Skip to content
§ Tech Intelligence / AI Model Theft · September 2026

The NSA, FBI, and CISA Say Six Chinese AI Companies Don’t Just Copy American Models. Copying Is the Strategy.

On September 8, 2026, the National Security Agency, the FBI, and the Cybersecurity and Infrastructure Security Agency jointly accused six China-based AI developers — DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI — of running industrial-scale campaigns since late 2024 to extract the capabilities of Claude, ChatGPT, Gemini, and Grok through a technique called distillation.

The joint advisory doesn’t describe a side hustle. It says the practice “forms the core — not merely a supplement” of Chinese AI development strategy. Treasury Secretary Scott Bessent has already floated sanctions and Entity List designations against firms whose distillation “crosses the line into IP theft.”

§ 01 / 'The Core, Not Merely a Supplement'

Distillation is not, on its own, exotic or illegal. It is a standard machine-learning technique: a smaller “student” model learns to mimic a larger “teacher” model by training on the teacher’s outputs, producing a cheaper, faster model that approximates the original’s abilities. What the joint advisory describes is not that technique in the abstract — it is the specific, evasive machinery Chinese firms allegedly built around it. The advisory says Chinese AI companies route requests through a gray market of API proxies it calls “transfer stations” designed to bypass geographic restrictions and undermine traceability, layer on automated metadata sanitization that strips organizational identifiers at the infrastructure level, and bulk-buy premium subscriptions shared across developer teams using accounts with obfuscated origins.

“China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core — not merely a supplement — of their AI development strategy,” the advisory states. CISA Acting Director Nick Andersen put it more bluntly: “We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns.” The agencies recommend U.S. labs monitor subscription-to-usage ratios and immediate maximum usage from new accounts, quietly degrade responses to high-confidence distillation attempts without alerting the requester, and share intelligence on distillation campaigns across companies.

New DeepSeek, Alibaba Models Take On Anthropic, OpenAI — Bloomberg: The China Show
§ 02 / Six Companies, Four American Labs

The advisory lays out a company-by-company target list. DeepSeek allegedly pulled reasoning, agentic, and specialized capabilities from multiple GPT, Claude, Gemini, and Grok versions since late 2024 to train its R1 and V3 models — and the agencies say DeepSeek’s widely cited $5.6 million training-cost figure, the number that convinced markets a frontier-class model could be built for the price of a London townhouse, is misleading because it omits the cost of the distilled data itself. Moonshot AI drew on Claude and GPT since mid-2025 to sharpen its Kimi models’ software-engineering and reasoning skills. Alibaba used Claude and GPT-5 output to improve its Qwen family. MiniMax targeted Claude Code’s chain-of-thought and reinforcement-learning data through attempted prompt-injection attacks. StepFun went after reasoning and coding capabilities across several models. And Z.AI, the advisory says, had extracted billions of tokens from GPT-5.5 and Claude Opus 4.8 by mid-2026 to build chain-of-thought reasoning into its own systems.

Six companies, four American model families, and wildly different scales — the accounting problem underneath a single headline about 'theft.'
Chart · Claude Distillation Exchanges by Chinese AI Lab
Source: Anthropic disclosures to the U.S. Senate, Feb. & Jun. 2026 — bars log-scaled for readability, exact counts labeled
DeepSeek
150,000 exchanges
Disclosed by Anthropic, February 2026
Moonshot AI
3.4 million exchanges
Disclosed by Anthropic, February 2026
MiniMax
13 million exchanges
Disclosed by Anthropic, February 2026
Alibaba
28.8 million exchanges
Disclosed by Anthropic, June 2026 — via ~25,000 fraudulent accounts over 44 days
Z.AI and StepFun are excluded from this chart — the September 2026 federal advisory quantifies their activity in tokens extracted, not exchange counts, so the figures are not directly comparable.
X
Kyle Chan
@kyleichan · June 24, 2026

This is a really massive unauthorized distillation campaign. For comparison, reported from Anthropic: DeepSeek: 150,000 exchanges. Moonshot: 3.4 million. MiniMax: 13 million. Alibaba: 28.8 million.

