Security1 distinct publisher3 min readPublished
A White House memo calls Chinese model distillation deliberate and industrial in scale, then answers it with information sharing, best practices and a demarche. The detection work stays with providers.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Divide Anthropic's February numbers and the detection problem takes on a size: 16 million exchanges spread over 24,000 fraudulent accounts works out at roughly 667 exchanges per account [2][16]. At that per-account volume, nothing in the logs screams extraction rig. It looks like a small team running evaluations against an API. The signal exists in the correlations between accounts, in payment instruments and prompt structure and timing, not inside any one of them. Google's disclosure describes a different profile again, a single campaign of 100,000 queries against Gemini [3].
That is the queue the memo's language actually describes. Tens of thousands of proxy accounts to evade detection, plus jailbreaking to pull out proprietary behaviour [4], is a description of work that belongs to trust and safety and account integrity, the same people already sorting card fraud from real signups. The four things the administration committed to are information sharing, private sector coordination, best practices for identifying and mitigating and remediating, and exploring measures to hold actors accountable [5]. None of those four ships a classifier or pays for the humans reviewing its output.
The asymmetry is that the accounts being hunted are also revenue, and a wrong call suspends a paying customer. Providers absorb that cost; the memo does not offer to. Tom Uren, writing at Seriously Risky Business, argues the promised actions are reasonable and will make some difference but will not stop the campaigns, and reads them as the same information-sharing posture applied to two decades of Chinese IP theft [15]. His sharper complaint is the omission: the memo says nothing about semiconductor export restrictions [8].
The evidence he cites for those controls biting is real and also messy. DeepSeek's V4 was significantly delayed after an unsuccessful attempt to train on Huawei's Ascend, and the company reverted to Nvidia silicon for training while using Huawei parts for inference [9][10]. A Chinese tech blogger attributed V4 being text-only to constraints on computing power and cash [12]. Bulk Ascend production has historically happened in Taiwan in breach of sanctions, and Chinese firms cannot match Nvidia's volume [14]. Both levers depend on enforcement; the difference is that one is enforced at fabs and customs, and the other at a login screen owned by a private company.
The number that sets the price on either is DeepSeek's own: V4 trails frontier models by about three to six months, per its technical report [13]. Closing that with compute costs billions. Closing it with 24,000 accounts costs the price of the API calls. Diplomacy, meanwhile, produced a cable to posts, a demarche to Beijing [6], and an embassy statement calling the accusations pure slander [7].
Ranked by verification strength, evidence, and original report placement.
The White House memo said foreign entities principally based in China are engaged in deliberate, industrial-scale campaigns to distill US frontier AI systems, leveraging tens of thousands of proxy accounts to evade detection and using jailbreaking techniques to expose proprietary information.
Distillation attacks, also known as model extraction attacks, upskill less capable models cheaply by training them on the outputs of more advanced models.
Anthropic said Chinese labs had collectively generated "16 million exchanges" with Claude across 24,000 fraudulent accounts.
Google cited a distillation attack that involved 100,000 queries to Gemini.
In February, OpenAI, Google and Anthropic each said they had been victims of distillation attacks.
Per the memo, the administration will share information about distillation attacks, enable private sector coordination against attacks, facilitate development of best practices to "identify, mitigate, and remediate" them, and "explore a range of measures" to hold actors accountable.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary documents quoted, but through one commentary source
The substantive claims trace to identifiable primary material - the White House memo (quoted directly), Reuters reporting on the State Department cable, on-record vendor disclosures, DeepSeek's V4 technical report and the Chinese embassy statement. That is well above rumour grade. But the cluster contains exactly one publisher, none of those primaries is in the source set for direct checking, and two load-bearing details (the failed Ascend training run, the compute-and-cash explanation for text-only V4) rest on an unnamed Chinese tech blogger and unattributed reporting.
Attack activity quantified; countermeasures still commitments
There is real, quantified activity on the attacker side - 16 million Claude exchanges across 24,000 accounts, 100,000 Gemini queries, three providers on record - and a shipped Chinese model whose hardware path is documented. On the response side, nothing is yet deployed: the memo promises information sharing, coordination, best-practice development and 'exploring' accountability, and diplomacy amounts to a cable and a demarche. No provider is reported to have adopted any government-supplied detection capability.
Threat framed as industrial-scale; response is coordination
Positive gap: the rhetoric outruns the mechanism. The memo escalates language to 'deliberate, industrial-scale campaigns' and the administration frames itself as countering theft of frontier capability, but the committed instruments are information sharing, best practices and a formal complaint to Beijing - and the memo omits the one lever the source considers effective. The cluster also never establishes that the disclosed exchange volumes actually transferred capability, so the causal core of the alarm is asserted rather than measured. Offsetting the gap somewhat, the chip evidence is concrete and the author openly discounts his own government's plan rather than amplifying it.
Multiple aligned interests behind every figure
Nearly every number in the story comes from a party with a stake in it. Frontier labs disclosing extraction volumes benefit from stronger protection, enforcement attention and export controls, and the source notes leading AI firms have argued for tighter controls. The administration gains from naming a foreign culprit while a Trump-Xi meeting approaches, which the author explicitly offers as a reason export controls went unmentioned. Beijing's denial is equally interested. The newsletter itself is a sponsored publication (this edition sponsored by runZero) with a declared pro-export-control position. Disclosure is reasonably transparent throughout, which keeps this below the top band.
Documented events, one lens, unproven causal core
High confidence that the memo, cable, demarche, vendor disclosures and DeepSeek V4 release happened roughly as described - these are quoted or attributed to named primaries. Lower confidence in the interpretive layer: whether distillation is meaningfully closing the capability gap, whether the memo's measures will fail, and whether compute constraints alone explain V4's scope. Single-publisher coverage with declared positions caps this in the middle band.
product
A school agenda shipped with "Vitoiis" and a planet named Marc, and no one read it first1 distinct publisher
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
invest
Scalable Capital puts ChatGPT, Claude and Grok inside the European order ticket2 distinct publishers
security
The nationalization argument is really a vendor-continuity memo1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026