In brief

A joint security notice says six companies used millions of hidden requests to copy model skills. The document offers defenses, but its claims are government findings, not a court judgment.

New to this? Read it in simple words
  • US security agencies say six China-based AI companies copied skills from US frontier models. Their notice names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.
  • They say the companies used hidden accounts and millions of requests since late 2024.
  • One AI company may see only a small part of such a campaign. Shared warning signs can show one campaign across many services.
  • These are claims from US agencies. They have not been tested in court.
Words to know
Distillation
Training a smaller AI model using the answers of a stronger model.
Frontier model
One of the most advanced AI models available today.

What the agencies say happened

The NSA, FBI, CISA, and partners released a joint security notice. They say several companies tried to learn from outputs made by US frontier models. The notice names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.

The agencies call the method malicious distillation. Normal distillation can teach a smaller model from a stronger model with permission. The concern here is a hidden effort to avoid limits and copy useful behavior without permission.

The notice alleges billions of tokens across millions of requests since late 2024. It says traffic moved through many accounts, cloud services, providers, and brokers. These details come from the joint investigation and have not been tested in court.

Sources12

DEFENSE PATH 05
One service may see a normal request while several services see a campaign.

US agencies recommend stronger detection, focused responses, and careful information sharing. Their accusations remain government findings.

Unusual behavior can appear across services

One request may look normal. A much larger pattern can be different. Signals may include repeated questions about one skill, shared accounts, changing network addresses, and the same work spread across several providers.

This creates a hard balance. Providers want to stop abuse without blocking researchers, startups, or heavy business users. A warning sign should start a careful review. It should not become automatic proof of who sent the traffic.

The advisory says companies should share useful threat information. Shared signals can reveal one campaign across many services. That sharing also needs privacy limits, clear evidence rules, and safe handling of customer information.

Sources12

The response should protect evidence and users

The notice recommends stronger detection, focused changes to model responses, and wider information sharing. Providers can also rate-limit suspicious traffic and require stronger checks when a request pattern becomes risky.

A provider should keep enough records to explain a decision. Customers need a path to appeal if a normal use is blocked. Investigators also need to separate technical evidence from political claims about a company or country.

The advisory matters because one provider may see only a small piece of a campaign. The strongest defense combines several pieces while keeping uncertainty visible. Security improves when evidence is shared carefully, not when an allegation becomes a fact by repetition.

Sources12

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Primary source · September 8, 2026NSA and others warn China-based AI companies are distilling US frontier AI models US National Security Agency
  2. 2
    Primary source · September 8, 2026China-based AI companies conduct malicious distillation against US frontier AI models NSA, FBI, CISA and partners
How we checked this story

We used the official release and full joint advisory. We describe every accusation as a US government allegation because no court has decided it and we did not find timely independent proof before publication. We separate normal distillation from hidden abuse.