US agencies say Chinese AI firms steal capabilities from OpenAI, Anthropic, and others through massive distillation campaigns

US agencies name Alibaba, DeepSeek, and four other Chinese AI firms in an industrial-scale campaign that extracted billions of tokens from Claude, GPT, Gemini, and Grok to slash development costs.

Categorized in: AI News Government
Published on: Sep 10, 2026
US agencies say Chinese AI firms steal capabilities from OpenAI, Anthropic, and others through massive distillation campaigns

US agencies name Chinese AI firms in industrial-scale model extraction campaign

The FBI, NSA, and CISA published a joint advisory on Sept. 8 accusing Chinese AI companies of extracting billions of tokens from leading US frontier models - including Claude, GPT, Gemini, and Grok - to cut their own development costs. The advisory names Alibaba, DeepSeek, MiniMax, Moonshot AI, StepFun, and Z.AI as participants in what the agencies call "industrial-scale" distillation efforts dating back to at least late 2024.

The alleged activity violates terms of service on US platforms and uses evasive techniques to avoid detection. For government professionals tracking AI security threats, the advisory marks a formal escalation in how US agencies are framing economic espionage against American AI infrastructure.

How the distillation operation worked

Distillation is a standard machine learning technique where a mature "teacher" model trains a smaller "student" model. It is widely used in academic research and for improving model efficiency. What separates this case, according to the advisory, is the scale, the deliberate extraction of proprietary capabilities, and the methods used to hide the activity.

The agencies described "advanced industrial-scale distillation tactics" that include chain-of-thought reasoning extraction, automated failover between pathways when blocked, and quality evaluation frameworks designed to detect defensive countermeasures. Chinese firms allegedly obtained bulk premium subscriptions to US AI services and shared them across developer teams to reduce costs.

To evade detection, the firms routed requests through native APIs, remote cloud providers, and third-party aggregators that obfuscate user metadata. They also used "transfer stations" - a gray market of proxies built specifically to bypass geographic restrictions on US AI models. This is a core concern for anyone working in Generative AI and LLM security, where API abuse patterns are becoming a distinct threat category.

Specific claims against DeepSeek and Moonshot AI

The advisory singles out DeepSeek for running an organized distillation campaign against US frontier models since late 2024, using the outputs to generate synthetic training data. CISA said DeepSeek "targeted specific knowledge domains to extract proprietary functionality and reasoning capabilities to reduce their compute and research costs."

The agencies also challenged DeepSeek's public claim that its model cost $5.6 million to train. "DeepSeek's publicly quoted training costs of $5.6M are misleading as it does not include the true cost of the data acquired through extensive malicious distillation," the advisory said.

Moonshot AI allegedly extracted Claude data to train its Kimi-K3 model and GPT-4o data for its Kimi-K2 model. Both firms are accused of pulling from Anthropic, OpenAI, Google, and xAI systems as part of the campaign.

What US AI companies should do

The authoring agencies recommend that AI companies implement detection and mitigation measures for anomalous behavior, share threat intelligence across the industry, and tune responses to suspected malicious attempts so extracted outputs lose their value.

Ismael Valenzuela, vice president of labs, threat research and intelligence at Arctic Wolf, said model extraction and distillation "should be treated as a security event category" rather than API abuse or an intellectual property dispute. He urged organizations to monitor AI API access patterns around the clock for automation at scale, prompt harvesting, and distributed account creation. "Organizations should work with model providers to share telemetry and indicators, rather than treating detection as something each organization has to solve alone," Valenzuela said.

Why this matters for government professionals

This advisory signals that US agencies now treat AI model extraction as a national security issue, not just a commercial dispute. For procurement officers, security teams, and policy staff working on AI for Government, the takeaway is practical: review API access controls on any US frontier model your agency uses, audit for anomalous query patterns, and treat distillation attempts as a reportable security event rather than routine API abuse. The named companies are already on US government watchlists, and the advisory provides a framework your security teams can use to justify stricter monitoring budgets.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)