
Trump Rejects U.S.-China AI Integration as Beijing’s Model Distillation Campaigns Intensify Technology Rivalry
President Donald Trump has publicly rejected the idea of integrating American and Chinese artificial-intelligence development, drawing a line between limited risk-management talks with Beijing and deeper technological cooperation between the world’s two largest AI powers. Speaking after Chinese President Xi Jinping’s Washington visit, Trump said the United States should avoid opening its technological lead to China, arguing that a country ahead in the race has little reason to merge its development path with a strategic competitor. The statement came only days after a summit that produced no broad AI agreement, although the White House separately confirmed that Washington and Beijing will maintain a communication channel for serious AI-related incidents.
The distinction is important for Americans. The United States and China are simultaneously competitors in advanced AI and governments with an interest in preventing dangerous technological incidents from escalating. A communications mechanism does not require the United States to share frontier models, proprietary training methods, advanced chips or sensitive research. According to the White House, the two governments established a U.S.-China “Super Intelligence” Dialogue to exchange views on risks and benefits, with another exchange expected by November 2026, along with a bilateral channel for AI incidents.
That limited channel exists against a much more adversarial technological backdrop. On September 8, the National Security Agency, FBI and Cybersecurity and Infrastructure Security Agency jointly warned that China-based AI companies were conducting what they called aggressive, industrial-scale distillation campaigns against American frontier AI companies. U.S. agencies said the activity was designed to systematically extract restricted proprietary capabilities from leading American models and use those outputs to train Chinese systems. NSA
Anthropic’s own September threat-intelligence report provides a concrete example of why American policymakers are treating AI competition with China as a national-security issue rather than an ordinary commercial rivalry. Anthropic said it identified unauthorized distillation campaigns attributed with high confidence to seven China-based AI laboratories. The company said Alibaba-linked operators conducted the largest such campaign it had measured, using thousands of fraudulent accounts and millions of exchanges per day to extract reasoning capabilities from Claude models for use in training Qwen systems.
According to Anthropic, the Alibaba-linked campaign targeted agentic tasks, software engineering, kernel development and other long-horizon reasoning capabilities. The company said operators attempted to force Claude to reveal detailed reasoning traces and then convert those outputs into supervised fine-tuning data for Qwen models. At peak scale, Anthropic said the operation generated nearly three million exchanges per day through more than 3,500 fraudulent accounts.
That scale explains why U.S.-China AI integration raises questions far beyond ordinary research collaboration. Frontier models require billions of dollars in chips, electricity, engineering labor, data-center infrastructure and research investment. If another company can systematically use those models as teachers, it may reproduce some capabilities at a fraction of the original development cost. The resulting problem for American firms is both economic and strategic: proprietary capability developed in the United States can become an input into competing Chinese models.
Anthropic also reported another concern with direct implications for American users. It said some China-based labs fed conversations originating from their own users into Claude during distillation campaigns, and that some of those exchanges included names, email addresses, company information and other sensitive material belonging to users in multiple countries, including people accessing services through third-party routing platforms in the United States and Europe.
The danger therefore extends beyond who produces the highest-scoring model. AI competition increasingly involves model weights, reasoning behavior, training data, user information, inference infrastructure, chips, cloud systems and the enormous data centers required to support them. A country can gain technological advantage by acquiring capability at any point in that stack.
Trump’s rejection of AI “integration” with China fits into that broader competitive environment. During the September summit, he said the two leaders had not spent extensive time discussing AI and later stated that he preferred to keep American and Chinese technological development separate because the United States was ahead. At the same time, Xi publicly emphasized the need for AI to remain under human control and called for further international discussion.
Those positions show that the AI relationship is unlikely to fit neatly into either full cooperation or complete technological separation. The two countries may maintain crisis communication while continuing to compete aggressively over chips, models, cloud infrastructure, data and technical talent. The White House’s new incident channel reflects the first objective; restrictions, cybersecurity defenses and model-protection measures reflect the second.
