# Washington accuses six Chinese companies of plundering American AI

> A joint advisory from the NSA, FBI and CISA details massive distillation campaigns targeting Claude, GPT, Gemini and Grok since late 2024.

Canonical: https://ntilia.com/u/aidesk/en/washington-accuses-six-chinese-companies-of-plundering-american-ai
Language: en
Author: The AI Desk (https://ntilia.com/u/aidesk)
Published: 2026-09-10T08:57:52.517+00:00
Last updated: 2026-09-10T09:05:35.483+00:00
Tags: industrial-scale AI distillation, China, DeepSeek, NSA FBI CISA, Alibaba Qwen, Moonshot AI, national security, American AI models

---

On **September 8, 2026**, the **National Security Agency (NSA)**, the **Federal Bureau of Investigation (FBI)** and the **Cybersecurity and Infrastructure Security Agency (CISA)** published joint cybersecurity advisory **AA26-251a**. The document states that six Chinese artificial intelligence companies — **DeepSeek**, **Moonshot AI**, **Alibaba**, **MiniMax**, **StepFun** and **Z.AI** — have been conducting **industrial-scale AI distillation campaigns from China** against American frontier models since at least late 2024, notably variants of **Claude**, **GPT**, **Gemini** and **Grok**. According to the agencies, this systematic extraction constitutes the "core," not merely a complement, of these actors' development strategy.

Knowledge distillation, as recalled in the advisory, is a recognized machine learning technique. It involves training a less capable model from the outputs of a more powerful model. The authors emphasize that it becomes "aggressive, malicious and targeted" when it targets, at very large scale, restricted proprietary features, in violation of the terms of service of American providers. The public accusation, more detailed than earlier warnings from the spring, now places **industrial-scale AI distillation from China** at the center of the Washington–Beijing technological standoff, less than three weeks before an expected meeting between Donald Trump and Xi Jinping on **September 24**.

## What advisory AA26-251a says about industrial-scale AI distillation from China

The agencies estimate that the six companies extracted "billions of tokens" through "millions of exchanges or queries." They write that the Chinese government is "likely" aware of this. DeepSeek is presented as a structured actor since late 2024, with campaigns targeting reasoning capabilities, specialized optimizations and business functions to train notably **R1** and **V3**. The advisory considers the often-cited public training costs (around **$5.6 million** for DeepSeek-V3) to be misleading, as they would not include the actual cost of data obtained through distillation.

Moonshot AI is accused of having, since at least mid-2025, distilled Claude and GPT data for **Kimi** models, with an emphasis on supervised fine-tuning, reinforcement learning, software engineering and mathematics. Alibaba allegedly improved the **Qwen** family through industrial-scale distillation, including for software engineering skills, customer dialogue and image or character creation. MiniMax, StepFun and Z.AI appear in the same picture, targeting Claude and GPT for chain-of-thought reasoning, code and agentic functions. Ars Technica and The Register, which analyzed the text on Tuesday and Wednesday, highlight the shift in tone. This is no longer just accusations from private companies, but a document from national security agencies.

The access routes described go beyond simple API abuse. The advisory mentions native interfaces, remote cloud providers and third-party aggregators that obscure metadata. A gray market of proxies, dubbed **"transfer stations,"** would be used to circumvent geographic restrictions, break traceability and resell access at a fraction of the official price. The campaigns also reportedly rely on bulk purchases of premium subscriptions shared among teams, on prompt injections to force the revelation of internal reasoning (chain-of-thought), and on quality control pipelines capable of detecting when a provider deliberately degrades its responses.

## How the campaigns operate according to Washington

Operationally, the agencies describe pools of fraudulent accounts, highly coordinated queries with identical or near-identical prompt texts, and volumes ranging from thousands to millions of queries on similar themes. DeepSeek reportedly asked models to "imagine and articulate" the internal reasoning behind an already-produced response, step by step. MiniMax allegedly redirected its exchanges to a new Claude within **24 hours** of a release, a sign of prepositioned infrastructure. Moonshot AI reportedly multiplied millions of exchanges on agentic reasoning, tool use, data analysis and vision.

Three detection signals are highlighted for American labs. First, accounts shared across numerous IP addresses or user agents, with 24-hour usage showing no human variation. Second, abnormal subscription-to-usage ratios, and new accounts that immediately saturate limits rather than ramping up gradually. Third, behavioral patterns correlated across multiple paths (native API, cloud, aggregators), which reveal a single orchestration rather than isolated anomalies. The advisory maps these tactics to the **MITRE ATLAS** framework and adds "TTPs" deemed new, including automated metadata sanitization and systematic optimization of quotas and costs.

The recommended mitigations go beyond simple rate limiting. Washington calls for detecting abnormal prompts, accounts, networks and behaviors; **subtly altering** responses to suspected campaigns (less deep reasoning, different phrasing for correct information, discreet switching to a lower-tier model) without alerting the attacker; and sharing indicators among model providers, cloud platforms and aggregators. The agencies acknowledge the risk to legitimate users. A silent switch to a less capable model, or the addition of noise, can frustrate an ordinary customer as much as a distiller. However, they call for informing security researchers and third-party evaluators of the changes, while maintaining strong safeguards.

## What Beijing responds and what industrial-scale AI distillation from China changes

As early as **September 9**, the Chinese Ministry of Foreign Affairs rejected the accusations. Spokesperson **Mao Ning** stated that AI development in China results from "high-level scientific and technological autonomy," called on the United States to stop "baseless accusations," and advocated for cooperation between the two major AI powers. Xinhua, China Daily and several dispatches picked up by ABC News / AP relayed this framing. The Chinese Ministry of Commerce, for its part, described the American advisory as the politicization of a technical and commercial practice, an instrument of technological monopoly, and mentioned countermeasures if Washington used the pretext of distillation to contain Chinese companies. Beijing also points out that American companies distill open-source Chinese models, a double-standard argument already present in official press coverage.

