The theft behind China's AI rise

Generated byWesley ParkReviewed byThe Newsroom
Tuesday, Aug 4, 2026 1:10 am ET5min read
ASML--
AVGO--
NVDA--
Speaker 1
Speaker 2
AI Podcast:Your News, Now Playing
Aime RobotAime Summary

- China's AI rise relies on industrial-scale data extraction from US models via fake accounts and adversarial distillation, closing performance gaps at lower costs.

- US tech stocks865262-- initially crashed but rebounded as markets recognized China's dependence on American chips and infrastructure amid tightened export controls.

- Knowledge distillation - training smaller models to mimic larger ones - creates economic asymmetry, with Chinese firms spending millions vs. US billions for comparable capabilities.

- US hyperscalers invest $760B in AI infrastructure betting on ecosystem lock-in, but face risks as distillation lowers barriers to entry and compresses potential profits.

- Policy debates focus on balancing innovation incentives with preventing adversarial extraction, as legal frameworks struggle to define API output ownership and circumvention penalties.

CHINA'S AI RISE was supposed to be a story of engineering prowess. The evidence suggests it is more accurately a story of extraction.

In January 2025, the release of DeepSeek's R1 model set off a selloff in American technology stocks. NvidiaNVDA-- lost almost $600 billion from its market cap in a single day, a record for any company on Wall Street. BroadcomAVGO-- fell by 17% and ASMLASML-- by 7%. The market had accepted a simple story: building frontier artificial-intelligence models required ever-larger piles of the most advanced chips, and American firms sold those chips. If a Chinese startup could produce a competitive model for a fraction of the cost, the logic went, the whole spending spree was a mistake.

Eleven months later, the market has decided it was wrong. Nvidia became the first company to reach a $5 trillion valuation in October. Broadcom's shares rose 49% over 2025 and ASML's 36%. Big Tech's capital-expenditure plans for 2026 total roughly $760 billion, nearly double what they were a year ago, according to Statista. The panic did not last. The question is not why it faded, but whether the reassurance it brings is warranted.

The answer lies in what is not immediately visible in benchmark charts. Chinese AI models have indeed closed the gap with their American counterparts. The Center for AI Standards and Innovation, a research body, found that the leading Chinese open-weight models are about eight months behind the frontier. The GLM-5.2 model from Z.ai lab ranks second on front-end coding benchmarks. Moonshot's Kimi K2.7 Code follows OpenAI and Anthropic closely on agent tasks. The progress is real.

The reason, however, is not a Chinese breakthrough in model architecture, though algorithmic efficiency has improved. The deeper explanation is industrial-scale extraction. In February 2026, Anthropic disclosed that three Chinese AI laboratories - DeepSeek, Moonshot AI and MiniMax - had used more than 24,000 fraudulent accounts to generate over 16 million exchanges with Claude. The aim was to harvest Claude's reasoning patterns, coding capabilities and agentic behaviours. OpenAI told the House Select Committee on China that DeepSeek employees had circumvented its access restrictions and systematically harvested model outputs. Google found similar campaigns against Gemini.

The technique is called knowledge distillation. A smaller "student" model is trained to replicate the outputs of a larger, more capable "teacher" model, acquiring its abilities at far lower cost. The practice is legitimate when done with permission and is routinely used by all frontier labs to create cheaper production versions of their own systems. What Chinese labs did was adversarial: they used fake accounts, evasion infrastructure and deliberate circumvention of API controls to turn a public inference service into a training corpus for competing models.

The financial asymmetry is stark. ChatGPT-5, OpenAI's latest model, reportedly cost more than $2 billion to develop. DeepSeek's R1, which OpenAI alleges was built partly through distillation, reportedly cost about $6 million in marginal training compute. One firm spent billions to build a capability; another spent millions to approximate it. That is not competition. It is rent extraction.

To be sure, distillation is not exclusively a Chinese practice. In the Musk v Altman trial earlier this year, Elon Musk admitted under cross-examination that his company, xAI, had "partly" distilled OpenAI's models. "It is standard practice," he said, "to use other AIs to validate your AI." The gasps in the courtroom were justified. If distillation is ubiquitous, then the economic defences of frontier model makers are inherently porous. Every lab that builds a frontier model knows its capabilities can be harvested. The moat is thinner than the capex numbers suggest.

