US agencies accuse Chinese AI firms of systematic model distillation

This digest was compiled by AI from multiple sources — links to the originals are below.
The NSA, CISA, and FBI issued a joint advisory accusing Chinese AI companies of systematic, industrial-scale distillation of US frontier AI models. The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as having spent billions of tokens across millions of exchanges since late 2024. The agencies say the practice is tacitly encouraged by Beijing but not directly directed by political leaders.
Key Facts
- The joint advisory from NSA, CISA, and FBI states that distillation is a critical part of China's AI industrial policy.
- Chinese companies named in the advisory include DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
- The companies spent billions of tokens across millions of exchanges with US models like Anthropic's Claude, OpenAI's ChatGPT, Google Gemini, and xAI's Grok since at least late 2024.
- DeepSeek distilled four versions of Claude, two versions of Gemini, five versions of ChatGPT, and Grok 4 to generate synthetic training data for its R1 and R3 models.
- Moonshot AI allegedly distilled 18 different US models, including Anthropic's Fable 5, to train its Kimi-K2 and Kimi K3 models.
The Joint Advisory
The National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI issued a joint cybersecurity advisory on the systematic extraction of proprietary functionalities from US AI models. The advisory states that China-based AI companies are conducting industrial-scale knowledge distillation campaigns that form the core of their AI development strategy. The agencies wrote that the campaigns are 'not merely a supplement' but central to China's AI industrial policy. The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as companies involved in these efforts.
Distillation Tactics
Chinese AI companies routed requests and prompts through multiple pathways to avoid detection, according to the advisory. Common tactics included spreading requests across different accounts, models, and platforms, and using native APIs, remote cloud providers, and third-party aggregators to obfuscate user metadata. The companies also leveraged proxies and gray tech markets to circumvent geographic restrictions, terms of use, and safeguards built into frontier models. The advisory calls for a coordinated response across the AI ecosystem, including effective information-sharing spanning the US government and private sector.