US intelligence agencies accuse six Chinese AI firms of industrial-scale theft of American model capabilities
A joint advisory from the NSA, FBI and CISA says DeepSeek, Alibaba and four other Chinese AI developers have run systematic distillation campaigns against Claude, GPT, Gemini and Grok since late 2024, extracting billions of tokens to train their own models cheaply.

Three of the United States' principal security agencies said Tuesday that six Chinese artificial intelligence companies have spent nearly two years systematically extracting the underlying capabilities of America's leading AI models, in a campaign the agencies described as running at an "industrial scale."
A joint cybersecurity advisory issued by the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI names DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI as the companies behind what the advisory calls "aggressive, malicious, and targeted distillation activities" aimed at American frontier models, including variants of Anthropic's Claude, OpenAI's GPT series, Google's Gemini and xAI's Grok. The advisory, designated AA26-251A and published September 8, states the activity has been under way "since at least late 2024" and was likely conducted with the awareness of the Chinese government.
Distillation is a legitimate and widely used machine-learning technique in which a smaller model is trained to mimic the outputs of a larger, more capable one, cutting the cost of development. The agencies' complaint is not with the technique itself but with what they describe as covert, unauthorized use of it against competitors' proprietary systems, in violation of those companies' terms of service.
The numbers
According to the advisory, the named companies collectively extracted "billions of tokens across millions of exchanges and requests" from U.S. models. The agencies said the technique functions as "the core — not merely a supplement" of the companies' AI development strategy, rather than an occasional shortcut.
The advisory singles out DeepSeek for training its R1 and V3 models on outputs drawn from GPT-4, GPT-5 and multiple Claude versions, and says the company's widely cited $5.6 million training cost for R1 is "misleading" because it excludes the expense of the distilled data. Moonshot AI is accused of building its Kimi K3 model in part from Claude's Fable system and its earlier Kimi K2 from GPT-4o outputs. Alibaba is said to have used large-scale distillation to improve its Qwen model family, and MiniMax and StepFun are named in connection with their M2 and Step 4 models respectively.
Those figures echo a February report Anthropic published on distillation attacks, which said DeepSeek, Moonshot and MiniMax together generated more than 16 million exchanges with Claude using roughly 24,000 fraudulent accounts — DeepSeek alone logging more than 150,000 exchanges, Moonshot more than 3.4 million and MiniMax more than 13 million. Anthropic later told lawmakers that operators linked to Alibaba's Qwen lab had run more than 28.8 million exchanges through nearly 25,000 fraudulent accounts, which it called the largest distillation campaign it has publicly disclosed.
How the campaigns worked
The advisory describes methods designed to evade detection: routing requests through native APIs, remote cloud providers and third-party "aggregators" that obscure user metadata and location. It says gray-market "transfer stations," as the advisory describes them, resell access to frontier models at a fraction of the official price, letting distillation operations obtain outputs in bulk while masking their origin. Anthropic's own account described similar "hydra cluster" networks of fraudulent accounts spreading traffic across its API and third-party cloud platforms to avoid triggering abuse controls.
The advisory's recommended defenses for AI developers ask American companies to detect anomalous accounts and prompts, quietly degrade responses to suspected distillation attempts without alerting the accounts involved, and share threat intelligence across the industry — a practice OpenAI, Google and Anthropic say they already coordinate through the Frontier Model Forum, an industry body formed to address shared safety and security concerns.
Diplomatic backdrop
The advisory's release carries diplomatic weight. It lands roughly two weeks before Chinese President Xi Jinping is expected in Washington on September 24, and ahead of a planned U.S.-China AI safety dialogue later in the month. Treasury Secretary Scott Bessent said separately that China "can never get ahead" of the United States in AI.
Beijing rejected the allegations. Asked about the advisory at a regular briefing the following day, foreign ministry spokesperson Mao Ning said China's AI progress reflected "greater self-reliance and strength in science and technology," called on Washington to "stop leveling false allegations to smear China," and said the two countries, as major AI powers, "should step up cooperation." China's Commerce Ministry went further, characterizing distillation as a common industry practice and warning that "if the U.S. suppresses Chinese AI companies under the pretext of targeting distillation, China will take resolute countermeasures."
"China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models."
None of the six named companies has issued a public response to the specific claims in the advisory.
Who is affected, and what happens next
The advisory is aimed chiefly at the U.S. AI companies whose models are named as targets — Anthropic, OpenAI, Google and xAI — urging them to tighten account verification and monitoring. It also carries implications for enterprise customers who rely on Chinese open-weight models such as DeepSeek's R1 or Alibaba's Qwen, which the advisory suggests may carry over the training data, biases or vulnerabilities of the American systems they were distilled from without preserving those systems' safety guardrails. Anthropic has previously warned that models built through illicit distillation are unlikely to retain the safety safeguards of the models they were trained on, which it said creates a risk that dangerous capabilities could proliferate into less-controlled systems.
The dispute is not new — Anthropic, OpenAI and Microsoft have all previously restricted accounts they suspected of running distillation campaigns, and White House science adviser Michael Kratsios raised similar concerns publicly in July — but Tuesday's advisory marks the first time NSA, CISA and the FBI have jointly and publicly named specific Chinese companies at this scale. Whether it leads to concrete policy action, such as tighter export or access controls on U.S. model APIs, is likely to depend on the outcome of this month's Trump-Xi talks and the parallel AI safety dialogue between the two governments. For now, the advisory functions primarily as a public warning to industry, paired with a pointed diplomatic signal ahead of the highest-level U.S.-China contact of the year.

Mistral Raises €3 Billion in Europe's Largest Tech Funding Round, Led by Samsung

OpenAI says AI agents cracked part of the Navier-Stokes problem, but a credit fight erupts first
