The NSA, FBI, and CISA Say Six Chinese AI Companies Don’t Just Copy American Models. Copying Is the Strategy.
On September 8, 2026, the National Security Agency, the FBI, and the Cybersecurity and Infrastructure Security Agency jointly accused six China-based AI developers — DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI — of running industrial-scale campaigns since late 2024 to extract the capabilities of Claude, ChatGPT, Gemini, and Grok through a technique called distillation.
The joint advisory doesn’t describe a side hustle. It says the practice “forms the core — not merely a supplement” of Chinese AI development strategy. Treasury Secretary Scott Bessent has already floated sanctions and Entity List designations against firms whose distillation “crosses the line into IP theft.”
- 6 companiesnamed in the Sept. 8 advisoryDeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI accused of industrial-scale distillation against US models since late 2024 — CISA Advisory AA26-251A
- 28.8 millionClaude exchanges, 25,000 fake accountswhat Anthropic told the Senate Banking Committee an Alibaba-linked operation ran through Claude over 44 days in spring 2026 — Anthropic letter, via CNBC
- $5.6 millionDeepSeek's advertised R1 training costthe figure the advisory says is misleading because it excludes the cost of data acquired through distillation — CISA advisory, via TheNextWeb
Distillation is not, on its own, exotic or illegal. It is a standard machine-learning technique: a smaller “student” model learns to mimic a larger “teacher” model by training on the teacher’s outputs, producing a cheaper, faster model that approximates the original’s abilities. What the joint advisory describes is not that technique in the abstract — it is the specific, evasive machinery Chinese firms allegedly built around it. The advisory says Chinese AI companies route requests through a gray market of API proxies it calls “transfer stations” designed to bypass geographic restrictions and undermine traceability, layer on automated metadata sanitization that strips organizational identifiers at the infrastructure level, and bulk-buy premium subscriptions shared across developer teams using accounts with obfuscated origins.
“China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core — not merely a supplement — of their AI development strategy,” the advisory states. CISA Acting Director Nick Andersen put it more bluntly: “We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns.” The agencies recommend U.S. labs monitor subscription-to-usage ratios and immediate maximum usage from new accounts, quietly degrade responses to high-confidence distillation attempts without alerting the requester, and share intelligence on distillation campaigns across companies.
The advisory lays out a company-by-company target list. DeepSeek allegedly pulled reasoning, agentic, and specialized capabilities from multiple GPT, Claude, Gemini, and Grok versions since late 2024 to train its R1 and V3 models — and the agencies say DeepSeek’s widely cited $5.6 million training-cost figure, the number that convinced markets a frontier-class model could be built for the price of a London townhouse, is misleading because it omits the cost of the distilled data itself. Moonshot AI drew on Claude and GPT since mid-2025 to sharpen its Kimi models’ software-engineering and reasoning skills. Alibaba used Claude and GPT-5 output to improve its Qwen family. MiniMax targeted Claude Code’s chain-of-thought and reinforcement-learning data through attempted prompt-injection attacks. StepFun went after reasoning and coding capabilities across several models. And Z.AI, the advisory says, had extracted billions of tokens from GPT-5.5 and Claude Opus 4.8 by mid-2026 to build chain-of-thought reasoning into its own systems.
This is a really massive unauthorized distillation campaign. For comparison, reported from Anthropic: DeepSeek: 150,000 exchanges. Moonshot: 3.4 million. MiniMax: 13 million. Alibaba: 28.8 million.
The September advisory is the fourth escalation in a seven-month arc, not a first strike. Anthropic disclosed the first cluster of distillation attempts in February 2026 — DeepSeek, Moonshot AI, and MiniMax, combined, at roughly 24,000 fraudulent accounts and more than 16 million exchanges. The White House followed on April 23 with National Science and Technology Memorandum 4, in which OSTP Director Michael Kratsios wrote that “large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable” and accused foreign entities “principally based in China” of using “tens of thousands of proxy accounts” and jailbreaking techniques.
