. AI models |
| MiniMax | Collection of advanced-capability data from U.S. AI models through repeated queries using fraudulent accounts |
| China-Linked Hacking Groups | Expansion of cyberattack targets to include U.S. technology companies’ AI models, training data, and infrastructure |
Continued Attacks Aimed at Narrowing the Technology Gap
The United States claims that Moonshot AI’s recently released high-performance AI model, Kimi K3, was also developed through unauthorized distillation. In a July social media post, Kratsios said, “We have obtained information that Moonshot AI distilled Anthropic’s Fable to develop its K3 model,” adding, “They developed a sophisticated internal platform capable of conducting large-scale distillation against American models and rapidly switched among multiple approaches to evade detection.” He continued, “Legitimate AI distillation aimed at creating smaller and more efficient models plays an important role in an open innovation ecosystem,” but stressed that “covert, large-scale industrial distillation designed to steal proprietary American technology and undermine the U.S. research base is unacceptable.”
More recently, concerns have expanded beyond simple distillation to include cyberattacks originating from China. Matt Pearl, director of the Strategic Technologies Program at the U.S. think tank Center for Strategic and International Studies (CSIS), said, “As the AI competition intensifies, China is targeting the technology sector with increasing focus,” adding that “rather than concentrating on specific trade secrets such as hardware designs, hackers have broadened their interests to every area that could help narrow the AI gap with the United States.” In June, major U.S. cybersecurity company CrowdStrike reported that “during the 12 months from April last year through the end of March this year, Chinese groups were responsible for more than half of all state-sponsored hacking attacks targeting technology companies, particularly corporate AI assets.”
The Costs of Excessive Restrictions on Access
As the divide between the two countries deepens, experts increasingly believe that the upcoming summit will do little to alter the broader trajectory of the U.S.-China contest for AI supremacy. Both countries define AI not simply as an advanced industry but as a strategic technology that will determine their economic and military competitiveness. Limited discussions concerning AI safety standards took place during the May summit between Trump and Xi, but the meeting produced little progress on core issues such as advanced semiconductor export controls and cyber competition. CSIS subsequently assessed that most of the central issues in the technology rivalry—including AI, cybersecurity, and export controls—remained unresolved.
Some observers expect any U.S.-China compromise to remain within the realistic bounds of clarifying the “rules” of competition. One possible approach would be for the United States to establish separately defined, permissible channels of access, including the legitimate commercial use of application programming interfaces (APIs), the use of publicly available models, and joint safety research. A market participant said, “Stringent controls may delay China’s acquisition of advanced U.S. computing resources and technologies, but they also encourage Chinese companies to build their own semiconductor and AI ecosystems and seek alternative routes.” The person added, “If the two countries agree to preserve limited channels for lawful model use and safety research, they may not end their contest for supremacy, but they could curb at least some of the ‘appropriation’ carried out under the guise of technological competition.”