NSA, FBI and CISA accuse six Chinese AI firms of large-scale distillation of U.S. models

NSA, FBI and CISA accuse six Chinese AI firms of large-scale distillation of U.S. models

N
News Editor
2026-09-09 09:15:36
The U.S. National Security Agency, Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency have issued a joint advisory, numbered AA26-251A, alleging that six Chinese AI companies carried out industrial-scale knowledge distillation against leading American models. The firms named in the notice are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The agencies said the activity began in late 2024 and involved billions of tokens extracted through millions of requests. The advisory says the targeted systems included multiple versions of Claude, GPT, Gemini and Grok. It also describes a range of alleged evasion methods, including gray-market API proxy services used to bypass geographic restrictions, bulk account creation with obfuscated identities, automated metadata cleaning at the infrastructure layer and coordinated switching between blocked pathways. At the same time, the document draws a distinction between legitimate distillation as a recognized AI research technique and what the agencies describe as aggressive, targeted extraction centered on restricted proprietary capabilities. The accusations have been disputed. Moonshot denied earlier allegations tied to Kimi K3, and independent researchers including Snorkel AI co-founder Braden Hancock and analyst Nathan Lambert questioned whether the timeline cited in that earlier dispute was technically plausible.

The National Security Agency, the Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency issued a joint cybersecurity advisory on Sept. 8 alleging that six Chinese AI companies engaged in industrial-scale knowledge distillation of leading U.S. models. The notice is identified as AA26-251A.

Six companies named, with activity traced back to late 2024

The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The three agencies said the companies extracted billions of tokens through millions of requests starting in late 2024.

The models described as targets span several U.S. providers. The advisory lists multiple versions of Claude, GPT, Gemini and Grok.

For StepFun, the document says the company distilled data from Claude Opus 4.1 and 4.5, Claude Sonnet 4.5, Claude Haiku 4.5, as well as GPT-5 Mini, GPT-5 Pro, GPT-5.1, GPT-5.1 Codex and GPT-5.2 between late 2025 and early 2026.

Advisory outlines alleged evasion methods

The advisory describes several methods it says were used to avoid restrictions. Those include gray-market API proxy services described as "relay stations" to get around geographic controls, mass account creation using obfuscated identity information, automated metadata scrubbing at the infrastructure layer and coordinated switching between blocked routes.

Agencies distinguish legitimate from malicious distillation

The document says knowledge distillation itself is a common training method. In practice, it involves sending a large volume of prompts to a more capable model, collecting the answers and then using those outputs to improve another model. The advisory explicitly says this is a recognized and legitimate technique in AI research.

The agencies say the dividing line is scale and intent. In their view, the conduct described in the advisory was aggressive, targeted and carried out at industrial scale, forming a core part of development strategy rather than a supplementary method, while deliberately focusing on restricted proprietary capabilities.

Guidance for U.S. companies

The advisory recommends that U.S. companies monitor subscription counts against usage ratios, change response behavior when distillation is suspected, including through differential privacy or model downgrades, and share behavioral indicators across organizations.

Moonshot rejects the claim, researchers challenge the timeline

The companies named have not accepted the allegations. One earlier flashpoint came on July 22, when White House Office of Science and Technology Policy Director Michael Kratsios accused Moonshot of distilling Anthropic's Fable 5 to build Kimi K3. Moonshot business lead Huang Zhenxin denied the claim at the time.

According to United Daily News, Huang said on July 21 that K3's progress came from original architectural innovation at the foundation layer rather than from distilling existing models.

Independent researchers also raised technical objections. Braden Hancock of Snorkel AI and analyst Nathan Lambert said only 15 days elapsed between the public release of Anthropic's model and the launch of Kimi K3. They argued that was not enough time to distill and train a 2.8 trillion-parameter model, making it implausible for that model to have served as the primary training source.

Scope widened from one company to six

This joint advisory expands the scope of the accusation from a single company to six, and stretches the timeline from late 2024 to mid-2026.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.