US Agencies Warn of Chinese AI Distillation Campaigns

NSA, CISA, and FBI say Chinese AI firms, including DeepSeek and Alibaba, have extracted billions of tokens from US frontier models dating back at least to late 2024.

Sep 8, 2026
4 min read
Technobezz
US Agencies Warn of Chinese AI Distillation Campaigns

Don't Miss the Good Stuff

Get tech news that matters delivered weekly. Join 50,000+ readers.

The National Security Agency, Cybersecurity and Infrastructure Security Agency, and FBI jointly warned that China-based AI companies have been conducting industrial-scale knowledge distillation campaigns against US frontier AI models since at least late 2024, extracting billions of tokens across millions of requests. The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as conducting these campaigns, which the agencies say form the core of their AI development strategy rather than a supplement.

The agencies say the companies targeted models including variants of Claude, GPT, Gemini, and Grok, routing requests through native APIs, remote cloud providers, and third-party aggregators for unauthorized access, in breach of provider terms of use. They also describe a gray market of proxies called "transfer stations" used to bypass geographic restrictions and evade safeguards. DeepSeek, for example, is said to have distilled data from models such as Claude 3.7, GPT-4o, and Gemini 2.5 Pro Preview to train its R1 and V3 models, with the advisory noting that DeepSeek's publicly quoted training cost of $5.6 million is misleading because it excludes data acquired through distillation.

Moonshot AI reportedly took data from Claude Fable 5 for its Kimi-K3 model and from GPT-4o for its Kimi-K2 model, while Alibaba, MiniMax, StepFun, and Z.AI are each described as leveraging distillation for their own models. The advisory says these efforts are "likely with Chinese government awareness" and that they shorten development timelines and reduce costs for the Chinese firms.

The authoring agencies recommend US AI companies take three immediate actions: implement detection and mitigation for anomalous prompts and accounts, subtly alter responses to suspected distillation attempts, and establish cross-organization intelligence sharing to correlate activity across providers. The advisory frames the campaigns as a threat to US technological leadership and calls for a coordinated response across government, industry, and allied nations.

The warning arrives as US agencies have also been issuing alerts on other security fronts, including a separate advisory about hard-coded credentials in CareCam Pro IP cameras. The distillation advisory does not specify what actions, if any, the US government plans to take against the named companies.

Share