AI Policy

U.S. agencies warn of industrial-scale AI distillation campaigns as China rejects the claims

The NSA, FBI and CISA issued a joint advisory accusing China-based AI companies of extracting capabilities from U.S. frontier models, while Beijing rejected the allegations and called for cooperation.

Published Updated
AI SecurityCISANSAChinaModel Distillation

A dispute over artificial intelligence model distillation moved into sharper public view this week after the U.S. National Security Agency, Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency issued a joint cybersecurity advisory on September 8, 2026. The advisory accused China-based AI companies of conducting industrial-scale campaigns to extract restricted capabilities from U.S. frontier models. One day later, China rejected the allegations, according to reporting from the Associated Press, and urged the United States to avoid what Beijing described as unfounded accusations.

The U.S. advisory focuses on knowledge distillation, a common machine learning technique in which a smaller or newer model is trained using outputs from a larger or more capable system. In ordinary research and product development, distillation can be legitimate, especially when it uses open models, licensed data or an organization's own systems. The agencies argue that the activity described in their advisory is different because it allegedly targeted proprietary frontier AI services at large scale, violated providers' terms of use and attempted to reduce the cost and time needed to develop competing models.

According to the NSA release and the CISA advisory, the agencies believe China-based companies extracted billions of tokens across millions of requests from U.S. models, including variants of Claude, GPT, Gemini and Grok, since at least late 2024. The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and says the campaigns used multiple providers, cloud platforms and infrastructure paths to avoid centralized detection. It also frames the issue as a national security concern, arguing that accelerated model development could strengthen cyber and military capabilities.

The Associated Press reported that China's Ministry of Foreign Affairs pushed back on Wednesday. Spokesperson Mao Ning said China's AI development is the result of technological self-reliance and called for AI progress that is open, inclusive and beneficial. AP also reported that DeepSeek, Alibaba, Moonshot AI and Z.AI did not immediately respond to requests for comment. The dispute comes as AI governance is expected to be part of planned talks between U.S. President Donald Trump and Chinese leader Xi Jinping later this month.

The controversy highlights a difficult boundary in the AI economy. Distillation is not automatically malicious. Developers often use model outputs to improve smaller systems, evaluate behavior or build task-specific assistants. But when a closed commercial model is queried at high volume to reproduce restricted capabilities, the legal, security and competitive questions become more serious. The U.S. agencies recommend coordinated defenses across model providers, cloud platforms, API aggregators and infrastructure companies, because a campaign spread across many accounts and services can be hard for any single provider to see.

For AI companies, the advisory is a reminder that model access is now part of security architecture. Rate limits, anomaly detection, account verification, provenance tracking and contractual enforcement are no longer only business controls; they shape how quickly frontier capabilities can be copied or approximated. For policymakers, the exchange shows how AI competition is becoming entangled with diplomacy, export controls and cybersecurity. The facts behind the U.S. claims will remain contested, but the issue itself is likely to stay central as frontier models become more capable and more strategically valuable.