A joint NSA, CISA, and FBI advisory claims DeepSeek, Moonshot AI, Alibaba and others systematically extract proprietary reasoning and features from Claude, GPT, Gemini and Grok models. Critics note the strongly worded accusations arrive amid intensifying U.S.-China technology rivalry.


Washington has formally accused several leading Chinese artificial-intelligence companies of conducting coordinated, industrial-scale “knowledge distillation” campaigns that extract restricted capabilities from U.S. frontier models. The September 8, 2026 joint Cybersecurity Advisory from the National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation portrays the practice not as ordinary research but as the core strategy of firms including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.

According to the advisory, since at least late 2024 these companies have pulled billions of tokens across millions of queries from models developed by Anthropic, OpenAI, Google and xAI. DeepSeek alone is said to have targeted Claude 3.7 through Opus 4.1, multiple Gemini and GPT variants, and Grok 4 to train its R1 and V3 models. The extracted material allegedly includes chain-of-thought reasoning, agentic functions, legal specialization, software-engineering skills and supervised fine-tuning techniques.

The agencies map the activity to the MITRE ATLAS framework and describe novel tactics: gray-market “transfer stations” that bypass geographic restrictions, bulk procurement of shared premium subscriptions, automated metadata sanitization, centralized routing across native APIs, cloud providers and third-party aggregators, and sophisticated quality-evaluation pipelines that detect defensive degradation. MiniMax is accused of prompt-injection attempts designed to make Claude Code believe it was a MiniMax product. Campaigns are portrayed as deliberate, high-volume and optimized for cost, with operations distributed to avoid single-point detection.

U.S. officials argue the practice shortens Chinese development timelines and undercuts American technological leadership while violating terms of service. Publicly cited training costs for DeepSeek’s models, they contend, omit the true expense of the distilled data. Recommended countermeasures include behavioral monitoring of subscription-to-usage ratios, subtle response alteration for suspected distillation traffic, and cross-organization intelligence sharing among model providers, cloud platforms and aggregators.

The advisory’s language is unusually direct. It repeatedly labels the activity “malicious,” asserts Chinese government “awareness,” and frames the campaigns as a strategic economic threat. These characterizations invite scrutiny. Knowledge distillation itself is a long-standing, legitimate technique in machine learning; the boundary between aggressive competitive research and illicit extraction is drawn here by U.S. national-security agencies whose institutional missions emphasize technological competition with China. Attribution relies on patterns of volume, timing and infrastructure rather than publicly detailed forensic evidence of individual accounts. Claims of government knowledge remain qualified by the word “likely.”

Independent observers note that American firms have themselves used large-scale data collection and synthetic-data generation. The advisory cites private-sector reports from Anthropic and Google on distillation risks, yet those documents focus more on technical detection than on geopolitical attribution. The timing—mid-2026, following earlier White House memoranda on adversarial distillation—aligns with broader efforts to restrict Chinese access to advanced U.S. AI systems.

Whether the described practices constitute systematic intellectual-property theft or intense but conventional competitive intelligence remains contested. What is clear is that U.S. model providers face sophisticated, adaptive demand for their most valuable outputs, and that national-security agencies now treat the resulting capability transfer as a matter of strategic concern. The recommended technical and organizational defenses will test how effectively the AI industry can distinguish legitimate high-volume research from coordinated extraction campaigns.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner