The U.S. National Security Agency, Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency have accused six China-based artificial intelligence companies of running industrial-scale campaigns to extract capabilities from U.S. frontier AI models.
In a joint cybersecurity advisory issued Sept. 8, the agencies named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. They said the companies extracted billions of tokens across millions of exchanges and requests from U.S. AI models since at least late 2024.
The agencies described the activity as a systematic effort to obtain proprietary capabilities while reducing the research, computing and financial costs normally required to develop advanced models. They said the activity could shorten development timelines and threaten U.S. technological leadership.
Distillation is legitimate, but the U.S. alleges misuse
Knowledge distillation is a legitimate AI technique. Developers can use it to transfer useful behavior or capabilities from a larger model to a smaller one.
The U.S. agencies said the issue is not distillation itself. Their allegation is that the six companies used the technique at an industrial scale to extract restricted capabilities from U.S. frontier models.
The advisory says the companies used several routes to reach U.S. models. These included direct application programming interfaces, cloud providers and third-party API aggregators.
The agencies also described a gray market of API proxies, which they called “transfer stations.” They said these services could help users bypass geographic restrictions, avoid safeguards and make activity harder to trace.
The advisory says some operations also used multiple accounts, shared premium subscriptions and automated systems to distribute requests across different providers.
Six companies named in the U.S. advisory
The agencies said DeepSeek began an organized distillation campaign by at least late 2024. They allege that the company extracted capabilities related to reasoning, legal tasks, coding, question-and-answer performance and agentic functions for its R1 and V3 models.
The advisory says Moonshot AI began a widespread campaign by at least mid-2025. U.S. officials allege that the company used outputs from several American models to improve capabilities in software engineering, mathematics, supervised fine-tuning and reinforcement learning.
The agencies also named Alibaba, MiniMax, StepFun and Z.AI.
According to the advisory, Alibaba used distillation to improve areas including software engineering, customer-service dialogue and agentic workflows. MiniMax was accused of extracting reasoning, coding and software-development capabilities. StepFun was linked to coding and agentic functions, while Z.AI was accused of extracting reasoning capabilities.
The advisory says the campaigns generated activity on a very large scale. It describes operations involving thousands to millions of requests focused on particular areas of knowledge or model behavior.
U.S. agencies allege coordinated efforts to evade safeguards
The advisory says the companies used tactics designed to reduce the chance that providers would detect or block their activity.
These included fraudulent or multiple accounts, similar payment information, third-party aggregators and coordinated prompts. The agencies also allege that some operators switched between access routes when providers attempted to block activity.
U.S. officials also accused the companies of using prompt injection and jailbreak techniques to extract information from AI models. The advisory says some prompts attempted to make models reveal hidden chain-of-thought reasoning.
The agencies said such data could help train other models not only to reproduce information, but also to improve reasoning for coding, logical tasks and agentic systems.
The advisory further says some operators used automated quality checks to determine whether providers had changed model responses to disrupt extraction efforts.
China rejects U.S. accusations
China has rejected earlier U.S. allegations involving AI model distillation.
In July, China’s Ministry of Commerce said U.S. accusations against Chinese AI companies lacked factual and legal grounds. The ministry said distillation is widely used in AI research and argued that Washington was politicizing technology and trade issues.
The ministry also said Chinese AI companies had invested in basic research and technological development. It argued that U.S. companies also use Chinese AI models in research, development and training.
China’s response came after U.S. officials had discussed possible investigations and sanctions related to alleged use of American AI models by Chinese companies. The ministry said China would protect its interests if U.S. measures caused material harm.
The dispute adds pressure to the U.S.-China AI race
The U.S. allegations highlight a growing challenge for AI companies: protecting the capabilities of advanced models while making those systems available to legitimate users.
The agencies said industrial-scale distillation could allow companies to reproduce valuable capabilities with lower research and computing costs. They recommended that U.S. AI companies monitor unusual accounts, request patterns, network activity and usage levels.
They also urged companies to share information about suspicious activity across AI providers, cloud platforms and API aggregators. The goal is to identify campaigns that may appear fragmented when viewed from a single service but become visible when activity is compared across providers.
The dispute also reflects the broader strategic competition between the United States and China over advanced AI. Frontier models are increasingly tied to economic competitiveness, cybersecurity, military capabilities and control over critical technology.
The latest U.S. advisory presents the accusations as an intelligence and cybersecurity assessment. It does not establish a court finding that the six companies committed intellectual-property theft. The companies’ alleged conduct and the broader dispute remain part of the ongoing U.S.-China technology confrontation.
Reporting Credit: National Security Agency, Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency — Sept. 8, 2026 joint Cybersecurity Advisory identifying six China-based AI companies, describing the alleged industrial-scale distillation campaigns and outlining the tactics and defensive measures discussed by U.S. authorities. China’s Ministry of Commerce — July 2026 response rejecting U.S. allegations concerning Chinese AI companies and defending model distillation as a widely used AI technique.