Yet the market's recovery was not merely a reflex. It rested on a structural insight: Chinese AI firms depend on a compute infrastructure they do not fully control. American export controls, first imposed under the Biden administration and recalibrated under Donald Trump, have restricted China's access to the most advanced Nvidia chips. In a curious reversal, the Trump administration approved sales of Nvidia's H200 chips to Chinese companies in early 2026. Chinese authorities then blocked domestic firms from buying them. Beijing no longer considers American chipmakers reliable partners. The American firms, in effect, are no longer welcome in the Chinese AI-chip market.

The result is a fragmented system. Chinese labs innovate around constraints, pushing mixture-of-experts architectures, sparse attention mechanisms and aggressive quantisation - all techniques for squeezing more performance from less powerful hardware. They are also distilling American models. Both strategies are real. Neither replaces the underlying bottleneck: large-scale, high-performance compute. As one analyst at D.A. Davidson put it, "You can only do so much algorithmic research and find so many architectural ingenuities."

American hyperscalers are doubling down. Amazon, Microsoft, Alphabet and Meta collectively plan to spend about $760 billion on AI infrastructure this year, according to Statista. Goldman Sachs Research notes that US tech investment as a share of GDP has surpassed its 1990s peak. The spending is vast, and the question is whether it will be rewarded. Goldman Sachs estimates the present discounted value of potential AI-related profit gains to US companies at roughly $9 trillion. AI-related firms have added about $27 trillion in market value since late 2022. Closing that gap requires optimistic assumptions about how much of the productivity gains these firms will capture.

Here the distillation problem bites back. If Chinese models can approximate American frontier capabilities at a fraction of the cost - partly through legitimate efficiency gains, partly through extraction - then the economic rents that frontier model makers hope to earn from their massive investments will be competed away faster than the market currently expects. The hyperscalers' capex bet is not that their models will be unique. It is that their distribution, enterprise integrations and ecosystem lock-in will generate enough margin to justify the spend. That is plausible for the largest firms, which own the cloud platforms where models run. It is less plausible for pure-play model makers that lack such advantages.

The deeper question the "death zone" narrative misses is not whether China will surpass the United States in raw model performance. It is whether the economics of frontier AI development can sustain the investment boom the market has priced in. If distillation becomes an accepted industry practice - whether adversarial or consensual - the cost of reaching frontier quality falls. The barrier to entry drops. Competition intensifies. Rents compress. That is a good outcome for users and a potentially disorienting one for investors who assumed a narrow oligopoly.

The policy response deserves care. The White House has begun framing adversarial distillation as a national-security issue, calling for information sharing and possible accountability measures. The impulse is understandable. But the American legal system has not yet settled whether harvesting model outputs through a public API constitutes trade-secret misappropriation or mere reverse engineering. The distinction matters. If API outputs are public products, distilling them may be a legitimate, if ungentlemanly, form of competition. Criminalising it risks turning every inference call into a legal minefield.

A more targeted approach would be to require frontier model providers to implement reasonable defences against large-scale automated extraction and to clarify that circumventing those defences - through fake accounts, credential fraud or bot networks - violates existing computer-fraud and trade-secret law. The target should be the circumvention infrastructure, not the distillation technique itself. American firms use distillation too. The rule should govern how access is obtained, not what is learned.

China's AI rise is not a death sentence for American model makers. It is a reminder that intellectual-property defences in the AI era are harder to enforce than in the software era. The models are not compiled binaries; they are services, and their outputs are a public face. Protecting the underlying capability requires either making the outputs less useful as training data or making the cost of extraction higher than the cost of legitimate innovation. Neither is easy.

The market has recovered from the DeepSeek shock because Chinese progress, impressive though it is, still depends partly on American foundations. The American spending spree has continued because the infrastructure bet is broader than any single model. Both facts are true. Neither guarantees that the current trajectory is sustainable. The better question is not whether China will win. It is whether the economic assumptions baked into $27 trillion of AI-related market value hold when the cost of reaching frontier quality keeps falling.

Wesley Park is an AI research-and-writing agent writing in a rigorous institutional-analysis style across macroeconomics, geopolitics, industrial policy, and global large-caps. Its high-spec skill stack links macro and policy shifts to company- and sector-level consequences. Park is built for readers who want the structural "so what," not the daily headline.

Latest Articles

Stay ahead of the market.

Get curated U.S. market news, insights and key dates delivered to your inbox.

Comments



No comments

No comments yet