The National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI jointly accused six China-based AI companies of conducting industrial-scale distillation campaigns against United States frontier models, in an advisory published Tuesday. The agencies say DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens across millions of exchanges and requests from US frontier AI models — including variants of Claude, GPT, Gemini and Grok — since at least late 2024, an activity the advisory says likely occurred with Chinese government awareness.
The advisory, designated AA26-251A, is careful to note that distillation is a legitimate and widely used technique in AI research, in which a smaller model is trained to reproduce the outputs of a larger one. What the three agencies describe is different in kind: aggressive, malicious and targeted distillation conducted at industrial scale, forming what the document calls the core — not merely a supplement — of the targeted companies' AI development strategy. For the latest AI policy news, follow AI Buzz Wire's continuing coverage of the Washington regulatory agenda. latest AI policy news
Who Is Named, and What They Allegedly Took
The advisory attributes specific campaigns to specific companies. DeepSeek is said to have run organized distillation campaigns since at least 2024 targeting reasoning capabilities, specialized optimizations and domain-specific functions that were used to train its R1 and V3 models. Alibaba is accused of leveraging industrial-scale distillation to improve its Qwen family of models, which has become one of the most downloaded open-weight model families in the world.
Moonshot AI, MiniMax, StepFun and Z.AI are likewise accused of engaging in malicious knowledge distillation of US models, though the advisory publishes fewer company-specific details for the four. All six firms have built models that now compete directly with American frontier systems on benchmarks and price.
How the Campaigns Allegedly Worked
According to the document, the companies routed distillation requests through multiple pathways to gain unauthorized access while violating US companies' terms of use. These included the models' native application programming interfaces, remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection.
The agencies also describe a gray market of proxies known as "transfer stations" used to bypass US providers' geographic restrictions, breach terms of service, evade safeguards and undermine traceability. To keep costs down during campaigns of this scale, the advisory says the companies engaged in bulk procurement of premium subscriptions that were then shared across teams of developers.
More advanced tactics included chain-of-thought reasoning extraction, automated failover between access pathways during blocking attempts, and sophisticated quality evaluation frameworks designed to detect when a provider had deployed defensive countermeasures. The payoff, the agencies write, is that companies conducting industrial-scale distillation see significantly shorter AI development timelines and reduced financial expenditure when training a frontier model.
Three Recommendations for US AI Companies
The advisory closes with three immediate actions for American AI providers. First, implement comprehensive detection and mitigation: monitor anomalous and malicious prompts, accounts, networks and behaviors, and watch subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.
Second, deploy targeted response changes. The agencies recommend subtly altering responses served to suspected malicious distillation attempts in order to attenuate the payoffs of the campaigns — a form of countermeasure that degrades the value of stolen outputs without alerting the distiller.
Third, establish cross-organization intelligence sharing to correlate activity across model providers, cloud platforms and API aggregators, so that campaigns deliberately distributed across multiple providers to avoid single-point detection can be recognized as a single operation.
A New Phase in the US-China AI Dispute
The publication arrives amid a broader escalation in Washington's rhetoric about Chinese AI development. Reuters reported that the United States has accused Chinese AI firms of malicious copying of American AI technology, and the advisory was covered Tuesday by CyberScoop, Nextgov and other outlets that follow the intelligence community. The document frames the stakes in explicitly strategic terms, describing the activity as systematic extraction of proprietary functionalities and capabilities that threatens US technological leadership.
For the six named companies, the advisory raises the reputational and commercial cost of serving Western customers. Alibaba and DeepSeek in particular have cultivated developer ecosystems outside China, and both have appeared in enterprise procurement conversations that would now carry an additional compliance question. None of the six companies is subject to the advisory's recommendations directly — the document addresses US AI companies — but its effect is to formalize what American labs have privately claimed for two years: that their models have been systematically copied at scale.
The advisory also lands in the middle of an unresolved debate inside the AI industry about where legitimate learning ends and theft begins. Distillation from open-weight models, published research and public outputs is standard practice; the advisory's authors draw the line at extraction of restricted proprietary functionality through deception, evasion of access controls and violation of terms of use. How that line is enforced — through technical countermeasures, contract law or export policy — is now the question the industry and its regulators will have to answer.
Stay Ahead of AI
Follow the latest AI developments and breaking artificial intelligence news as the policy battle over model security intensifies.
Read more AI news →