US Warns of Industrial-Scale AI Model Distillation by Chinese Companies
CISA, NSA and the FBI say six Chinese companies obtained outputs from US AI models on a large scale. Beijing rejects the allegations as unfounded.

AI model distillation is the subject of a joint cybersecurity advisory issued by US agencies CISA, NSA and the FBI on September 8. They said six Chinese companies had allegedly obtained outputs from leading US generative models on a large scale since the end of 2024, with the goal of using them to develop their own systems.
The agencies named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. According to their assessment, the companies allegedly obtained billions of tokens through millions of interactions with the models. The activity allegedly involved variants of the Claude, GPT, Gemini and Grok models.
China’s Ministry of Foreign Affairs rejected the allegations as unfounded on September 9 and urged the United States to stop making them. Public, independent technical evidence confirming every specific case attributed to the individual companies is not currently available.
What AI Model Distillation Means
Knowledge distillation is a common machine-learning technique. A smaller or new model can learn from the behavior of a more capable model, for example by using its responses to a large number of questions. In the advisory, however, the US agencies describe alleged coordinated and concealed extraction of outputs from competing systems on an industrial scale.
According to CISA, the NSA and the FBI, such an approach could bypass the research costs, computing power and security restrictions associated with developing proprietary frontier models. The agencies claim that the named companies used a large number of interactions with US services to obtain outputs from which other models could learn.
This is an official allegation by US security agencies, not a publicly substantiated court ruling against the named companies. The assessment that the activities took place with the knowledge of the Chinese government is the position of the US agencies and is not publicly supported by a judicial finding.
Recommendations for AI Service Providers
The joint advisory is aimed primarily at model and API operators. It advises them to monitor accounts, networks and prompts that show signs of suspicious activity. Recommended measures also include modifying model responses when an attempt to extract its capabilities is suspected.
The agencies also urge companies to share indicators of compromise and other information about such activities. The goal is to make it easier to detect coordinated patterns that may not be apparent when monitoring a single account or service.
The warning moves the dispute over AI model training data and capability copying into the realm of national security. US providers may respond by tightening detection, account verification or access conditions for APIs. Such measures could also affect legitimate foreign users if their accounts or activity are assessed as risky.
What Is Not Yet Known
The published advisory does not provide publicly independent technical evidence for every alleged case and every named company. Responses from DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI to the specific claims will therefore be an important next signal.
It is also unconfirmed whether the United States will impose sanctions, restrict access to services or take other legal action following the warning. Attention will also focus on whether the operators of Claude, GPT, Gemini and Grok announce API changes, account restrictions or new protections against model extraction.
Sources
- CISA – Confirms the joint advisory, the named companies, the scope of the alleged activities and the recommended mitigations.
- Associated Press – Confirms the Chinese Ministry of Foreign Affairs’ rejection of the allegations and reports that several named companies did not immediately respond.
- Nextgov/FCW – Independently summarizes the joint warning and its technical recommendations.
Verified and updated: 09. 09. 2026 15:23



