FMF Intelligence Share: U.S. Labs Coordinate Against Adversarial Distillation
Bloomberg: OpenAI, Anthropic, and Google share threat intel via the Frontier Model Forum to detect Chinese-lab adversarial distillation — high-volume ToS-violating extraction to train copycats. OpenAI cites DeepSeek; Anthropic names DeepSeek, Moonshot, MiniMax; FMF brief Feb 23. Rare operational coop — allegations, not adjudicated IP verdicts.

U.S. frontier rivals usually compete on benches. Distillation flips the game: shared adversary detection through the nonprofit they co-founded — because free-riding on frontier outputs is cheaper than matching training spend.
Bloomberg (April 6) reported OpenAI, Anthropic, and Google coordinating via the Frontier Model Forum (FMF; co-founded with Microsoft in 2023) to detect and counter adversarial distillation by Chinese competitors — automated querying to harvest outputs/reasoning for cheaper copycat models, framed as ToS violations. OpenAI has accused DeepSeek; Anthropic identified DeepSeek, Moonshot AI, and MiniMax, with analyses citing on the order of millions of suspicious exchanges (one figure in coverage: ~16 million). FMF issued an adversarial-distillation issue brief (February 23, 2026). OpenAI confirmed participation and prior Congress warnings on Chinese extraction.
Mechanism (as reported)
- High-volume targeted queries → harvest traces/outputs → train smaller/competing models.
- Industry response mirrors cyber info-sharing: detect, block, brief peers via FMF.
- Motive: cost/safety moat erosion + IP/national-security framing from U.S. labs.
Chinese labs’ strong results relative to claimed resources fueled scrutiny — lab allegation / press synthesis, not a court finding.
Claims vs checks
Collaboration existence is Bloomberg primary (The Decoder, Tech in Asia, et al. confirming). Named actors and exchange counts come from lab statements and analyses cited in reporting. Distillation as the causal explanation for any specific model’s strength remains contested without public forensic dumps.
Limits
- Private intel-sharing — outsiders see claims, not packets.
- ToS enforcement ≠ proof of state-directed theft.
- False positives can block legitimate research traffic.
Sources
- Bloomberg: “OpenAI, Anthropic, Google Unite to Combat Model Copying in China” (April 6, 2026).
- FMF issue brief: Adversarial Distillation (February 23, 2026).
- OpenAI congressional memo references; The Decoder / Tech in Asia confirming named labs.