For readers searching for **industrial-scale AI distillation from China**, the essentials are as follows. **What**: a joint NSA–FBI–CISA advisory accuses six Chinese labs of systematically extracting capabilities from Claude, GPT, Gemini and Grok via APIs, proxies and premium subscriptions. **Who**: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI on the accused side; Mao Ning and the Ministry of Commerce on the Chinese response side; American providers called on to detect, discreetly degrade and share indicators. **When**: advisory published on September 8, 2026, Chinese diplomatic response on the 9th, coverage by Ars Technica, The Register and Caixin Global shortly after. **What it changes**: the battle no longer concerns only chips or export controls, but inference traffic itself — who can query a frontier model, at what volume, and whether a lab can still claim "cheap" training without counting the hidden cost of tokens extracted from a competitor.

The issue also arises as China's Ministry of Industry and Information Technology announces plans to sharply increase intelligent computing capacity over five years, notes the South China Morning Post as cited by Ars Technica. Between American defense of frontier models, Chinese diplomatic retaliation and the Trump–Xi timeline, **industrial-scale AI distillation from China** is becoming a credibility test both for API terms of service and for technological diplomacy. The coming weeks will show whether American labs actually implement the recommended silent switches, and whether Beijing turns its rhetorical counterattack into concrete measures.

## Sources

- [CISA — China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies (AA26-251a)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a), September 8, 2026
- [CISA — Announcement of the joint NSA / FBI / CISA advisory](https://www.cisa.gov/news-events/news/cisa-nsa-and-fbi-warn-china-based-ai-companies-targeting-us-ai-models-industrial-scale-knowledge), September 8, 2026
- [Ars Technica — Six Chinese AI firms accused of aggressively copying US frontier models](https://arstechnica.com/tech-policy/2026/09/six-chinese-ai-firms-accused-of-aggressively-copying-us-frontier-models/), September 9, 2026
- [The Register — US claims Chinese AI companies' core AI strategy is distilling American models](https://www.theregister.com/ai-and-ml/2026/09/09/us-claims-chinese-ai-companies-core-ai-strategy-is-distilling-american-models/5295171), September 9, 2026
- [Caixin Global — In Depth: AI Distillation in China Leaves U.S. Tech Giants at Odds](https://www.caixinglobal.com/2026-09-10/in-depth-ai-distillation-in-china-leaves-us-tech-giants-at-odds-102483506.html), September 10, 2026
- [Xinhua — Spokesperson dismisses accusations that Chinese AI firms "copy" U.S. technologies](http://english.news.cn/20260909/33f7c8017a7a421aa8d837323ade07aa/c.html), September 9, 2026
- [ABC News / AP — China hits back at US claims of 'malicious' AI distillation ahead of planned talks](https://abcnews.com/Technology/wireStory/china-hits-back-us-claims-malicious-ai-distillation-136296225), September 9, 2026

<!-- ntilia:faq -->
## Frequently asked questions

### Which Chinese companies are targeted by the American advisory AA26-251a?

The joint NSA-FBI-CISA advisory targets six Chinese artificial intelligence companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It accuses them of conducting distillation campaigns against American frontier models since at least late 2024.

### What is the knowledge distillation these companies are accused of?

Knowledge distillation is a recognized machine learning technique that involves training a less capable model from the outputs of a more powerful model. The advisory deems it "aggressive, malicious and targeted" when it targets, at very large scale, restricted proprietary features, in violation of American providers' terms of service.

### Which American models were reportedly targeted by these campaigns?

According to American agencies, the campaigns targeted variants of Claude, GPT, Gemini and Grok. They estimate that the six companies extracted "billions of tokens" through "millions of exchanges or queries."

### Why does the advisory dispute the training costs claimed by DeepSeek?

The advisory considers the often-cited public training costs, around $5.6 million for DeepSeek-V3, to be misleading, as they would not include the actual cost of data obtained through distillation.

### What measures does Washington recommend to American model providers?

Washington calls for detecting abnormal prompts, accounts, networks and behaviors, subtly altering responses to suspected campaigns without alerting the attacker, and sharing indicators among model providers, cloud platforms and aggregators. The agencies acknowledge that these silent switches to a less capable model risk frustrating legitimate users as well.

### How did Beijing react to the American accusations?

As early as September 9, the Chinese Ministry of Foreign Affairs rejected the accusations, with spokesperson Mao Ning invoking "high-level scientific and technological autonomy" and calling for an end to "baseless accusations." The Ministry of Commerce described the advisory as the politicization of a technical practice and mentioned possible countermeasures.

### What detection signals do the agencies highlight?

Three signals are highlighted: accounts shared across numerous IP addresses or user agents with 24-hour usage showing no human variation, abnormal subscription-to-usage ratios with new accounts that immediately saturate limits, and correlated behavioral patterns across multiple access paths. The advisory maps these tactics to the MITRE ATLAS framework.

### In what diplomatic context does this advisory come?

The advisory was published on September 8, 2026, less than three weeks before an expected meeting between Donald Trump and Xi Jinping on September 24. It places industrial-scale distillation at the center of the Washington-Beijing technological standoff, beyond mere questions of chips and export controls.
<!-- /ntilia:faq -->
