American AI companies may have spent years and billions building frontier models, but US officials say six Chinese firms found a faster route: asking those models questions at industrial scale.
The NSA, CISA and FBI on Tuesday accused DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of running large-scale knowledge-distillation campaigns against US frontier AI models since at least late 2024.
According to the advisory, the companies collectively extracted billions of tokens through millions of requests involving models from Anthropic, OpenAI, Google and xAI. They said the activity was conducted “likely with Chinese government awareness,” but did not allege that Chinese intelligence agencies directly participated.
“China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale,” US officials said.
Distillation itself is a legitimate AI technique. It allows a smaller model to learn from the outputs of a more capable system. The US allegation centers instead on how the technique was allegedly used — including massive volumes of requests, account pools, proxy services and attempts to bypass geographic and usage restrictions.
How the alleged campaigns worked
The advisory says DeepSeek conducted organized extraction campaigns targeting reasoning, specialized functions and other capabilities used to develop its R1 and V3 models.
Moonshot AI allegedly used multiple US models to improve its Kimi systems. The advisory separately accused Alibaba of targeting software engineering, customer-service and agentic capabilities; MiniMax of extracting reasoning and software-development capabilities; StepFun of targeting coding and agentic functions; and Z.AI of extracting chain-of-thought reasoning data.
The agencies also described infrastructure designed to make the activity harder to detect. Companies allegedly used “transfer stations,” or gray-market proxy services, to route requests through different pathways and obscure their origins. Other warning signs included accounts shared across multiple IP addresses, continuous 24-hour usage and new subscriptions immediately consuming maximum quotas.
The defensive move that could change AI services
One of the advisory’s most unusual recommendations is for AI companies to alter responses sent to suspected distillation operations. Providers could reduce reasoning depth, change how correct answers are reached or move suspicious users to less capable models without notifying them.
Such defenses could affect legitimate users if detection systems produce false positives. The agencies therefore recommend altering responses only during confirmed malicious campaigns, supported by stronger identity checks, behavioral monitoring and information sharing among model providers, cloud companies and API aggregators.
The bigger AI race
The accusations matter because successful distillation could reduce the time and money required to develop competitive models. The US agencies said companies conducting these campaigns can achieve “significantly shorter AI development timelines and reduced financial expenditures” when training frontier systems.
That creates a difficult problem for US AI companies: protecting proprietary capabilities without making their products harder to use for legitimate customers.
The stakes also extend beyond corporate competition. US officials warned that capabilities obtained through the alleged activity could strengthen Chinese military and cyberattack capabilities.
China rejects the allegations
China has rejected the accusations. Its Foreign Ministry described the claims as lacking factual basis and legal grounding, while saying distillation is a widely used technical method.
“We hope the US will earnestly implement the important consensus reached by the leaders of both countries and refrain from making false accusations and smearing China,” Chinese Foreign Ministry spokesperson Mao Ning said, according to Reuters.
The dispute arrives ahead of a planned Sept. 24 meeting between President Donald Trump and Chinese President Xi Jinping, according to Reuters, adding another technology flashpoint to already strained US-China relations.
What enterprise AI customers should do
For enterprise AI customers, this dispute could affect more than geopolitics. Providers may introduce stricter identity checks, tighter account-sharing rules, lower usage limits or undisclosed model downgrades when they detect suspicious activity. That could create inconsistent outputs or service disruptions for organizations running legitimate high-volume workloads.
IT leaders should use dedicated enterprise accounts, prohibit shared credentials, establish normal API-usage baselines and ask vendors how suspected distillation activity affects model routing and response quality. They should also verify which underlying models power third-party AI services, particularly when those services handle sensitive data or business-critical workflows.