"China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy," the joint advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI stated.
The joint advisory and its central claim
The U.S. agencies released a joint cybersecurity advisory accusing China-based AI firms of deliberate, industrial-scale distillation of frontier U.S. AI models. The advisory says those campaigns have been ongoing since at least late 2024 and characterizes the activity as constituting a critical part of China’s AI industrial policy rather than a peripheral tactic. The agencies describe the behavior as “aggressive, malicious, and targeted distillation activities at an industrial scale.”
Which companies and U.S. models are named
The advisory names Chinese companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It identifies the targeted frontier U.S. models as Anthropic’s Claude, OpenAI’s ChatGPT, Google Gemini and xAI’s Grok, among others. The agencies say the Chinese firms spent “billions of tokens across millions of exchanges and requests” with those models to extract data used to strengthen domestic systems.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildConcrete examples: DeepSeek and Moonshot AI
The advisory gives specific case studies. DeepSeek allegedly distilled frontier U.S. models to generate synthetic training data for its R1 and R3 models, drawing from four different versions of Claude, two versions of Gemini, five versions of ChatGPT and Grok 4. The agencies say those distilled outputs helped DeepSeek train capabilities in areas including agentic functioning, question-and-answer optimization, and creative and occupational writing.
Moonshot AI is named for distilling 18 different U.S. models — including Fable 5 and “Anthropic’s current, most advanced commercially available model” — to train its Kimi-K2 and Kimi K3 models. According to the advisory, Moonshot used millions of queries designed to extract enhanced capabilities in agentic reasoning, coding and data analysis, computer vision, larger logical frameworks and visual processing.
Tactics the advisory says were used to avoid detection
The advisory details a toolkit of evasion techniques. Observed behaviors include spreading requests across different accounts, models and platforms; using native APIs, remote cloud providers and third-party aggregators to obfuscate user metadata; and leveraging proxies and “gray tech markets” to sidestep geographic restrictions, terms of use and built-in safeguards on frontier models. The agencies contend these routing and obfuscation methods support industrial-scale knowledge distillation campaigns.
What this means for technologists, policymakers, and rights holders
- Technologists and security teams: The advisory frames distillation as a large-scale operational problem that combines volume (billions of tokens, millions of requests) with layered evasion techniques. Teams will need to watch for patterns the advisory highlights — cross-account spreading, third-party aggregation, and proxy routing — in addition to individual anomalous queries.
- Policymakers and regulators: The agencies urged a coordinated response “across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations.” The advisory places distillation squarely in the domain of national-security-related industrial policy and calls for cross-sector collaboration to address it.
- Artists, authors and media organizations: The advisory’s allegations arrive against a backdrop in which frontier AI companies themselves are facing lawsuits from creators and media organizations asserting illegal training on copyrighted or trademarked work. The agencies acknowledge that model-sharing and legitimate distillation occur in research contexts, but characterize the Chinese firms’ activities as targeted and malicious at scale — a distinction that may affect legal and commercial disputes over training data provenance.
The advisory also notes a continuity with past U.S. concerns about Chinese acquisition of sensitive technologies: for decades national-security officials and Western business leaders have accused China of using cyberattacks, insider threats and other espionage to obtain proprietary technologies. In June, Michael Kratsios, the White House head of the Office of Science and Technology Policy, made a similar accusation about Moonshot AI distilling Fable 5 and described a “sophisticated” system for evading guardrails.
The U.S. agencies end with a policy prescription: industrial-scale distillation requires coordinated information-sharing among government, private industry and allies. That recommendation is both a directive for action and a test. The advisory paints distillation as a strategic, high-volume effort that is reshaping how some Chinese firms build AI; whether defenders can match that scale through detection, legal action or international cooperation remains the immediate question posed by the agencies’ findings.