§ 03 / From a Senate Letter to a Federal Advisory

The September advisory is the fourth escalation in a seven-month arc, not a first strike. Anthropic disclosed the first cluster of distillation attempts in February 2026 — DeepSeek, Moonshot AI, and MiniMax, combined, at roughly 24,000 fraudulent accounts and more than 16 million exchanges. The White House followed on April 23 with National Science and Technology Memorandum 4, in which OSTP Director Michael Kratsios wrote that “large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable” and accused foreign entities “principally based in China” of using “tens of thousands of proxy accounts” and jailbreaking techniques.

Then came Alibaba, specifically. On June 10, Anthropic sent Senate Banking Committee leaders Tim Scott and Elizabeth Warren a letter accusing Alibaba-linked operators of the largest known distillation attack to date — a campaign it called “brazen” and “illicit,” run through roughly 25,000 fraudulent accounts across 44 days. September’s joint advisory folds that Alibaba-specific finding into a six-company federal warning — the shift from one company’s letter to Congress to three agencies’ joint name-and-shame.

Timeline · From a White House Memo to a Federal Advisory
Feb 2026
Anthropic's first distillation disclosure
Anthropic reports catching DeepSeek, Moonshot AI, and MiniMax running extraction campaigns against Claude using roughly 24,000 fraudulent accounts and more than 16 million exchanges combined.
Apr 16, 2026
“China's Campaign to Steal America's AI Edge”
The House Select Committee on the CCP holds a hearing on Chinese AI acquisition tactics; former acting DIA director David Shedd testifies that distillation sharply cuts the cost of recreating U.S. capabilities.
Apr 23, 2026
The White House names the problem: NSTM-4
OSTP Director Michael Kratsios issues National Science and Technology Memorandum 4, accusing foreign entities “principally based in China” of running deliberate, industrial-scale distillation campaigns.
Jun 10, 2026
Anthropic writes to the Senate Banking Committee
A letter to Sens. Tim Scott and Elizabeth Warren accuses Alibaba-linked operators of the largest known distillation attack yet: 28.8 million Claude exchanges through roughly 25,000 fake accounts.
Jul 22, 2026
Bessent puts sanctions on the table
Treasury Secretary Scott Bessent posts that covert, industrial-scale distillation crossing into IP theft will trigger sanctions and Entity List designations.
Sep 8, 2026
NSA, FBI, and CISA name six companies at once
The joint advisory expands the accusation beyond Alibaba to DeepSeek, Moonshot AI, MiniMax, StepFun, and Z.AI, calling distillation the core of Chinese AI strategy, not a supplement to it.
Sep 24, 2026
Trump and Xi are scheduled to meet
AI governance is expected on the agenda for the two leaders' planned talks, arriving two and a half weeks after the advisory's publication.
Anthropic vs Alibaba: 28 Million Queries, 25K Fake Accounts — The Biggest Claude Distillation Ever
§ 04 / Sanctions, an Entity List, and a Bill With Teeth

Congress moved on the gap between “named” and “punished” before the advisory even shipped. The Deterring American AI Model Theft Act of 2026 (H.R. 8283), introduced in April and advanced by the House Foreign Affairs Committee, would require the State Department to identify foreign entities extracting American closed-source model capabilities, publish a public “AI Model Extraction Attackers List,” and make anyone on it eligible for Commerce Department Entity List designation and blocking sanctions. Select Committee on the CCP Chairman John Moolenaar, a cosponsor, said the bill “complements the work my colleagues and I are doing in Congress to stop China’s AI theft and protect national security,” adding that “to keep our advantage over our adversary, I will continue working to pass legislation that modernizes our export controls.”

X
Scott Bessent
@SecScottBessent · July 22, 2026

We support open-source AI and the innovation it unlocks. But open source is not open season on American IP. When PRC firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.

The Reframe — Distillation Isn't the Crime, Evasion Is

Every major AI lab distills its own models, and rivals training on public outputs are not automatically doing anything unlawful. What the advisory and Anthropic’s letters describe as the violation isn’t the technique — it’s the alleged terms-of-service evasion: proxy “transfer stations,” fabricated accounts, and stripped metadata built specifically to avoid detection. That distinction is what H.R. 8283 and the Entity List threat are actually aimed at.