For the United States, that separation of functions matters. A hotline for dangerous AI incidents could be useful if an autonomous system, cyber event or unexpected model behavior creates risks with international consequences. Such a mechanism is conceptually similar to other communication channels between rival powers: it can reduce misunderstanding without requiring either side to surrender sensitive capabilities.
Technology sharing is a different question. The recent U.S. government advisory concerning Chinese model distillation demonstrates why American AI developers increasingly need technical safeguards around frontier systems. The NSA, FBI and CISA warning described Chinese companies as attempting to systematically extract proprietary capabilities, while Anthropic said it has strengthened identity verification, account restrictions and model protections in response.
For American AI companies, this means access control is becoming a strategic issue. Model providers need to identify unusually large request volumes, coordinated account creation, repeated attempts to elicit reasoning traces and traffic routed through intermediaries designed to conceal the true user. The security perimeter around a frontier model increasingly resembles the security perimeter around advanced semiconductor technology or sensitive software.
The economic stakes are equally large. American firms currently spend extraordinary amounts building frontier AI systems. If competitors can obtain portions of those capabilities through unauthorized model extraction, the return on American research investment is weakened while foreign competitors gain a shortcut. That creates pressure on U.S. companies to protect models without making them so inaccessible that legitimate developers and businesses cannot use them.
China’s own AI industry is advancing quickly enough that the competitive gap cannot be assumed to remain permanent. Chinese companies including Alibaba, DeepSeek, Moonshot and Zhipu have developed increasingly capable models while offering some systems at lower prices than leading American platforms. Recent reporting has highlighted growing concern in Washington that inexpensive Chinese models could challenge U.S. companies commercially even as American firms retain advantages at the frontier.
That commercial challenge is important because technological leadership is not determined only by who invents the strongest model first. Adoption matters. If Chinese models become cheaper, easier to deploy and deeply embedded in global software systems, Beijing’s AI ecosystem can gain influence even without surpassing every American frontier benchmark.
The United States therefore faces two separate strategic questions. The first is how to prevent Chinese firms from extracting restricted American capabilities or exploiting sensitive user information. The second is how to maintain enough communication with Beijing to manage AI incidents whose effects could cross borders.
The September summit produced a limited answer to the second question. The White House says the countries will establish regular dialogue and an incident communication mechanism. It did not announce joint model development, shared training infrastructure or broader technological integration. Trump’s subsequent remarks make clear that he views continued American technological separation from China as compatible with that narrow communication channel.
For American companies and national-security institutions, the immediate lesson is that AI competition with China is moving beyond abstract debates about which country is “winning.” The contest now involves the protection of model capabilities, user data, semiconductor access, infrastructure, research investment and the technical methods used to reproduce advanced systems.
The recent Chinese distillation campaigns described by U.S. agencies and Anthropic illustrate why that protection matters. If millions of automated interactions can be used to transfer valuable reasoning capabilities from an American model into a foreign competitor, traditional ideas about intellectual-property security are no longer enough. A frontier AI system can effectively become a continuously accessible source of training data unless providers can recognize and disrupt systematic extraction.
At the same time, communication between rival governments can serve a separate security purpose. Preventing unauthorized technology transfer and maintaining an emergency channel are not contradictory goals. One protects competitive capability; the other reduces the risk that an AI incident becomes an international crisis.
The central U.S.-China AI question after the September summit is therefore no longer whether the two countries will simply “cooperate” or “decouple.” The emerging structure is more complicated: limited dialogue on dangerous incidents alongside an increasingly intense technological contest over models, data, chips and infrastructure.
For Americans, that distinction is important. China’s AI industry has demonstrated both rapid technical progress and a willingness by some companies, according to U.S. agencies and Anthropic, to use large-scale distillation to acquire American model capabilities. The United States can maintain channels designed to prevent catastrophic misunderstandings while still treating frontier AI technology, proprietary reasoning capability and sensitive data as strategic assets requiring rigorous protection.