Skip to main content
  • Home
  • Policy
  • Chip Controls Slowed China's AI but Distillation Never Needed Chips

Chip Controls Slowed China's AI but Distillation Never Needed Chips

Picture

Member for

1 year 3 months
Real name
The Economy Editorial Board
Bio
The Economy Editorial Board oversees the analytical direction, research standards, and thematic focus of The Economy. The Board is responsible for maintaining methodological rigor, editorial independence, and clarity in the publication’s coverage of global economic, financial, and technological developments.

Working across research, policy, and data-driven analysis, the Editorial Board ensures that published pieces reflect a consistent institutional perspective grounded in quantitative reasoning and long-term structural assessment.

Modified

Chip controls slowed China's AI but did not stop it
Distillation, not raw compute, drives China's competitive AI models
Terminology drift and one factual verb need correcting before publication

In July 2026, researchers from the US Center for Artificial Intelligence Standards and Innovation and its British counterpart tested the Chinese Kimi K3 model in a 32-step cyberattack test. The model reached an average of step 17. The leading American models reached step 28.5. The difference shows something that public benchmarks often hide: the apparent convergence between Chinese and American AI systems does not mean real equivalence in difficult and prolonged tasks. The emergence of models such as the Kimi K3, DeepSeek V4 Pro and GLM 5.3 has led many commentators to conclude that American chip controls have failed. The picture is more complex. Chip controls appear to have delayed China's access to computing power. Still, they are not the only obstacle in Beijing's path to cutting-edge artificial intelligence, nor the only tool at Washington's disposal.

Benchmark Gains Do Not Prove Chip Controls Have Failed

According to the Epoch Capabilities Index, a composite scale based on curated benchmarks, Kimi K3 was at 158 points in September 2026, Anthropic's Claude Fable 5 at 163 and OpenAI's GPT 6 Astra at 169. The distance corresponds to about four to ten months of progress based on the recent historical rate of evolution, which is a real capability that should not be underestimated. Researcher Erich Grunewald of the Institute for AI Policy and Strategy in Washington notes that benchmarks do not fully capture performance on difficult and open problems during prolonged work, which explains why the cyberattack test showed a larger gap than standard benchmarks.

Figure 1: On a 32-step simulated attack, Kimi K3 completed barely six of every ten steps the leading US models did.

Moonshot AI itself, the creator of the Kimi K3, admits that the overall performance of the model remains behind the best systems. There is also a difference between building an impressive model and serving hundreds of millions of users on a regular basis. Moonshot AI suspended new subscriptions to the Kimi K3 shortly after its launch, when demand exceeded its available computing capacity. The choice of several Chinese companies to publish their model weights openly, rather than making them available exclusively through their own services, is likely linked to the lack of computing power for large-scale development and not just a strategic open-source choice.

The argument that performance proves a failure of the tests misses the right comparison. The question is not how Chinese models compare to American models today but what Chinese models would look like without any restrictions on access to chips. This scenario cannot be directly observed but there are theoretical and empirical reasons to believe that China would have stronger models and greater capacity to serve users without these restrictions. Executives of Chinese AI companies have repeatedly publicly stated that American chip bans are significantly delaying them.

Smuggling and Rentals Have Not Closed the Computing Gap

At the end of 2025, Chinese companies held about 5 percent of the world's computing power for artificial intelligence through official channels, according to an estimate by the organization Epoch AI. This figure is smaller than that of any single American cloud computing superprovider. Even taking into account chips entering the country through smuggling or renting remote access from providers in Malaysia and elsewhere, the gap remains significant. It limits the number and scale of experiments that Chinese AI companies can conduct and reduces the scale at which they can develop and perform their models economically.

Chip checks are not perfect. In March 2026, US prosecutors charged a co-founder of US server maker Super Micro with conspiring to divert up to $2.5 billion worth of Nvidia equipment to China through a virtual company in Southeast Asia. According to an estimate by Epoch AI, up to a third of total Chinese computing power by 2025 may have been smuggled into the country, which equates to about 3 percent of the world's AI computing power, although the actual figure may vary significantly. Cloud-leased computing power still adds at least 3 percent of access, a source that is difficult to measure and often legitimate as long as the chip owners are not based in China.

Token Data Reveals China's Thin Domestic Compute Base

The picture becomes more complicated when one examines how the actual use of artificial intelligence is measured, i.e., through tokens, the basic unit of data that language models process. According to a study of 100 trillion tokens by the OpenRouter platform in collaboration with investment fund Andreessen Horowitz, open-source Chinese models started at a share of 1.2 percent at the end of 2024 and reached almost 30 percent of global usage in a few months, with an average weekly share of about 13 percent in 2026, marginally below the 13.7 percent recorded by the rest of the world outside the United States. These numbers seem at first glance to confirm the narrative of Chinese dominance in artificial intelligence.

The reality is more mixed. Researcher Wang Peng from the Beijing Academy of Social Sciences observed that Chinese developers account for just over 6 percent of OpenRouter users, indicating that most of the use of Chinese models comes from users outside China. Chinese models dominate global usage rankings because they are cheap and open, not because China itself consumes huge volumes of tokens for its in-house AI development. The country exports access to cheap computing power through software, but this does not mean that it has a correspondingly huge amount of its own hardware to train cutting-edge models from scratch.

