Near FutureSeptember 11, 2026

The Next AI Export Control Is a Quietly Worse Answer

A US advisory naming six Chinese AI labs reportedly asks providers to degrade suspect accounts instead of banning them. If you use a US model from Asia, you may never be told. Here is how you would notice.

By Race to AGI· AI-assisted analysis, grounded in Race to AGI data and reviewed before publishing

On September 8 the NSA, CISA and FBI published a joint advisory, AA26-251A, accusing six China-based AI firms, DeepSeek, Moonshot AI and Alibaba among them, of running industrial-scale distillation campaigns against US frontier models. Follow-up coverage says the firms allegedly pulled billions of tokens out of Claude, GPT, Gemini and Grok.

The accusation is old. The remedy is new.

According to that follow-up coverage, the agencies are urging US providers to quietly downgrade suspected accounts rather than ban them. Chinese-language analysis of the same advisory read it as a push to silently route Chinese users to weaker models. If that is how it gets applied, the next AI control arrives as a slightly worse answer, with no error message attached.

The logic is easy to follow. A ban is visible: the banned party opens a new account through a new entity and the provider learns nothing. A downgrade is invisible. The suspected distiller keeps paying, keeps querying, and trains on outputs that are quietly worse than the real thing. As counter-intelligence, that is clever.

As product policy, it is new territory. It makes model quality something a provider can adjust per account, for reasons it does not have to disclose.

There is also a problem with the target. Distillation matters most when the model you want to copy is locked away, and the labs named here are increasingly the ones publishing. Moonshot released open weights for its 2.8 trillion parameter Kimi K3 in July. DeepSeek put out MIT-licensed weights for a 305B multimodal model on August 31. Z.ai's open GLM-5.2 was reported in August to be within a few months of OpenAI and Anthropic on cyber and bio benchmarks.

Beijing's line, from the July round of this same dispute, is that distillation runs both ways and that some US companies distill from Chinese open models. We cannot verify either side's claim. What is on the record is price: in July, Fortune reported some Chinese frontier-level models priced under 2 percent of Anthropic's Fable per token, and gaining traction with US developers.

So who actually gets downgraded? Detection is statistical. Providers will flag accounts by traffic pattern: volume, prompt diversity, where requests come from. Distillers are the intended catch. The false positives will be heavy, legitimate users who look similar in the logs, such as eval teams, data-labelling shops and batch pipelines. If the screening leans on geography, users in China and nearby markets carry that risk first.

Access already runs through side doors, which is part of why a quiet dial is attractive. In July, OpenAI and Google confirmed selling frontier AI through Singapore units to subsidiaries of Alibaba, Baidu and Tencent. A per-account quality setting closes doors like that without announcing it.

A hedge is due. This is one advisory and a few days of coverage. In our news records, no provider has confirmed it is degrading anyone. Bloomberg also reported this week that China remains willing to hold AI talks with the US despite the row. This could still de-escalate.

What to do with this:

If you build on a US frontier API from Asia, or you run high-volume batch workloads anywhere, pin a small fixed eval set now and run it weekly from each region you serve. A silent downgrade produces no error. It shows up only as drift against a baseline, and you only have a baseline if you recorded one before.

Then ask your provider one question in writing: can my account be routed to a different model or configuration without notice, and would you tell me if it were? The answer tells you whether the model you pay for is a product or a policy lever.

Referenced in this analysis

#china#distillation#export-controls#open-weights#asia-ai