The National Security Agency, the Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency issued a joint cybersecurity advisory on Sept. 8 alleging that six Chinese AI companies engaged in industrial-scale knowledge distillation of leading U.S. models. The notice is identified as AA26-251A.
Six companies named, with activity traced back to late 2024
The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The three agencies said the companies extracted billions of tokens through millions of requests starting in late 2024.
The models described as targets span several U.S. providers. The advisory lists multiple versions of Claude, GPT, Gemini and Grok.
For StepFun, the document says the company distilled data from Claude Opus 4.1 and 4.5, Claude Sonnet 4.5, Claude Haiku 4.5, as well as GPT-5 Mini, GPT-5 Pro, GPT-5.1, GPT-5.1 Codex and GPT-5.2 between late 2025 and early 2026.
Advisory outlines alleged evasion methods
The advisory describes several methods it says were used to avoid restrictions. Those include gray-market API proxy services described as "relay stations" to get around geographic controls, mass account creation using obfuscated identity information, automated metadata scrubbing at the infrastructure layer and coordinated switching between blocked routes.
Agencies distinguish legitimate from malicious distillation
The document says knowledge distillation itself is a common training method. In practice, it involves sending a large volume of prompts to a more capable model, collecting the answers and then using those outputs to improve another model. The advisory explicitly says this is a recognized and legitimate technique in AI research.
The agencies say the dividing line is scale and intent. In their view, the conduct described in the advisory was aggressive, targeted and carried out at industrial scale, forming a core part of development strategy rather than a supplementary method, while deliberately focusing on restricted proprietary capabilities.
Guidance for U.S. companies
The advisory recommends that U.S. companies monitor subscription counts against usage ratios, change response behavior when distillation is suspected, including through differential privacy or model downgrades, and share behavioral indicators across organizations.
Moonshot rejects the claim, researchers challenge the timeline
The companies named have not accepted the allegations. One earlier flashpoint came on July 22, when White House Office of Science and Technology Policy Director Michael Kratsios accused Moonshot of distilling Anthropic's Fable 5 to build Kimi K3. Moonshot business lead Huang Zhenxin denied the claim at the time.
According to United Daily News, Huang said on July 21 that K3's progress came from original architectural innovation at the foundation layer rather than from distilling existing models.
Independent researchers also raised technical objections. Braden Hancock of Snorkel AI and analyst Nathan Lambert said only 15 days elapsed between the public release of Anthropic's model and the launch of Kimi K3. They argued that was not enough time to distill and train a 2.8 trillion-parameter model, making it implausible for that model to have served as the primary training source.
Scope widened from one company to six
This joint advisory expands the scope of the accusation from a single company to six, and stretches the timeline from late 2024 to mid-2026.

