
US security agencies accuse six Chinese AI firms of industrial-scale distillation
The NSA, CISA, and the FBI released a joint advisory naming six Chinese artificial intelligence companies that extracted data from American frontier models to build rival systems.
Government advisory names six Chinese developers
On 8 September 2026, three United States security agencies published a joint cybersecurity advisory accusing six Chinese artificial intelligence companies of conducting systematic, large-scale distillation campaigns against American frontier models since late 2024. The National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI in the joint document, titled "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies."
According to the advisory, the Chinese firms extracted billions of tokens across millions of requests from models created by Anthropic, OpenAI, Google, and xAI. The agencies stated that these operations occurred likely with Chinese government awareness, arguing that distillation represents the core foundation of how these companies develop AI rather than a minor supplement.
Targeted models and tactical methods
The advisory details specific campaigns directed at American systems, including variants of Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok. DeepSeek allegedly drew capabilities across all four platforms to build its R1 reasoning model. The document notes that DeepSeek's reported 5.6 million dollar training cost excludes the value of data acquired through distillation. Moonshot AI used data from Claude's Fable to build Kimi K3, and GPT-4o data for Kimi K2. Alibaba distilled Claude and GPT-5 in late 2025 to develop its Qwen models, while MiniMax targeted chain-of-thought and reinforcement learning data from Claude Code. StepFun extracted reasoning and coding capabilities between late 2025 and early 2026, and Z.AI extracted tokens from GPT-5.5 and Claude Opus through mid-2026.
- Chinese AI firms begin systematic distillation campaigns targeting Claude, GPT, Gemini, and Grok
- Moonshot AI extracts data from Claude and GPT for its Kimi model family
- Alibaba targets Claude and GPT-5 for Qwen development as StepFun begins extracting coding capabilities
- Z.AI extracts tokens from GPT-5.5 and Claude Opus
- China Ministry of Commerce rejects distillation claims following comments by US official Michael Kratsios
- NSA, CISA, and FBI issue joint advisory naming six Chinese AI companies
To bypass platform defences and terms of service, the firms disguised traffic through fraudulent accounts, cloud providers, and third-party aggregators that strip identifying metadata. The operations also utilized grey-market API proxies known as transfer stations to circumvent geographic restrictions. Operators deployed jailbreak prompts designed to force models to narrate the reasoning behind their answers, exposing internal chain-of-thought pathways.
Diplomatic context and industry reactions
The joint warning preceded planned bilateral discussions between Washington and Beijing. United States Treasury Secretary Scott Bessent is scheduled to meet Chinese officials later in September 2026 to discuss AI security, alongside a planned meeting between President Donald Trump and Chinese President Xi Jinping at the White House.
American AI developers previously lodged similar complaints. Anthropic accused DeepSeek, Moonshot, and MiniMax of unauthorized distillation earlier in 2026, while OpenAI previously investigated DeepSeek and banned associated accounts. In cross-examination during his lawsuit against OpenAI, Elon Musk stated that xAI used OpenAI outputs to train its models. In July 2026, China's Ministry of Commerce rejected distillation allegations, accusing American firms of training models on Chinese data.