Then came Alibaba, specifically. On June 10, Anthropic sent Senate Banking Committee leaders Tim Scott and Elizabeth Warren a letter accusing Alibaba-linked operators of the largest known distillation attack to date — a campaign it called “brazen” and “illicit,” run through roughly 25,000 fraudulent accounts across 44 days. September’s joint advisory folds that Alibaba-specific finding into a six-company federal warning — the shift from one company’s letter to Congress to three agencies’ joint name-and-shame.
Congress moved on the gap between “named” and “punished” before the advisory even shipped. The Deterring American AI Model Theft Act of 2026 (H.R. 8283), introduced in April and advanced by the House Foreign Affairs Committee, would require the State Department to identify foreign entities extracting American closed-source model capabilities, publish a public “AI Model Extraction Attackers List,” and make anyone on it eligible for Commerce Department Entity List designation and blocking sanctions. Select Committee on the CCP Chairman John Moolenaar, a cosponsor, said the bill “complements the work my colleagues and I are doing in Congress to stop China’s AI theft and protect national security,” adding that “to keep our advantage over our adversary, I will continue working to pass legislation that modernizes our export controls.”
We support open-source AI and the innovation it unlocks. But open source is not open season on American IP. When PRC firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.
Every major AI lab distills its own models, and rivals training on public outputs are not automatically doing anything unlawful. What the advisory and Anthropic’s letters describe as the violation isn’t the technique — it’s the alleged terms-of-service evasion: proxy “transfer stations,” fabricated accounts, and stripped metadata built specifically to avoid detection. That distinction is what H.R. 8283 and the Entity List threat are actually aimed at.
China’s Ministry of Foreign Affairs rejected the advisory the same week it was published. Spokesperson Mao Ning said China’s AI development “is the result of high-level technological self-reliance and strength” and urged Washington to “refrain from making unfounded accusations or smears.” A Chinese embassy spokesperson, Liu Chang, called the advisory “a deliberate attack on China’s development and progress in the AI industry.” None of the six named companies had issued a public response as of publication.
The timing is not incidental. President Trump and President Xi Jinping are scheduled to meet on September 24, and AI governance is expected on the agenda. A federal advisory naming six of China’s highest-profile AI developers — published sixteen days before that meeting — hands American negotiators a specific, public grievance to raise, and hands Beijing a specific, public grievance to reject before the two leaders sit down.
The government’s framing is not universally shared inside the industry it’s meant to protect. OpenAI CEO Sam Altman, asked about distillation risk in a July 2026 interview, was unbothered: “I would rather people not distill from us, for sure. But this is not in my top ten list of worries.” Tesla and xAI’s Elon Musk went further, turning the accusation back on Anthropic itself — a pointed jab at Anthropic’s own $1.5 billion settlement over how it acquired training-book data.
“Anthropic is guilty of stealing training data at massive scale and has had to pay multi-billion dollar settlements for their theft.”
Elon Musk · February 23, 2026, on X
The dispute over how alarmed to be hasn’t slowed the underlying market. CNBC reported in September that Claude API keys, obtained through exactly the kind of fraudulent-account campaigns the advisory describes, are now resold on gray-market forums at 70–90% below retail price — evidence, security researchers say, that the extraction pipeline the government is warning about has already spawned its own secondary economy, independent of whether Washington and Beijing ever agree on what to call it.
At our April 16 hearing, 'China's Campaign to Steal America's AI Edge,' one thing was clear: the CCP is racing for AI dominance and stealing American AI models and IP to get ahead. Chairman Rep. Moolenaar highlighted how Chinese firms combine legal purchases with theft.
Distillation is fast and cheap precisely because it skips the years of research the original model required — which is exactly why Washington escalated from a White House memo to a six-company federal advisory in five months flat. A sanctions-ready bill is sitting in Congress, a Treasury Secretary has named Entity List designations on X, and a Trump-Xi summit lands sixteen days after the advisory’s ink dried. Nobody involved disputes that distillation happened. What’s still unresolved is who pays for it, and how.



