← All posts / Policy

Six Chinese AI Firms Named and Shamed: Inside the NSA-CISA-FBI Advisory on Industrial-Scale Model Distillation

Joint advisory AA26-251A alleges DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens from Claude, GPT, Gemini and Grok since late 2024 — and recommends quietly serving degraded responses to suspected distillation traffic.

Six Chinese AI Firms Named and Shamed: Inside the NSA-CISA-FBI Advisory on Industrial-Scale Model Distillation

On September 8, 2026, three of the most powerful intelligence and security agencies in the United States — the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation — published a joint cybersecurity advisory that does something government documents rarely do: it names names. Advisory AA26-251A, “China-Based Artificial Intelligence Companies Conducting Malicious AI Model Distillation,” alleges that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have run “aggressive, malicious, and targeted” distillation campaigns against U.S. frontier models since at least late 2024, extracting billions of tokens across millions of exchanges — likely with the awareness of the Chinese government.

The document’s most striking phrase is its central claim: these campaigns “form the core — not merely a supplement” of the named companies’ AI development strategy. That is not the language of an incidental Terms-of-Service dispute. It is an assertion that a meaningful share of the Chinese AI ecosystem’s recent progress was not independently earned, but siphoned from American models through the front door of their own APIs.

What the advisory actually alleges

Knowledge distillation — training a smaller or cheaper model on the outputs of a larger, more capable one — is a legitimate and universally used machine learning technique. Every major American lab does it internally. What AA26-251A describes is different in kind: the industrial-scale, coordinated extraction of proprietary capabilities from competitors’ production models in violation of their terms of use, at a volume no legitimate research program would resemble.

The advisory walks through each company in detail. DeepSeek, it says, has conducted an organized campaign since at least late 2024 to generate synthetic training data for its models, including R1. Between late 2024 and mid-2025, the agencies allege DeepSeek distilled from Claude 3.7, Claude Sonnet 4, Claude Sonnet 4.5, Claude Opus 4.1, Gemini 2.5 Pro Preview, Gemini 2.5 Flash Preview, GPT-4, GPT-4o, GPT-4 Mini, GPT-4 Nano, GPT-5, and Grok 4 to train R1 and V3 — twelve distinct model versions queried to target reasoning capabilities, specialized optimizations, and domain-specific functions. The agencies also take direct aim at DeepSeek’s famous $5.6 million training-cost figure, calling it misleading because it excludes the cost of data acquired through distillation.

Moonshot AI is accused of running a widespread campaign since at least mid-2025, extracting significant Claude Fable 5 data to train Kimi-K3 and GPT-4o data to train Kimi-K2, with millions of exchanges targeting agentic reasoning, tool use, coding, data analysis, and computer-use agent development. Alibaba, per the advisory, distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 in late 2025 to improve software engineering, customer-service dialogue, and image and character creation in its Qwen family. MiniMax allegedly pulled chain-of-thought reasoning, reinforcement learning signals, and software-engineering capability from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro, and Gemini 3 Pro to build its M2 model — and, remarkably, used prompt injections to try to convince Claude Code it was a MiniMax product during internal development. StepFun distilled from a menu of Claude Opus 4.1 and 4.5, Sonnet 4.5, Haiku 4.5, and several GPT-5 variants for its Step 4 model. And by mid-2026, Z.AI had distilled billions of tokens of GPT-5.5 and Claude Opus 4.8 data to develop chain-of-thought reasoning.

The machinery of extraction

The tactical detail is what elevates this from diplomatic complaint to operational threat intelligence. The named firms routed requests through native APIs, remote cloud providers, and third-party aggregators that scrub user metadata; they leaned on a gray market of API proxies the advisory calls “transfer stations” to bypass geographic restrictions and undermine traceability; they bought premium subscriptions in bulk and shared them across developer teams. The agencies mapped the activity to the MITRE ATLAS framework across the full adversary lifecycle, from resource development through exfiltration.

The advisory also flags four techniques it describes as novel: regional-restriction evasion combined with subscription exploitation, centralized request-routing infrastructure, automated sanitization of request metadata, and systematic quota and cost optimization. Detection indicators include shared accounts used from many IP addresses, sustained round-the-clock usage without human variation, anomalous subscription-to-usage ratios, and new subscriptions immediately running at maximum volume. In one detail that reads like a spy novel, the advisory notes that MiniMax redirected its exchanges to a new Claude model within 24 hours of that model’s release.

The most controversial recommendation

Buried in the mitigations section is a recommendation that will be debated for years: the agencies advise AI companies to deploy “targeted response changes that subtly alter responses” to suspected malicious distillation attempts — serving downgraded models or adding differential-privacy noise — and to vary those changes across requests so attackers cannot easily evaluate response quality. More striking still: the advisory recommends against informing suspected distillation users when their responses have been altered, while saying legitimate safety researchers and third-party evaluators should be notified of model changes.

In other words, the U.S. government is officially blessing a practice where a model provider quietly serves poisoned or degraded outputs to traffic it suspects — a defensive mirror of the data-poisoning attacks the industry has warned about for years. CISA Acting Director Nick Andersen urged labs to “take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies.”

Context, pushback, and what it means

This advisory formalizes what the labs had been saying on their own. In February, OpenAI, Anthropic, and Google each published evidence of systematic extraction campaigns; OpenAI sent Washington an open letter describing “ongoing attempts by DeepSeek to distill frontier models of OpenAI and other US frontier labs, including through new, obfuscated methods.” What changed this week is that the accusation now carries the FBI’s signature rather than a startup’s blog post.

Not everyone accepts the framing. Microsoft CEO Satya Nadella has pointed out that the same labs banning distillation built their models on internet-scraped data largely without permission — a fair jab, though it doesn’t address the agencies’ actual claim, which is about contract violation at state-sanctioned scale. None of the six named companies has publicly responded.

The practical stakes reach well beyond geopolitics. If U.S. labs enforce their terms of service more aggressively, rate limits and licensing terms could tighten for everyone — including the American startups building on Claude, GPT, and Gemini APIs today. And for anyone who treated DeepSeek’s R1 as proof that a lean Chinese lab could match frontier capability on a shoestring budget, the government’s version of events offers an uncomfortable reframe: a chunk of that gap may have been closed simply by querying American models millions of times. For the open-weight Chinese models now flooding model hubs, provenance just became a first-class question.