The National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI issued a joint advisory on September 8 and 9, 2026, accusing six China-based AI companies of running campaigns to copy America's leading AI models. The advisory, tracked as AA26-251A, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, and says the campaigns extracted billions of tokens across millions of queries sent to US systems since late 2024.
The agencies describe the activity as aggressive, malicious, and targeted. The targets are the four model families that anchor the American AI industry: Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok. According to the advisory, the six Chinese firms used the output of those models to train their own systems at a fraction of the cost it took to build the originals.
RelatedAnthropic Says It Never Asked to Ban Open-Weights Models
What exactly is AI distillation?
Distillation is a legitimate and widely used machine learning technique, not something invented for this story. It works by feeding a smaller model huge volumes of a larger model's outputs, then training that smaller model to imitate them. Instead of paying for years of research, curated data, and compute, a company doing distillation borrows the finished judgment of an existing model and repackages it. Training a frontier model from scratch can run into tens of millions of dollars in compute alone, so skipping that step is a shortcut with obvious economic appeal.
What separates ordinary distillation from what the advisory describes is scale and method. The agencies say the six companies relied on fraudulent accounts, bulk purchases of premium subscriptions, and proxy routing services, sometimes called transfer stations, to funnel queries through in ways that evaded detection and bypassed regional access restrictions placed on the US models.
Which companies and models are named?
The advisory lays out specific pairings between the accused firms and the model lineages they allegedly targeted. DeepSeek is accused of drawing on multiple versions of Claude, GPT, and Gemini to generate training data for its R1 and V3 models. Moonshot AI is accused of extracting data from Claude to train its Kimi K3 system, and of using GPT-4o output to help develop the earlier Kimi K2. Alibaba is accused of distilling Claude 4, Claude Opus, Claude Sonnet, and GPT-5 in late 2025. MiniMax, StepFun, and Z.AI are named as using distillation techniques as well, though the advisory does not break out specific model pairings for those three.
| Company | Alleged target models | Alleged use |
|---|---|---|
| DeepSeek | Claude, GPT, Gemini (multiple versions) | Training data for R1 and V3 |
| Moonshot AI | Claude, GPT-4o | Kimi K3 and Kimi K2 development |
| Alibaba | Claude 4, Claude Opus, Claude Sonnet, GPT-5 | Distillation in late 2025 |
| MiniMax | Not specified | Named distillation technique use |
| StepFun | Not specified | Named distillation technique use |
| Z.AI | Not specified | Named distillation technique use |
- Three agencies signed the advisory: NSA, CISA, and FBI.
- Six companies are named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
- Four US model families are described as targets: Claude, GPT, Gemini, and Grok.
- Extraction methods named include fraudulent accounts, bulk subscriptions, and proxy transfer stations.
Why does this matter for the AI race?
This advisory is a bigger deal than a similar-sounding episode from July 2026, when the US Treasury and White House sanctioned Moonshot AI specifically over Kimi K3 distillation. That was one company facing one enforcement action. This is three federal agencies formally naming six companies, four model families, and specific extraction techniques in a single cybersecurity advisory, which signals a broader assessment that the problem is industry-wide rather than a single bad actor.
If the allegations hold up, the economics matter as much as the security angle. Anthropic, OpenAI, Google, and xAI have each spent years and enormous sums on research, safety testing, and compute to build their frontier models. Distillation, done at the scale the advisory describes, lets a competitor skip most of that spending and arrive at a comparable product much faster and cheaper. That erodes the very moat that is supposed to justify the capital these US labs have raised, and it raises the stakes for Nvidia and other compute providers whose growth story depends partly on the idea that frontier model development requires massive, hard-to-replicate spending. None of this is investment advice, but it is a signal worth tracking for anyone following the AI sector.
RelatedOpenAI Cuts Off Cursor's Model Access After SpaceX Buyout
- Export and access controls. Whether Washington pairs this advisory with new restrictions on the six named companies.
- Platform defenses. Whether Anthropic, OpenAI, Google, and xAI tighten rate limits, account verification, or output watermarking in response.
- Compute demand narratives. Whether evidence of large-scale distillation changes how investors read growth assumptions tied to frontier model training.
- Further enforcement. Whether other governments or agencies issue matching advisories against the same six firms.
What happens next?
The advisory itself is not an enforcement action. It does not impose fines, sanctions, or trade restrictions on its own. What it does is put an official, three-agency name to a pattern that AI labs have alleged informally for years, and it gives the US government a documented basis to pursue further action if it chooses to. Given that the July 2026 sanctions against Moonshot AI already showed a willingness to act on a single case, a formal advisory naming five additional companies raises the odds of follow-up steps, whether that means expanded sanctions, tighter export controls, or diplomatic pressure tied to trade talks.
For now, the named companies have not issued detailed public responses matching the specifics in the advisory, and the agencies have not published the underlying evidence beyond the summary claims. Readers should expect more reporting and likely pushback from the companies named as this story develops.
- OfficialCISA Advisory AA26-251A joint NSA/CISA/FBI cybersecurity advisory
- OfficialCISA news release agency summary of the advisory
- CoverageEngadget summary and context
- CoverageCyberScoop additional reporting on the advisory
This report draws on the joint NSA, CISA, and FBI advisory and independent coverage of its release, compiled by GenZTech Team.
