On September 8 the NSA, the FBI and CISA published a joint cybersecurity advisory, AA26-251A, naming six China-based AI companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. According to the agencies, those firms extracted “billions of tokens across millions of exchanges/requests” from US frontier models, including versions of Claude, GPT, Gemini and Grok, since at least late 2024. The document is a warning addressed to US companies, and none of the agency pages announces charges, sanctions or trade measures.
Distillation is not the accusation
Distillation, training a model on the outputs of another, is a common technique, and the agencies say so themselves. What they call malicious is the combination around it: the scale, the deceptive routes to access and the breach of US companies’ terms of use. The pages read describe the conduct as “malicious knowledge distillation” and systematic extraction; the word “theft” comes from headlines and from what US officials threatened earlier, not from the advisory’s own text.
What the advisory describes
The access ran through official APIs, cloud providers and third-party aggregators, and through a gray market of proxies that resell frontier-model access to get around geographic restrictions, which the advisory calls “transfer stations.” Among the tactics it lists are jailbreak prompts used to extract hidden chain-of-thought reasoning, automatic switching between access routes when one is blocked, and employee-run account pools with daily budgets per agent, which it attributes to StepFun. It says MiniMax retargeted a new Claude model within 24 hours of its release, that DeepSeek’s campaigns fed R1 and V3, and that Alibaba used distillation to improve its Qwen models.
Two of its judgements are assessments rather than evidence the document makes public: that the campaigns happened “likely with Chinese government awareness,” and that they form the core of the firms’ AI development strategy. The agencies publish no method for their token counts.
What US companies are asked to do
The advisory asks AI providers to detect anomalous usage, such as new accounts that go straight to maximum use, to quietly degrade or alter responses to suspected distillation requests without telling the suspected party, and to correlate activity across providers, clouds and aggregators. “We strongly urge AI companies to take immediate steps to safeguard their platforms,” said Nick Andersen, CISA’s acting director.
Beijing’s answer
China’s Foreign Ministry rejected the accusations on September 9. Its spokesperson, Mao Ning, said China’s AI development comes from its own scientific strength and asked the United States to “stop leveling false allegations to smear China.” Six weeks earlier, on July 27, China’s Ministry of Commerce had already answered US threats to investigate and sanction Chinese AI companies over distillation, calling the claims baseless and “a typical form of AI hegemonism,” and asserting that US companies have also distilled Chinese models, a claim for which no US source was found.
What remains open
The public record does not yet show which terms of use were breached in each case, how the token counts were measured, or whether any legal step will follow. The advisory describes in detail how access to frontier models moves across borders, and for now its evidence is the agencies’ own description.
Related reading
- Cybersecurity Advisory AA26-251A — CISA, NSA and FBI
- Foreign Ministry press conference, September 9 — Ministry of Foreign Affairs of China
- US Closes Chip Export Loophole to China — IA al Día