Credit: DailyNewsBay via Shutterstock.com China’s foreign ministry has rejected the joint US intelligence advisory accusing Chinese developers of extracting capabilities from American frontier models at industrial scale, calling on Washington to stop making unfounded accusations and smears. Mao Ning, a ministry spokesperson, said China’s AI development is the result of high-level technological self-reliance and strength, according to accounts of her remarks. The response was reported on Wednesday, a day after the advisory was published. We reported the advisory when it appeared.
The NSA, FBI, and CISA named six Chinese companies, listed which American model each was said to have targeted, and described distillation as the core of how those companies build rather than a supplement to it. The document also disputed the training cost figure that made DeepSeek famous. Note what the rejection does not do. It does not address any of the per-company allegations, does not dispute the technical account of how requests were routed, and does not respond to the claim about bulk-purchased premium subscriptions shared across teams.
It asserts self-reliance as a matter of national principle, the same framing Beijing used when the accusation was first made by the White House earlier this year. That is a diplomatic answer to a technical document, which is the normal shape of these exchanges and is also why they never resolve anything. The advisory was unusually specific for a public intelligence product, which is what makes the mismatch conspicuous. Naming six firms and attributing particular models to each invites a rebuttal on those particulars.
None has been offered by the ministry or, as far as is publicly known, by the companies. Timing explains some of the register. Trump and Xi are expected to discuss AI governance later this month, and neither side benefits from a detailed argument about who trained on whose outputs in the days before. Treasury secretary Scott Bessent, who has previously threatened sanctions on Chinese AI, has said China can never get ahead of the United States, which is the sort of remark that guarantees a foreign ministry response regardless of the underlying facts.
The awkwardness for Washington is that distillation is not obviously illegal, and the industry it is defending has its own history with other people’s data. US labs face a growing stack of litigation over training material they did not license. The advisory’s answer is that this is different because it involves circumventing access controls rather than scraping the open web, which is a real distinction. It is also a narrower one than the framing suggests.
There is also a commercial subtext neither government mentions. Chinese open-weight models have been undercutting American ones on price for two years, and European buyers have noticed. Our reporting on the competitiveness argument in Brussels keeps running into the same fact: the cheapest capable models are frequently not American. An advisory that reframes that price advantage as the proceeds of theft is doing work in a market, whatever else it is doing in intelligence.
For Europe the practical question is neither country’s. Both DeepSeek and the American models named in the advisory are in use in European companies and public bodies. If the US position is that a set of Chinese models were built on capabilities taken without authorisation, that is a procurement question for anyone running them, and no European regulator has said anything about it. The AI Office has enforcement powers and a very small team.
Nothing in the exchange changes what either side does next. The advisory was an attribution exercise, not an enforcement action, and the rejection was a statement, not a defence. What both do is set the terms for the meeting later this month, where the disagreement will be about export controls and market access rather than about training data.















Leave a Reply