# FMF Intelligence Share: U.S. Labs Coordinate Against Adversarial Distillation

Times of AI Desk · 2026-04-06 · Policy

[https://timesof.ai/2026/04/openai-anthropic-google-frontier-model-forum-china-distillation](https://timesof.ai/2026/04/openai-anthropic-google-frontier-model-forum-china-distillation)

> Bloomberg: OpenAI, Anthropic, and Google share threat intel via the Frontier Model Forum to detect Chinese-lab adversarial distillation — high-volume ToS-violating extraction to train copycats. OpenAI cites DeepSeek; Anthropic names DeepSeek, Moonshot, MiniMax; FMF brief Feb 23. Rare operational coop — allegations, not adjudicated IP verdicts.

U.S. frontier rivals usually compete on benches. Distillation flips the game: **shared adversary detection** through the nonprofit they co-founded — because free-riding on frontier outputs is cheaper than matching training spend.

**Bloomberg** (April 6) reported **OpenAI**, **Anthropic**, and **Google** coordinating via the **Frontier Model Forum** (FMF; co-founded with Microsoft in 2023) to detect and counter **adversarial distillation** by Chinese competitors — automated querying to harvest outputs/reasoning for cheaper copycat models, framed as ToS violations. OpenAI has accused **DeepSeek**; Anthropic identified **DeepSeek**, **Moonshot AI**, and **MiniMax**, with analyses citing on the order of **millions** of suspicious exchanges (one figure in coverage: ~16 million). FMF issued an adversarial-distillation issue brief (**February 23, 2026**). OpenAI confirmed participation and prior Congress warnings on Chinese extraction.

## Mechanism (as reported)

- High-volume targeted queries → harvest traces/outputs → train smaller/competing models.
- Industry response mirrors cyber info-sharing: detect, block, brief peers via FMF.
- Motive: cost/safety moat erosion + IP/national-security framing from U.S. labs.

Chinese labs’ strong results relative to claimed resources fueled scrutiny — **lab allegation / press synthesis**, not a court finding.

## Claims vs checks

Collaboration existence is **Bloomberg primary** (The Decoder, Tech in Asia, et al. confirming). Named actors and exchange counts come from **lab statements and analyses cited in reporting**. Distillation as the causal explanation for any specific model’s strength remains **contested** without public forensic dumps.

## Limits

- Private intel-sharing — outsiders see claims, not packets.
- ToS enforcement ≠ proof of state-directed theft.
- False positives can block legitimate research traffic.

## Sources

- [Bloomberg: “OpenAI, Anthropic, Google Unite to Combat Model Copying in China”](https://www.bloomberg.com/news/articles/2026-04-06/openai-anthropic-google-unite-to-combat-model-copying-in-china) (April 6, 2026).
- [FMF issue brief: Adversarial Distillation](https://www.frontiermodelforum.org/issue-briefs/issue-brief-adversarial-distillation) (February 23, 2026).
- OpenAI congressional memo references; The Decoder / Tech in Asia confirming named labs.
