Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
China Invokes Counter-Espionage Law Against US Firms After CIA Names Chinese AI and Chip Companies as Spy Targets

Since CIA Deputy Director Michael Ellis told the Billington Cybersecurity Summit in Washington on Tuesday, September 8, that Chinese AI, semiconductor and biotech companies are now "legitimate targets" for CIA espionage, Beijing has escalated its response twice in three days, culminating in a formal threat to invoke its Counter-Espionage Law against American firms.
China's Ministry of Commerce issued its first rebuke on Thursday, September 10, then followed with a sharper statement Friday, September 11, accusing Washington of "gangster logic" and "bandit logic of hegemony," according to both the South China Morning Post and Agence France-Presse, as carried by Daily Sabah. The ministry said the US had "torn away the fig leaf" hiding intelligence agencies' "covert theft" and vowed to "firmly take necessary measures" under Chinese law to protect its companies, per AFP's reporting.
The exchange occurs twelve days before President Donald Trump and Chinese President Xi Jinping are scheduled to meet at the White House on September 24, with AI and trade expected high on the agenda, according to Daily Sabah and the South China Morning Post.
What Ellis Actually Said
Ellis's remarks, delivered at a named industry conference rather than through an anonymous leak, were unusual for a serving intelligence official, according to Federal News Network's coverage of the speech. His argument was structural: because China lacks a genuinely independent private sector, and the Communist Party can direct or absorb any Chinese company, commercial firms in AI, chips and biotech function as extensions of state power for intelligence purposes.
"Our economy is intertwined with theirs," Ellis said, according to Daily Sabah's citation of the remarks, framing that interdependence as a vulnerability rather than a stabilizing tie. He said the CIA needs "a different kind of workforce" and different collection expertise for economic-security intelligence than it has traditionally used for political and military targets.
CIA officials have discussed economic intelligence priorities since former CIA Director Robert Gates raised the issue in 1991, and former Director James Woolsey pursued similar goals in 1993. What changed on September 8 was that Ellis named the sectors and defended the targeting publicly rather than through diplomatic ambiguity.
China's Legal Threat
China's Commerce Ministry response invoked the country's 2023 revised Counter-Espionage Law, which covers the removal or unauthorized transfer of documents, data and materials related to national security, according to a Korean-language report from mk.co.kr citing the ministry's statement. The ministry said it would "strictly punish illegal and criminal acts" to protect Chinese companies' rights, and accused the US of applying a double standard, pointing to a 2014 Obama-administration guideline that restricted foreign collection of US commercial trade secrets, per the same report.
No specific American company has been named as a target of a Chinese espionage investigation. The threat, as reported, is a general legal warning tied to Ellis's remarks, not an announced case, charge, or named defendant.
A Separate Fight Over Stolen AI Models
Running alongside the spying dispute, the FBI, NSA and Cybersecurity and Infrastructure Security Agency issued a joint advisory around the same week accusing six China-based AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, of running "industrial-scale" campaigns to extract proprietary capabilities from US models including Claude, GPT, Gemini and Grok since at least late 2024, according to the Epoch Times.
Acting CISA Director Nick Andersen said the agency was urging AI companies to "safeguard their platforms against knowledge distillation campaigns," per the Epoch Times report. The advisory disputed DeepSeek's widely cited $5.6 million training cost figure for its R1 model, calling it misleading because it excludes the value of distilled data.
This builds on a security report Anthropic published in February, which accused DeepSeek, Moonshot and MiniMax of generating over 16 million exchanges through roughly 24,000 fraudulent accounts to extract Claude's capabilities, according to Breitbart's account of the Anthropic report. China's Commerce Ministry dismissed the broader distillation accusations as "groundless" and accused Washington of large-scale cyber theft of its own, Breitbart reported.
A reasonable defender of Beijing's position would note that knowledge distillation, training a smaller model on a larger one's outputs, is a legitimate and widely used AI research technique, not inherently theft, and that competitive advantage built on "technology, talent and innovation," as China's Commerce Ministry put it, is normal commercial activity rather than a national security threat. Whether the specific volume and method described in the US advisory, 24,000 fraudulent accounts and violations of terms of service, crosses from legitimate research into theft is a claim made by Anthropic and the US government that Beijing disputes and that no court or independent arbiter has adjudicated.
No criminal charges have been filed against any of the six named Chinese firms in either the US or China. The question is whether either government's legal threats, Beijing's Counter-Espionage Law warning or the US advisory's naming of specific companies, produce actual enforcement action before Trump and Xi sit down on September 24, or whether both remain rhetorical positioning ahead of the summit.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.