"While 'distillation' is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models," the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation wrote in a joint bulletin.
NSA, CISA, and FBI: the advisory and its central claim
The three agencies say China-based AI firms have conducted "systematic extraction" of proprietary functionalities and capabilities from U.S. frontier models through what they call industrial-scale distillation attacks. The bulletin alleges this activity forms the "core" of those firms' AI development strategy and adds that the campaigns likely proceeded with the blessing of the Chinese government.
Accused China-based firms and the U.S. models cited
The advisory names specific companies and links them to distinct extraction campaigns. It alleges DeepSeek ran organized efforts between late 2024 and mid-2025 to harvest reasoning capabilities, specialized optimizations, and domain-specific functions for its R1 and V3 models. Moonshot AI is accused of extracting Claude Fable 5 data for its Kimi-K3 and GPT-4o data for its Kimi-K2. Alibaba is said to have distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 in late 2025 to improve software engineering, customer service dialogue, image and character creation, and the integration of RL, SFT, and distillation techniques. MiniMax, StepFun, and Z.AI are also named with specific target-model timelines extending into early 2026.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleIndustrial-scale techniques: chain-of-thought, automated failovers, and quality frameworks
The agencies describe advanced tactics that go beyond simple bulk querying. Those tactics include extraction of chain-of-thought (CoT) reasoning, automated failover between query pathways when blocking is encountered, and sophisticated quality-evaluation frameworks designed to detect defensive countermeasures. The bulletin says such approaches shorten AI development timelines and reduce training costs for the accused firms.
Access channels, geographic restrictions, and a gray market
The bulletin notes U.S. frontier models are officially restricted and not offered in China, and it links that restriction to a variety of workarounds. The advisory says Chinese developers relied on virtual private networks, obfuscated accounts, automated agents, and third-party aggregators that hide user metadata to bypass geographic controls. It also cites a gray market of proxies that relay or transfer illicit access through servers hosted outside mainland China, with such services marketed on Chinese online marketplaces Taobao and Xianyu. The agencies add that cost savings for distillation campaigns were achieved through bulk procurement of U.S. AI companies' premium subscriptions shared across developer teams.
Corroborating signals: vendors and industry voices
The bulletin follows related public statements. Anthropic said earlier in February it had identified industrial-scale campaigns by DeepSeek, Moonshot AI, and MiniMax to extract Claude's capabilities. Google Threat Intelligence Group is cited as observing a spike in distillation campaigns targeting Google's AI models, some exceeding 100 million prompts and focusing on visual and audio understanding, image generation, and video generation. Google warned that attackers rotate queries across thousands of compromised credentials and fraudulent accounts to obscure origin and bypass standard security controls.
What this means for technologists, policymakers, and enterprises
- Technologists and security teams: The agencies recommend comprehensive detection and mitigation measures, subtle alteration of responses for suspected malicious distillation attempts, and correlation of activity across model providers, cloud platforms, and API aggregators to reveal distributed campaigns.
- Policymakers and regulators: The advisory frames the activity as not just commercial theft but a national-security concern, asserting that industrial-scale distillation "extract[s] restricted proprietary functionalities" and likely involved state complicity.
- Affected enterprises and procurement leaders: Arctic Wolf's Ismael Valenzuela, vice president of Labs, Threat Research and Intelligence, urged seeing the bulletin as abuse of legitimate access and warned that exposed API keys and service accounts make model access an attractive target — abuse that can appear legitimate and be hard to distinguish from normal traffic.
The bulletin the NSA, CISA, and FBI released paints a picture of systematic, distributed campaigns that fuse technical ingenuity with marketplace workarounds. It names firms, model families, dates, and specific extraction techniques — and it prescribes coordination and detection as the immediate response. Whether those prescriptions slow or stop the campaigns the agencies describe will depend on how effectively U.S. providers can detect obfuscated queries, coordinate signals across providers and clouds, and harden access without undermining legitimate research and commercial use.
https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html




