Tuesday, September 29, 2026
AI desk
/
/
US Agencies Accuse 6 Chinese AI Firms of Industrial-Scale Model Distillation

US Agencies Accuse 6 Chinese AI Firms of Industrial-Scale Model Distillation

US agencies accuse six Chinese AI firms of extracting capabilities from U.S. frontier models through industrial-scale distillation campaigns.
Last updated
September 10, 2026
8 min read
Fact-checked

Photo: TechJournal

Share

Quick Answer

US agencies allege that six China-based AI companies ran industrial-scale campaigns to distill restricted capabilities from U.S. frontier models. The joint NSA, FBI, and CISA advisory names DeepSeek and Alibaba among the firms and describes alleged account, API, and proxy tactics. The claims are disputed by China. AI providers should review abuse detection and share threat intelligence.

Key Takeaways

  • US agencies named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI in a September 8, 2026 advisory.
  • The advisory alleges that campaigns targeted variants of Claude, GPT, Gemini, and Grok beginning at least in late 2024.
  • Alleged methods included APIs, cloud providers, third-party aggregators, proxy services, and shared subscriptions.
  • The agencies urged AI providers to detect suspicious usage patterns and share intelligence across companies.
  • China rejected the allegations and described distillation as a normal technical and commercial practice.

What did US agencies allege about AI model distillation?

US agencies allege that China-based AI companies systematically extracted restricted proprietary functions and capabilities from American frontier AI models to train competing systems. The September 8, 2026 joint advisory from the National Security Agency, FBI, and Cybersecurity and Infrastructure Security Agency describes the activity as industrial-scale distillation rather than ordinary use of publicly available AI services.

The NSA release on the joint advisory says the alleged campaigns sought to obtain restricted model capabilities at scale. This matters because frontier AI providers generally place usage controls around high-volume access, premium features, and certain model functions to prevent unauthorized extraction or misuse.

AI model distillation is not inherently improper as a technical concept. Developers can use a stronger model’s outputs to help train a smaller or more efficient system when the activity is permitted by the model provider’s terms and access rules. The agencies’ allegation focuses on the claimed use of restricted access, automated accounts, and evasion methods to obtain capabilities that providers did not authorize for large-scale copying.

The practical conclusion is that the advisory does not establish a court finding against the companies named in it. The advisory does, however, set out a specific US government assessment of alleged methods and targets that AI providers, enterprise customers, and policymakers are likely to examine closely.

Which AI companies and models did the advisory name?

The joint advisory named 6 China-based AI companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies said the alleged activity likely occurred with Chinese government awareness, although the advisory did not present that claim as a judicial determination.

The advisory says the alleged campaigns targeted variants of Anthropic Claude, OpenAI GPT, Google Gemini, and xAI Grok models beginning at least in late 2024. The list matters because these models are widely used through consumer chatbots, developer APIs, workplace tools, and cloud services. A company that relies on API-based AI features may therefore need to consider whether its access controls are designed for individual users or for automated, enterprise-scale extraction attempts.

Frontier model competition has also increased pressure to make AI systems cheaper to operate. For example, developers are increasingly interested in systems that route tasks across several models to control inference costs, a goal reflected in multi-model coding systems. Lower operating costs can be legitimate, but the NSA advisory distinguishes authorized optimization from alleged attempts to bypass provider limits.

The most important limitation is that the advisory identifies targets and alleged activity, not a complete technical record for public inspection. Readers should treat the government claims as serious allegations that remain contested by China and the companies implicated by the advisory.

How did the alleged AI model copying campaigns operate?

The alleged AI model copying campaigns used several access paths rather than relying on a single method. The agencies identified native APIs, remote cloud providers, third-party aggregators, gray-market proxy services called transfer stations, shared premium subscriptions, chain-of-thought extraction, and automated account switching after blocks.

Alleged methodHow the advisory describes itWhy it matters for providers
Native APIsDirect use of a model provider’s application programming interface.High-volume requests can expose unusual usage patterns and require rate-limit monitoring.
Remote cloud providersAccess through cloud infrastructure rather than a single local network.Distributed infrastructure can make account and network attribution more difficult.
Third-party aggregatorsUse of intermediary services that provide access to several models.Intermediaries can complicate provider visibility into the end user.
Transfer stationsGray-market proxy services that route requests through other accounts or systems.Proxy routing can undermine account-level controls and subscription enforcement.
Automated account switchingMoving activity to other accounts after a provider blocks one account.Providers need to correlate accounts, networks, and request behavior.

Chain-of-thought extraction was also listed as an alleged tactic. The term refers to attempts to obtain intermediate reasoning or other restricted behavior from a model rather than only receiving a final answer. The concern is not that every detailed prompt is abusive, but that automated prompt patterns can seek information or capabilities that providers intentionally limit.

The advisory’s description is particularly relevant to companies offering developer access. Providers can face abuse that appears ordinary when viewed through one account, while the combined pattern across subscriptions, IP addresses, cloud networks, and request volume indicates coordinated activity.

Why does the distinction between distillation and theft matter?

The distinction between permitted distillation and alleged unauthorized extraction matters because AI development often involves learning from model outputs, but providers set contractual and technical limits on how their services may be used. China said distillation is a normal technical and commercial practice, while US agencies said the campaigns described in the advisory involved restricted proprietary functions and evasive access methods.