Distillation Is the Real Workaround for Chip Controls

If Chinese companies don't need to consume a huge amount of computing power to produce competing models, distillation is largely the point: a technique in which a smaller model is trained on the responses of a larger and more expensive system. In April 2026, Michael Kratsios, director of the White House Office of Science and Technology, wrote in an official note that entities based primarily in China are running deliberate, industrial-scale distillation campaigns of cutting-edge American AI systems, using tens of thousands of fake accounts and restriction-circumvention techniques to extract proprietary information. Anthropic had already accused DeepSeek, Moonshot AI and MiniMax in February 2026 for over 16 million exchanges through around 24,000 fraudulent accounts, of which 3.4 million were linked exclusively to Moonshot AI.

Figure 2: MiniMax accounted for nearly four-fifths of the exchanges Anthropic attributes to distillation, dwarfing Moonshot's and DeepSeek's shares.

In July 2026, Kratsios specifically accused Moonshot AI, claiming that the company distilled Anthropic's advanced Claude Fable 5 model to develop its own Kimi K3, while also acquiring servers with Nvidia GB300 processors via Thailand, bypassing export restrictions. Kimi K3 costs around $3 per million incoming tokens, versus $10 for Fable 5, while it scored higher in the Frontend Code Arena rankings. Moonshot AI denied the allegations, arguing that its development is based on its own innovations, but Treasury Secretary Scott Bessent warned that covert, industrial-scale distillation attacks that go beyond intellectual property theft could lead to sanctions and inclusion in restricted entity lists.

The scale of the phenomenon was confirmed in September 2026, when the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation issued a joint warning about aggressive, malicious and targeted distillation tactics by Chinese companies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, which allegedly raised billions of tokens from conversations with cutting-edge American models as of 2024, likely with the knowledge of the Chinese government. The campaigns targeted variants of Anthropic's Claude, OpenAI's ChatGPT, Google's Gemini and SpaceX's Grok, through multiple access paths that included direct programmatic environments, remote cloud providers and intermediate aggregators that obfuscate user metadata.

Washington Needs More Than Chip Controls

Distillation is not limited to commercial applications. A Reuters review of over 80 Chinese academic papers and patents, with research by the Washington-based Jamestown Foundation, showed that researchers affiliated with the Chinese People's Liberation Army widely use the technique for military purposes. A paper by Unit 96941, a military information and cyber warfare unit in Beijing, described the use of OpenAI's GPT-3.5 to process sensitive military source code, which was then used to train a domestic model that operates exclusively within Chinese military networks. Researchers at the Academy of Military Sciences applied similar techniques for target reconnaissance models to simulated naval operations with drones, ships and underwater vehicles.

The conclusion is not that chip controls were useless, but that they address only one part of the problem. Even if China had full access to advanced American chips, its companies and research institutions would likely have continued to use distillation, as it is the cheapest and fastest avenue to acquire cutting-edge capabilities without the cost of training from scratch. Legislative initiatives such as the Remote Access Security Act, which has already been passed in the House of Representatives and is pending in the Senate, aim to expand controls beyond physical chips, including remote access to computing power. At the same time, talks between the US and China on artificial intelligence governance are scheduled for September, shortly before President Donald Trump meets with President Xi Jinping in Beijing.

Step 17 that the Kimi K3 reached in the cyberattack test does not prove that the chip tests failed, but neither does it prove that they are sufficient on their own. Limiting access to advanced chips has delayed the development of cutting-edge models in China and limited the scale at which the country can develop them commercially. At the same time, distillation has allowed companies such as Moonshot AI, DeepSeek and Alibaba to produce models that approach the top without needing a corresponding amount of computing power of their own, directly exploiting the work of American laboratories through billions of queries to publicly accessible models. The goal of chip tests cannot be to completely block Chinese artificial intelligence, but to slow it down. Without tools that also cover distillation, this achievement will remain unfinished.


This article reflects the analytical judgment of The Economy Editorial Board and does not constitute policy advice or the official position of any affiliated institution.


References

Baptista, E. (2026) 'Exclusive: Chinese military researchers tap US AI models to train defence systems', Reuters, 31 July.
Cheng, Y. (2026) 'Chinese AI models lead global token consumption', China Daily, 7 April.
Chow, V. (2026) 'Trump tech official accuses China's Moonshot AI of stealing from Anthropic', South China Morning Post, 23 July.
Grunewald, E. (2026) 'China's AI models aren't proof that US chip controls have failed', East Asia Forum, 10 September.
Kelley, A. (2026) 'China is trying to steal US AI models' secrets, intel agencies warn', Defense One, 8 September.
Lee, K. (2026) 'Open Weights, Extracted Capabilities: Reassessing the Distillation Economy and the Contest for American AI Leadership', The Economy Research (SIAI), 13 August.

Picture

Member for

1 year 3 months
Real name
The Economy Editorial Board
Bio
The Economy Editorial Board oversees the analytical direction, research standards, and thematic focus of The Economy. The Board is responsible for maintaining methodological rigor, editorial independence, and clarity in the publication’s coverage of global economic, financial, and technological developments.

Working across research, policy, and data-driven analysis, the Editorial Board ensures that published pieces reflect a consistent institutional perspective grounded in quantitative reasoning and long-term structural assessment.