September 11, 2026 · CISA / NSA / FBI
NSA, FBI and CISA Name Six Chinese AI Companies for Industrial-Scale Distillation Campaigns Against US Models
My take: The joint advisory published September 8 by the NSA, FBI, and CISA surfaces something the AI sector had long suspected: that frontier model capabilities are not just a technological asset, but an active target for systematic extraction. The six companies named (DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI) ran industrial-scale distillation campaigns, sending billions of tokens across millions of queries against Claude, GPT, Gemini, and Grok to capture their behavior and replicate it in domestic models. The agencies indicated these operations were carried out with the probable knowledge of the Chinese government.
The most revealing data point is DeepSeek's: the agencies note that its publicly cited training cost of $5.6 million is misleading because it excludes the cost of data acquired through distillation. The widely celebrated "efficiency" of DeepSeek was, in part, financed by training work already done by US companies.
For those building products with AI, this has practical implications. The platforms you use to prototype and ship have clear incentives to monitor anomalous usage patterns, and the advisory recommends that AI companies deploy behavioral monitoring tools and coordinate threat intelligence with peer organizations. The question is what level of visibility your organization has over how it uses the AI APIs integrated into its products, and whether controls exist to detect whether your own developments are being replicated by others.
Want to use these tools? See the unbiased reviews or back to the news.