The National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI have alleged that six China-based AI companies conducted sustained, industrial-scale campaigns to extract capabilities from leading U.S. artificial-intelligence models. The joint cybersecurity advisory, released September 8, 2026, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and says the activity dates to at least late 2024. (media.defense.gov)

The agencies said the companies extracted billions of tokens across millions of exchanges or requests from variants of Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini and xAI’s Grok. These are U.S. government allegations, rather than findings independently established by public evidence. (media.defense.gov)

What the advisory alleges

The advisory marks an escalation in the way U.S. security agencies describe the risks surrounding access to frontier models. It frames the alleged extraction not simply as a commercial or research dispute over model outputs, but as a threat to technological competitiveness. The agencies’ focus is on what can be observed through products and services that provide model access, rather than on theft of a model’s weights or original training data. (nsa.gov)

Knowledge distillation is a recognized machine-learning technique in which a less capable “student” model learns from the outputs of a stronger “teacher” model. Used legitimately, it can help developers create smaller, cheaper or specialized systems. The distinction drawn by the advisory is the agencies’ allegation that the named companies used multiple accounts and proxy-routing services to evade restrictions, limits or detection. (media.defense.gov)

According to the advisory, the alleged campaigns used multiple accounts and proxy-routing services to evade restrictions, limits or detection. (media.defense.gov)

The public reporting does not independently establish the agencies’ allegations. China’s Commerce Ministry rejected the accusations as groundless, said distillation is commonly used by AI companies around the world and warned of countermeasures if the United States suppresses Chinese firms over the issue. Available reports did not include direct responses from the six companies. (apnews.com)

Recommended defenses for providers

For frontier-model providers, the practical significance of the advisory lies in its recommended defenses. The agencies urge companies to use behavioral monitoring and access controls. The guidance calls for measures aimed at suspected malicious distillation. (media.defense.gov)

The agencies also call for targeted response changes when a provider has identified a suspected malicious distillation effort. Reporting says providers should consider quietly modifying or downgrading outputs for users identified with high confidence as conducting malicious distillation, rather than only blocking them. (media.defense.gov)

The available reporting frames the practical response for frontier-model providers as behavioral monitoring, access controls and information-sharing. Any broad effect on ordinary customers’ API pricing, limits or availability remains speculative. (media.defense.gov)

Information-sharing and the broader question

The call for information-sharing is equally central. The advisory says a campaign can be distributed across model providers, cloud platforms, aggregators and infrastructure providers specifically to avoid single-point detection. In the agencies’ view, correlating activity across those organizations may help identify a common operator or method that may not be visible in one company’s logs alone. That could increase pressure on AI-service providers and intermediaries to treat account provenance, routing and coordinated usage as shared security concerns. (nsa.gov)

The joint advisory sets out the U.S. government’s threat assessment and its preferred defensive posture for AI providers. The broader question is whether providers can apply the recommended controls precisely enough to disrupt alleged industrial-scale extraction while preserving predictable access for legitimate users and avoiding opaque differences in service quality.