NSA, FBI, and CISA Named Six Chinese AI Labs for Industrial-Scale Distillation of US Models

A joint advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as extracting billions of tokens from Anthropic, OpenAI, Google, and xAI models since late 2024, likely with Chinese government awareness. It recommends US labs subtly alter responses to suspected distillers.

NSA, FBI, and CISA Named Six Chinese AI Labs for Industrial-Scale Distillation of US Models

The NSA, FBI, and CISA released a joint advisory on September 8 titled China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies, per CISA. It names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, and assesses that they extracted billions of tokens across millions of requests from Anthropic, OpenAI, Google, and xAI models since at least late 2024, likely with Chinese government awareness. Distillation means training a cheaper model on the outputs of a stronger one, and the agencies argue it sits at the core of how these companies build rather than supplementing their own research. The target lists run to specific versions, with Z.AI accused of going after GPT-5.5 and Claude Opus 4.8.

Moonshot's inclusion bears on coverage we have run. The advisory says it pulled Claude and GPT outputs into its Kimi models. When we covered Kimi K3 in July as the largest open-weight model yet and a genuine rival to the US labs, the benchmark parity was the story. The advisory is a government assessment rather than a court finding, and no charges accompany it, but it is a direct allegation about how that parity was reached, and it lands while Moonshot is raising in Hong Kong ahead of a listing.

The evasion methods describe an adversary using the same plumbing legitimate developers use. Requests were routed through native APIs, cloud platforms, and third-party aggregators that strip user metadata. A gray market of proxies known as transfer stations defeated geographic restrictions. Pools of fraudulent accounts shared bulk-purchased premium subscriptions, and automated failover switched pathways whenever one was blocked.

The recommendations are where this reaches ordinary customers. The agencies tell US labs to detect anomalous prompts, accounts, networks, and behaviors, to share intelligence across providers, and to subtly alter responses to suspected distillation attempts. That last item means deliberately degraded outputs served to traffic a classifier flags, and classifiers misfire. Aggregators are named as a primary pathway, so companies reaching frontier models through them are the likeliest to meet tighter verification, cross-provider flags, and responses quietly worse than what a direct customer receives, with no notice that anything changed.

The advisory turns distillation into a national-security matter and endorses altered outputs as a countermeasure. If your production traffic reaches frontier models through an aggregator or proxy, move it to direct, verified accounts and add output-quality monitoring that would catch a silent downgrade.