Most AI systems aren't ready. Check yours in 15 min →
UA

US Agencies Accuse DeepSeek, Moonshot AI of Systematic IP Theft

AuthorAndrew
Published on:
Published in:AI

This is the part of the AI race nobody wants to talk about out loud: a lot of “innovation” is just copying with better lighting. And if the latest accusations are even half true, we’re not looking at a one-off bad actor. We’re looking at a strategy.

Based on public reporting, US security agencies are accusing major Chinese AI companies, including DeepSeek and Moonshot AI, of systematically extracting proprietary knowledge from American firms. The warnings aren’t subtle. Silicon Valley developers are being told to tighten protections around their work because the assumption now is: if it’s valuable, someone is trying to pull it out of your systems.

Here’s my take: this is both predictable and dangerous—and not only because “China vs US” makes people reach for slogans. It’s dangerous because it pushes the AI world toward a security mindset that will change how research gets done, who gets trusted, and what kind of products even get built.

Let’s be clear about what’s being claimed. Not “they learned from public papers” or “they hired smart people.” The accusation is about extracting proprietary knowledge—stuff that companies believe is theirs because it’s behind internal tools, private datasets, unreleased models, confidential code, or paid access. If that’s the behavior, it’s not a gray area. It’s theft. And I don’t think we should soften the word just because the topic is AI.

Now the uncomfortable part: the incentives basically invite this.

AI rewards speed. It rewards scale. And it rewards the ability to catch up fast. If you can shave months off by pulling someone else’s model behavior, training tricks, or data pipeline ideas, you do it—especially if you think your competitors are doing the same to you. That’s the logic that turns “a few incidents” into “systematic.”

And it’s not just foreign companies. If you’re an American startup watching this, you’re probably thinking, “So what am I supposed to do—hide everything?” That’s where the consequences start piling up.

Imagine you’re a small team building a niche model. You finally get something good. You put out an API so customers can try it. Then you notice weird patterns: users making endless queries, probing edge cases, trying to map what your model “knows” and how it behaves. Maybe it’s legit testing. Maybe it’s someone trying to reproduce your product without paying the cost you paid. Either way, you now have to treat curiosity like a threat.

Or imagine you’re an engineer at a big company. You used to share ideas freely across teams, post internal demos, write up notes. Now you’re told to lock it down. Fewer people get access. More approvals. More monitoring. It’s not just annoying. It changes the culture. It slows down honest work while the dishonest work keeps moving.

That’s why I don’t love the simple framing of “protect developers.” Yes, protections matter. But the price of “more protection” is often “less openness.” And openness has been a huge reason AI moved as fast as it did. If we clamp down too hard, we may end up with a world where only the biggest players can afford to build anything serious—because only they can run the security, legal, and compliance machine needed to operate.

So who wins?

Big firms with budgets win. Governments that prefer control win. The rest of us—the smaller labs, independent builders, researchers who rely on sharing—get squeezed.

There’s also a geopolitical trap here. These accusations land in an already tense US–China tech relationship. People will use this story to argue for harsher restrictions, fewer partnerships, and more walls. Some of that may be necessary. But walls also create their own incentives: they push talent and tools into separate ecosystems, and they make it easier for each side to tell itself a story where the other side is always the villain. That’s how you end up with a permanent cold war vibe in a field that’s shaping everything.

To be fair, there is a serious alternative view: this could be overstated, politicized, or based on partial evidence. Security agencies are not neutral narrators. They have agendas. And “IP theft” can be a messy label when companies already train on lots of public material, buy data from third parties, and learn from each other’s products in ways that are hard to separate from normal competition. The line between “learning” and “stealing” can be clear in principle and muddy in practice.

But even if the claims are only partly true, the reaction will still reshape behavior. Once fear enters the loop, it doesn’t need perfect proof to change the market. It just needs enough doubt that companies start acting like they’re under attack.

And I think that’s the real story: AI is moving from a bragging contest to a counterintelligence problem.

If you’re a builder, you’ll be forced to choose between growth and control. More access can mean more users—but also more exposure. If you’re a policymaker, you’ll be tempted to respond with broad rules that sound tough but punish the wrong people. If you’re a customer, you may get fewer choices, higher prices, and less transparency, all justified by “security.”

So where do we draw the line in a way that punishes real theft without turning AI into a locked-down club run by a handful of giants?

Frequently asked questions

What is AI agent governance?

AI agent governance is the set of policies, controls, and monitoring systems that ensure autonomous AI agents behave safely, comply with regulations, and remain auditable. It covers decision logging, policy enforcement, access controls, and incident response for AI systems that act on behalf of a business.

Does the EU AI Act apply to my company?

The EU AI Act applies to any organisation that develops, deploys, or uses AI systems in the EU, regardless of where the company is headquartered. High-risk AI systems face strict obligations starting 2 August 2026, including risk management, data governance, transparency, human oversight, and conformity assessments.

How do I test an AI agent for security vulnerabilities?

AI agent security testing evaluates agents for prompt injection, data exfiltration, policy bypass, jailbreaks, and compliance violations. Talan.tech's Talantir platform runs 500+ automated test scenarios across 11 categories and produces a certified security score with remediation guidance.

Where should I start with AI governance?

Start with a free AI Readiness Assessment to benchmark your current maturity across 10 dimensions (strategy, data, security, compliance, operations, and more). The assessment takes about 15 minutes and produces a prioritised roadmap you can act on immediately.

Ready to secure and govern your AI agents?

Start with a free AI Readiness Assessment to benchmark your maturity across 10 dimensions, or dive into the product that solves your specific problem.