China’s Commerce Ministry rejected the US allegations on September 10, 2026, calling them groundless and arguing that US companies have also disclosed distilling Chinese models. The Chinese Commerce Ministry response frames the dispute as a broader disagreement over commercial AI development practices rather than evidence of one-sided misconduct.

This disagreement matters because model providers, regulators, and courts may evaluate the same technical activity differently depending on access terms, the type of output collected, the volume of requests, and whether a party bypassed account restrictions. Public claims about AI training practices also intersect with ongoing debates about copyright, contracts, trade secrets, and fair use, including the federal government’s position in the AI training fair use case.

The practical response is to avoid treating the word “distillation” as a complete legal or ethical verdict. The key question is whether model outputs and features were accessed under authorized terms and without evading the provider’s safeguards.

What defenses did the agencies recommend for AI providers?

The NSA, FBI, and CISA recommended that AI providers monitor suspicious prompts, accounts, networks, subscription-to-usage ratios, and enterprise-scale throughput. The agencies also urged cross-company intelligence sharing so one provider’s detection of a coordinated campaign can help other providers recognize related activity.

Subscription-to-usage ratios can help identify accounts whose consumption does not match normal individual or business behavior. Enterprise-scale throughput can indicate that requests are being automated or routed through a network of accounts. Neither signal proves wrongdoing by itself, because legitimate organizations can have heavy workloads, but the combination of signals can justify closer review.

The agencies’ recommended approach recognizes that account bans alone may not stop coordinated activity. A group that switches accounts, networks, subscriptions, or intermediary services can resume access unless providers compare patterns across those systems. The published details of the alleged methods and mitigations also emphasize the agencies’ focus on coordinated defensive measures.

AI providers should start with logging, rate controls, account review processes, and escalation paths that distinguish routine high-volume use from suspicious automated extraction. Security teams should stop short of automated enforcement when evidence is incomplete, because a false positive can interrupt legitimate enterprise customers and developers.

What has China said about the US allegations?

China rejected the US allegations and said AI model distillation is a normal technical and commercial practice. China’s Foreign Ministry called the accusations unfounded on September 9, 2026 and said China would take resolute countermeasures if the United States suppressed Chinese AI companies over distillation.

The AP report on China’s response records the Foreign Ministry’s rejection of the allegations. China’s Commerce Ministry followed on September 10 with a separate statement that characterized the US claims as groundless and pointed to disclosures by US firms involving Chinese models.

The competing statements show that the dispute is both technical and geopolitical. US agencies describe alleged unauthorized extraction of proprietary capabilities, while Chinese officials describe distillation as an accepted development practice and object to US restrictions on Chinese companies.

Readers should separate the two positions carefully. The US advisory provides the government’s assessment of alleged conduct and recommended defenses. China’s responses dispute the factual and policy basis for that assessment. Neither position removes the need for AI providers to protect accounts, APIs, and premium model access against unauthorized automated use.

What should AI companies and ordinary users do now?

AI companies should review access controls now if their services expose high-value model capabilities through APIs, subscriptions, or third-party platforms. The advisory’s recommendations point to 5 areas for review: prompts, accounts, networks, subscription-to-usage ratios, and enterprise-scale throughput.

  1. Review rate limits and account verification rules for API and premium subscription access.
  2. Monitor repeated prompts that seek restricted functions, hidden reasoning, or other protected behavior.
  3. Compare account behavior with network activity and request volume to identify coordinated automation.
  4. Document escalation procedures before blocking high-volume customers or suspected proxy activity.
  5. Share relevant indicators with trusted security partners when a pattern appears coordinated across providers.

Ordinary users do not need to change how they ask normal questions in consumer AI apps because the advisory addresses alleged industrial-scale activity. Users should still avoid entering confidential work material, financial information, health records, or private credentials into AI tools unless their organization has approved that use. The security risks surrounding AI access also reinforce why organizations should follow timely security update guidance across the systems that employees use to access cloud services.

Security teams should contact their AI provider, cloud provider, or legal counsel when suspected activity involves account compromise, unauthorized API use, contract questions, or possible trade-secret exposure. Individual users should not attempt to investigate suspicious account activity by accessing logs or systems they do not own.

FAQ

What is AI model distillation?

AI model distillation is a training approach that uses outputs or capabilities from one model to help build another model. The US advisory alleges that the named companies extracted restricted proprietary functions from US frontier models without authorized large-scale access.

Which companies did US agencies name in the advisory?

The joint US advisory named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The advisory says the alleged campaigns targeted variants of Claude, GPT, Gemini, and Grok models.

Did the US agencies prove that the companies copied AI models?

The US agencies presented allegations and a cybersecurity assessment, not a court judgment. China rejected the allegations, so the claims remain disputed.

What are transfer stations in the AI model distillation advisory?

Transfer stations are gray-market proxy services that the advisory says can route AI requests through intermediary accounts or systems. The alleged practice can make account-level controls and provider monitoring less effective.

Should ordinary AI users change how they use chatbots?

Ordinary AI users do not need to change normal chatbot use because the advisory focuses on alleged enterprise-scale extraction campaigns. AI users should continue to keep confidential personal, financial, and work information out of prompts unless approved safeguards are in place.

Share this guide
Facebook
X
LinkedIn
Written by
James Chen is a technology journalist covering artificial intelligence, software tools, and the future of work. He has been testing and reviewing AI products since 2023 and has hands-on experience with every major AI platform. His work focuses on helping everyday users get more done with AI — without the hype.

In this article

The AI Brief

Guides like this, every Friday.

One email. No hype cycle.

Keep reading