§ 05 / Beijing Pushes Back, Trump-Xi Three Weeks Out

China’s Ministry of Foreign Affairs rejected the advisory the same week it was published. Spokesperson Mao Ning said China’s AI development “is the result of high-level technological self-reliance and strength” and urged Washington to “refrain from making unfounded accusations or smears.” A Chinese embassy spokesperson, Liu Chang, called the advisory “a deliberate attack on China’s development and progress in the AI industry.” None of the six named companies had issued a public response as of publication.

The timing is not incidental. President Trump and President Xi Jinping are scheduled to meet on September 24, and AI governance is expected on the agenda. A federal advisory naming six of China’s highest-profile AI developers — published sixteen days before that meeting — hands American negotiators a specific, public grievance to raise, and hands Beijing a specific, public grievance to reject before the two leaders sit down.

US: Anthropic Accuses Alibaba Of Massive AI 'Theft' Campaign — Firstpost Live
§ 06 / Not Everyone Is Alarmed

The government’s framing is not universally shared inside the industry it’s meant to protect. OpenAI CEO Sam Altman, asked about distillation risk in a July 2026 interview, was unbothered: “I would rather people not distill from us, for sure. But this is not in my top ten list of worries.” Tesla and xAI’s Elon Musk went further, turning the accusation back on Anthropic itself — a pointed jab at Anthropic’s own $1.5 billion settlement over how it acquired training-book data.

Anthropic is guilty of stealing training data at massive scale and has had to pay multi-billion dollar settlements for their theft.

Elon Musk · February 23, 2026, on X

The dispute over how alarmed to be hasn’t slowed the underlying market. CNBC reported in September that Claude API keys, obtained through exactly the kind of fraudulent-account campaigns the advisory describes, are now resold on gray-market forums at 70–90% below retail price — evidence, security researchers say, that the extraction pipeline the government is warning about has already spawned its own secondary economy, independent of whether Washington and Beijing ever agree on what to call it.

How China Is 'Stealing' America's Best AI (Distillation Explained) — Cloud Codes
X
Select Committee on China
@ChinaSelect · April 16, 2026

At our April 16 hearing, 'China's Campaign to Steal America's AI Edge,' one thing was clear: the CCP is racing for AI dominance and stealing American AI models and IP to get ahead. Chairman Rep. Moolenaar highlighted how Chinese firms combine legal purchases with theft.

Bottom Line

Distillation is fast and cheap precisely because it skips the years of research the original model required — which is exactly why Washington escalated from a White House memo to a six-company federal advisory in five months flat. A sanctions-ready bill is sitting in Congress, a Treasury Secretary has named Entity List designations on X, and a Trump-Xi summit lands sixteen days after the advisory’s ink dried. Nobody involved disputes that distillation happened. What’s still unresolved is who pays for it, and how.

Sources & Methodology · 20 Sources
The underlying story — that NSA, CISA, and the FBI jointly named six China-based AI developers over industrial-scale model distillation — originates with a joint federal advisory (AA26-251A) published September 8, 2026, and Bloomberg’s same-day report; this page relies on CISA’s own advisory and news release as primary text, with NBC News, CNN, CyberScoop, Nextgov/FCW, and TheNextWeb used to corroborate figures and quotes where Bloomberg’s article sits behind a paywall. Distillation figures for DeepSeek, Moonshot AI, and MiniMax come from Anthropic’s February 2026 disclosure; the Alibaba figure comes from Anthropic’s June 10, 2026 letter to the Senate Banking Committee, reported by CNBC and Tom’s Hardware. Z.AI and StepFun figures are reported in extracted tokens rather than exchange counts by the September advisory and are described qualitatively rather than charted alongside the exchange-count figures for that reason. Distillation is a standard, often legal machine-learning technique; the dispute detailed here concerns the specific methods — terms-of-service evasion, proxy accounts, and undisclosed automation — that U.S. agencies say cross into unauthorized access, not the underlying technique itself. No named Chinese company had filed a public legal response as of publication; all allegations described are as stated by the named U.S. agencies and Anthropic and have not been adjudicated. Per this site’s non-political AI/tech coverage style, U.S. officials’ party affiliations are omitted as immaterial to this national-security and export-policy reporting. No genuine Truth Social post specific to this advisory was located in this reporting window and none is embedded here rather than fabricated to fill the standard.