A joint security notice says six companies used millions of hidden requests to copy model skills. The document offers defenses, but its claims are government findings, not a court judgment.
New to this? Read it in simple words
- US security agencies say six China-based AI companies copied skills from US frontier models. Their notice names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.
- They say the companies used hidden accounts and millions of requests since late 2024.
- One AI company may see only a small part of such a campaign. Shared warning signs can show one campaign across many services.
- These are claims from US agencies. They have not been tested in court.
- Distillation
- Training a smaller AI model using the answers of a stronger model.
- Frontier model
- One of the most advanced AI models available today.
What the agencies say happened
The NSA, FBI, CISA, and partners released a joint security notice. They say several companies tried to learn from outputs made by US frontier models. The notice names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
The agencies call the method malicious distillation. Normal distillation can teach a smaller model from a stronger model with permission. The concern here is a hidden effort to avoid limits and copy useful behavior without permission.
The notice alleges billions of tokens across millions of requests since late 2024. It says traffic moved through many accounts, cloud services, providers, and brokers. These details come from the joint investigation and have not been tested in court.
US agencies recommend stronger detection, focused responses, and careful information sharing. Their accusations remain government findings.
Unusual behavior can appear across services
One request may look normal. A much larger pattern can be different. Signals may include repeated questions about one skill, shared accounts, changing network addresses, and the same work spread across several providers.
This creates a hard balance. Providers want to stop abuse without blocking researchers, startups, or heavy business users. A warning sign should start a careful review. It should not become automatic proof of who sent the traffic.
The advisory says companies should share useful threat information. Shared signals can reveal one campaign across many services. That sharing also needs privacy limits, clear evidence rules, and safe handling of customer information.
The response should protect evidence and users
The notice recommends stronger detection, focused changes to model responses, and wider information sharing. Providers can also rate-limit suspicious traffic and require stronger checks when a request pattern becomes risky.
A provider should keep enough records to explain a decision. Customers need a path to appeal if a normal use is blocked. Investigators also need to separate technical evidence from political claims about a company or country.
The advisory matters because one provider may see only a small piece of a campaign. The strongest defense combines several pieces while keeping uncertainty visible. Security improves when evidence is shared carefully, not when an allegation becomes a fact by repetition.
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1Primary source · September 8, 2026NSA and others warn China-based AI companies are distilling US frontier AI models US National Security Agency
- 2Primary source · September 8, 2026China-based AI companies conduct malicious distillation against US frontier AI models NSA, FBI, CISA and partners
We used the official release and full joint advisory. We describe every accusation as a US government allegation because no court has decided it and we did not find timely independent proof before publication. We separate normal distillation from hidden abuse.