← All posts / Policy

Self-Reliance, Not Stolen Tokens: Beijing Formally Rejects the US Distillation Advisory

China's Foreign Ministry calls the NSA-CISA-FBI accusations 'false allegations' and hails its AI as homegrown, escalating a war of words days before Trump-Xi talks where AI governance tops the agenda.

Self-Reliance, Not Stolen Tokens: Beijing Formally Rejects the US Distillation Advisory

One day after the FBI, NSA, and CISA published a joint cybersecurity advisory accusing six Chinese AI companies of industrial-scale model distillation, Beijing has answered — and it did not mince words. At a regular press conference in the Chinese capital on September 9, 2026, Foreign Ministry spokesperson Mao Ning rejected the allegations outright, urging Washington to “stop leveling false allegations to smear China” and framing her country’s AI progress as the product of domestic ingenuity rather than appropriated American know-how.

The exchange marks the first formal government-to-government rebuttal of advisory AA26-251A, and it lands at a singularly awkward moment: President Donald Trump and Chinese leader Xi Jinping are expected to meet later this month, with AI governance widely reported to be near the top of the agenda.

What Beijing actually said

Mao Ning’s remarks, delivered at the ministry’s regular briefing, paired a flat denial with an olive branch. “The development of AI in China comes from greater self-reliance and strength in science and technology,” she said, “and is fueled by China’s vision of extensive consultation and joint contribution for shared benefit and commitment to open cooperation.”

She continued: “We believe all parties need to make sure AI development is open and inclusive and promotes the well-being of humanity as a force for good and for all. We hope the U.S. side will earnestly act on the important common understandings reached between the two presidents and stop leveling false allegations to smear China. As two major powers in AI, China and the U.S. should step up cooperation.”

The framing is deliberate on at least two axes. First, “self-reliance and strength in science and technology” is a established slogan of Chinese industrial policy — invoking it reframes the country’s model advances as the intended payoff of years of state investment in domestic compute and research. Second, the appeal to “common understandings reached between the two presidents” ties the rebuttal to the diplomatic track, implicitly scolding Washington for airing accusations ahead of a summit. The Associated Press, which first reported the comments, noted that the ministry characterized the U.S. claims as unfounded accusations and smears.

What the US advisory alleged

The Tuesday advisory — designated AA26-251A and published through the FBI, NSA, and CISA — accused China-based AI developers of extracting, or “distilling,” capabilities from U.S. frontier models including Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini, and xAI’s Grok “since at least late 2024.” It named DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI, and said the activities were conducted “likely with Chinese government awareness.”

The language was unusually pointed for a cybersecurity bulletin. “China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models,” the advisory stated. It described companies routing distillation requests “through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use,” and achieving cost savings “through bulk procurement of the U.S. AI companies’ premium subscriptions shared across teams of developers.”

The Associated Press observed that this week’s joint advisory contains more detail than earlier U.S. accusations — which include Anthropic’s June claim that Alibaba-linked operators ran nearly 25,000 fake accounts and more than 28.8 million exchanges against Claude, described by the company as the largest distillation campaign it had detected to date.

The subtext: a summit in the balance

The timing is the story. Trump and Xi are due to meet later this month — reporting consistently points to late September — and AI governance is expected to figure prominently, alongside trade and investment. Reuters reported in July that the two countries planned their first official AI talks in September, a follow-up to the May Trump-Xi summit. The distillation advisory dropping one to two weeks before those conversations reads less like coincidence than positioning: a public laying-down of the U.S. evidentiary case before negotiations begin.

Treasury Secretary Scott Bessent reinforced the message on Tuesday, telling an event at Southern Methodist University’s Cox School of Business in Dallas that China could “never get ahead” of the United States in AI. “The Chinese distill our models and they can never get ahead of us,” Bessent said — a striking claim in that it treats distillation simultaneously as pervasive and as self-limiting, implying that a copying strategy caps China at whatever the American frontier was yesterday.

Beijing’s rebuttal serves a parallel domestic and diplomatic function. Externally, it keeps the moral high ground narrative alive for Global South audiences, where Chinese open-weight models are increasingly the default affordable option. Domestically, the “self-reliance” framing supports the case that export controls have failed to contain Chinese AI — a message Beijing has every incentive to amplify.

The open question neither side answered

Notably absent from Wednesday’s briefing: a substantive rebuttal of the advisory’s specific technical claims. Mao Ning did not address the alleged transfer-station infrastructure, the bulk subscription purchases, or the per-company timelines laid out in AA26-251A. The named companies — DeepSeek, Alibaba, Moonshot AI, and Z.AI — did not immediately respond to requests for comment, according to the AP report. A categorical denial at the ministry level is a diplomatic response; it is not a technical one, and the gap between the two is where this dispute will actually be adjudicated.

There is also an uncomfortable wrinkle for the U.S. case: distillation outputs are, by construction, the models doing what they were built to do — generating text. The advisory’s argument rests on terms of use and scale, not on a conventional intrusion. Whether that framing can anchor enforcement — or whether it mainly serves as leverage ahead of the summit — is now the operative question.

What to watch

Three signals will indicate whether this exchange is theater or prelude. First, whether the September U.S.-China AI talks proceed on schedule despite the public rhetoric. Second, whether any of the six named companies issue individual technical responses — a coordinated silence would itself be informative. Third, whether U.S. frontier labs escalate enforcement, such as tightened subscription verification or rate-limit patterns aimed at distillation workloads, turning the advisory’s recommendations into de facto policy.

Neither capital has an interest in collapsing the diplomatic track over the accusations. But with both sides now on the record — one with a detailed technical indictment, the other with a categorical denial — the Trump-Xi meeting inherits a dispute that neither leader can quietly drop. The war of words over whose models trained whom has become part of the summit’s agenda whether the principals wanted it there or not.