U.S. Agencies Name Six Chinese AI Companies in Landmark Distillation Advisory

Written by

in

U.S. intelligence agencies took an unprecedented step this week, publicly naming six Chinese artificial intelligence companies for systematically extracting proprietary capabilities from leading American AI models. The joint advisory, issued on September 8, 2026, by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI), describes what the agencies call “industrial-scale knowledge distillation campaigns” that have been ongoing since at least late 2024. The disclosure marks the first time the U.S. government has formally accused specific companies by name for AI intellectual property theft of this nature, representing a sharp escalation in the government’s response to AI security threats.

What Was Announced

The advisory, designated AA26-251A and published on the CISA website, names six Chinese companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. According to the agencies, these companies pulled billions of tokens across millions of queries from the frontier AI models of U.S. providers, specifically Anthropic’s Claude, OpenAI’s GPT series, Google’s Gemini, and xAI’s Grok. The agencies describe the distillation as “aggressive, malicious, and targeted” and assert that it forms “the core, not merely a supplement” of the named companies’ AI development strategies.

DeepSeek receives particular attention in the advisory. The agencies assert that DeepSeek specifically targeted reasoning capabilities, agentic functions, and specialized optimizations from models including GPT-4, GPT-5, and multiple Claude versions to train its R1 and V3 models. The advisory further states that DeepSeek’s publicly cited training cost of approximately $5.6 million is “misleading” because it excludes the significant cost of the data acquired through distillation campaigns.

The advisory also outlines a range of tactics the companies reportedly used to evade detection: spreading requests across different accounts, models, and platforms; using native APIs, remote cloud providers, and third-party aggregators to obscure user metadata; and leveraging proxies and gray tech markets to circumvent geographic restrictions, platform terms of service, and built-in AI safeguards.

Technical Details

Knowledge distillation, in its legitimate form, is a well-established machine learning technique in which a smaller “student” model is trained to replicate the behavior of a larger “teacher” model. When used without authorization against commercial AI systems, however, it becomes a method of extracting proprietary capabilities at scale. By querying frontier models with carefully crafted prompts and using the responses as training data, a company can effectively capture months or years of proprietary research and fine-tuning without the underlying computational expense.

The scale described in the advisory is notable. Billions of tokens across millions of queries suggests highly coordinated, automated pipelines designed to systematically probe the capabilities of target models. The agencies note that the use of rotating accounts and third-party aggregators made it difficult to attribute the activity to specific organizations in real time, as individual queries appeared to originate from legitimate users scattered across different geographic regions and access methods.

From a defensive standpoint, the advisory recommends that U.S. frontier AI companies take three specific actions: develop detection and mitigation strategies to identify malicious prompts and accounts attempting distillation; alter or degrade responses sent to accounts suspected of malicious activity; and build cross-industry networks to share intelligence on adversarial actors. These recommendations suggest that AI providers have some technical capability to detect distillation-style query patterns, even if attribution remains difficult.

Industry Impact and Reactions

The advisory arrives at a moment when the competitive dynamics of global AI development are under intense scrutiny. DeepSeek’s R1 and V3 models attracted widespread attention earlier in 2026 for their apparent performance relative to their reported training costs. The agencies’ assertion that those cost figures are materially incomplete reframes how the AI industry and investors should evaluate the competitiveness of Chinese AI firms — if the true cost of training includes the value of distilled data from U.S. systems, the economics look very different.

For Anthropic, OpenAI, Google, and xAI, the advisory validates concerns that have been discussed internally and in policy circles for some time. The commercial and reputational stakes are high: if frontier model capabilities can be systematically extracted at scale, the barriers to entry for competitive AI development become significantly lower, potentially eroding the research and capital investments that U.S. AI leaders have made over years. The government’s move to name specific companies publicly also signals that it views AI model IP in a similar light to other forms of protected trade secrets and national security assets.

The named Chinese companies have not publicly responded to the advisory as of this writing. The advisory does not announce sanctions or legal action against the companies, but it does create a public record that could inform future regulatory or legislative action, both in the United States and among allied governments watching closely.

What Comes Next

The advisory calls on U.S. AI providers to begin implementing detection and response capabilities, which suggests the government expects action from the private sector rather than relying solely on legal or diplomatic levers. Industry observers expect the major AI providers to accelerate work on behavioral anomaly detection systems capable of flagging distillation-style query patterns in real time. Cross-industry intelligence sharing — historically rare due to competitive sensitivities — may now gain traction given the explicit government recommendation and the shared threat.

On the policy side, the advisory is likely to fuel ongoing legislative discussions around AI export controls, access restrictions for foreign nationals to frontier AI systems, and potential requirements for AI providers to implement minimum security standards. Whether Congress moves quickly on such measures remains to be seen, but the formal public naming of specific companies by the NSA, CISA, and FBI substantially raises the political stakes and makes inaction more difficult to defend.

Conclusion

The joint advisory from the NSA, CISA, and FBI represents a watershed moment in the AI industry’s relationship with national security. By publicly naming six Chinese AI companies and providing specific technical detail on their alleged distillation tactics, the U.S. government has drawn a clear line around the intellectual property embedded in American frontier AI models. For AI developers, enterprises, and policymakers alike, the message is clear: the race to develop the most capable AI systems now has an explicit security dimension, and the rules of that race are being written in real time.

Stay updated on the latest AI news at Evolve Digital.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *