Tuesday, September 8, 2026

News

US Accuses Six Chinese Firms of Mass AI Model Theft

PolicyPatryk Raba

NSA, FBI and CISA have published a joint advisory on distillation campaigns in which Chinese AI firms systematically extracted the capabilities of Claude, GPT, Gemini and Grok models. Named entities include DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.

Contents
  1. What the agencies found
  2. Six named companies
  3. Recommendations for AI companies
  4. Consequences and open questions

Three US security agencies published a joint advisory on September 8, naming six Chinese companies as responsible for a years-long, industrial-scale campaign to extract the capabilities of American artificial intelligence models.

What the agencies found

The document describes a mechanism known as model distillation, a technique in which a weaker system learns from responses generated by a far more powerful model. In the hands of legitimate researchers, it's a standard method for cutting training costs. According to the NSA, FBI and CISA, however, Chinese firms turned it into an organized operation for extracting intellectual property, circumventing regional blocks and the security rules of American providers.

The agencies state outright that while distillation itself is a recognized, legitimate research technique, the campaigns they describe are malicious and systemic in nature. The scale isn't limited to isolated incidents - queries are counted in billions of tokens, and the operations themselves stretch from single days to many months of continuous activity against a single domain.

Six named companies

The list of entities includes DeepSeek, Moonshot AI (Beijing Moonshot Technology), Alibaba Group, MiniMax (Shanghai MiniMax), StepFun (Shanghai Jieyue Xingchen Intelligence Technology) and Z.AI. This expands on earlier accusations made by the White House in April 2026, when Michael Kratsios, director of the Office of Science and Technology Policy, named only three companies - DeepSeek, Moonshot AI and MiniMax.

Anthropic had already reported in February that DeepSeek, Moonshot AI and MiniMax together generated more than 16 million exchanges with Claude using a network of roughly 24,000 fictitious accounts, circumventing the regional block on the model's access in China. MiniMax proved the most active, with over 13 million exchanges concentrated on agentic coding and tool orchestration.

While distillation is a recognized, legitimate technique in AI research, the campaigns described here constitute malicious, industrial-scale operations - NSA, FBI, CISA, joint advisory AA26-251A

Recommendations for AI companies

The agencies recommend that model providers deploy anomaly detection for traffic from suspicious accounts, subtly modify responses sent to accounts suspected of running distillation, and build mechanisms for sharing threat information across companies in the industry. It's a signal that Washington treats the protection of foundation models as a matter of national security, not merely a civil dispute between competing firms.

In practice, this marks a new level of formalization for a dispute that until now has played out mainly in press statements and individual analyses from companies like Anthropic and OpenAI. A joint advisory from three federal agencies elevates the matter to the status of an official national security document, complete with a concrete list of named companies and operational recommendations.

Consequences and open questions

Treasury Secretary Scott Bessent had previously signaled the possibility of subjecting Chinese open-source models to scrutiny over illegal use of American technology, pointing to possible sanctions restricting cooperation with Chinese AI firms and access to US cloud infrastructure. Enforcing such measures remains problematic, however, since open-source models, once released, are difficult to pull back from global circulation.

Some experts are tempering the tone of the accusations, noting that attributing Chinese successes solely to copying oversimplifies the picture - distillation has a relatively limited impact on building strong models, and virtually every lab, including American ones, uses it. For Polish companies and institutions using open Chinese models, such as DeepSeek or Kimi variants, the federal agencies' document signals that the provenance of these systems' training data will increasingly come under US export and regulatory scrutiny, which could affect the availability and licensing terms of these tools in Europe.

Share: