Back to News
Technology
Sep 9, 20260 views2 min read

NSA, CISA, and FBI Warn That Chinese AI Firms Are Systematically Extracting US Frontier Model Capabilities

The NSA, CISA, and FBI issued a joint advisory on September 8 warning that six Chinese AI companies, including DeepSeek and Moonshot AI, have been conducting large-scale knowledge distillation campaigns against U.S. frontier AI models since late 2024. The agencies say the activity is likely occurring with the awareness of the Chinese government.

NSA, CISA, and FBI Warn That Chinese AI Firms Are Systematically Extracting US Frontier Model Capabilities
Source:CISA

The National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI issued a joint advisory on September 8 warning that six China-based AI companies have been conducting large-scale knowledge distillation campaigns against U.S. frontier AI models since at least late 2024.

The advisory, designated AA26-251A, identifies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as the companies involved. The agencies say these firms have been systematically extracting proprietary capabilities from U.S. models, including reasoning, coding, and agentic functions, to accelerate their own development and reduce research costs.

Knowledge distillation is a standard machine learning technique in which a smaller model is trained to mimic the outputs of a larger one. The advisory says the Chinese firms are using it at industrial scale as a core development strategy rather than as a supplement to original research.

DeepSeek is accused of targeting models including Claude, Gemini, GPT-4 and GPT-5, and Grok to train its R1 and V3 models. Moonshot AI allegedly extracted data from Claude and GPT-4o to train its Kimi-K2 and Kimi-K3 models.

To evade detection, the companies reportedly use a gray market of API proxies to bypass geographic restrictions and terms of service. Requests are routed through multiple pathways to obscure their origin, and some actors use prompt injection techniques to extract internal reasoning from target models.

The agencies estimate the activity has occurred with the awareness of the Chinese government, though they stopped short of saying the government directed it.

The advisory recommends that U.S. AI companies monitor for anomalous usage patterns, deploy targeted countermeasures when distillation is suspected, and share intelligence across the industry.

The advisory is the most detailed public accounting to date of how Chinese AI firms have allegedly used U.S. models to close the capability gap.