NSA, CISA, FBI: China AI Firms Stole US Model IP
The National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation released a joint cybersecurity advisory on September 8, 2026, warning that China-based artificial intelligence companies are systematically extracting proprietary capabilities from U.S. frontier AI models through industrial-scale knowledge distillation campaigns running since at least late 2024. The agencies stated that, likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges and requests from U.S. frontier models, including variants of Claude, GPT, Gemini, and Grok. In the advisory, designated AA26-251A, the agencies state that these campaigns “form the core—not merely a supplement” of the companies’ AI development strategy.

Specific Distillation Activities by Company
The joint advisory detailed specific examples of how each of the six named companies allegedly conducted these distillation operations. DeepSeek is accused of conducting organized distillation campaigns involving Claude Sonnet 3.7, Claude Sonnet 4 and Claude Sonnet 4.5, as well as multiple GPT, Gemini and Grok models, to generate training data for its R1 and V3 models. The government calls DeepSeek’s publicly quoted $5.6 million training cost “misleading” because it excludes the true cost of data allegedly acquired through extensive malicious distillation.
In late 2025, the advisory states, Alibaba distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 to improve software engineering, customer service dialogue, and image and character creation in its Qwen family of models. In the same period, MiniMax distilled chain-of-thought reasoning, reinforcement learning, supervised fine-tuning, and software engineering capabilities to improve its M2 model from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro, and Gemini 3 Pro.
Tactics Used to Evade Detection
According to the advisory, MiniMax also used Claude Code for internal software development and used prompt injections to try to trick Claude Code into believing it was a MiniMax product. Moonshot AI is separately accused of extracting Claude Fable 5 data to train its Kimi-K3 system, while also using GPT-4o data to train Kimi-K2.

By mid-2026, Z.AI had distilled billions of tokens of data from GPT-5.5 and Claude Opus 4.8 to develop chain-of-thought reasoning capabilities. The agencies documented these operations as part of a coordinated effort to extract advanced AI capabilities while attempting to avoid detection by the U.S. companies targeted.
Scale of Fraudulent Account Operations
Anthropic said in February that DeepSeek, Moonshot AI, and MiniMax generated over 16 million exchanges with Claude through about 24,000 fraudulent accounts. Anthropic said those operations targeted reasoning, coding, tool use, computer vision, and other valuable capabilities while violating access restrictions and terms of service.
The agencies allege they ran continuous, high-volume queries designed to extract proprietary capabilities, reasoning patterns and specialized functions from US frontier models. The campaigns use tactics, techniques and procedures (TTPs) mapped to the MITRE ATLAS framework, spanning resource development, AI model access, execution, privilege escalation, defense evasion, discovery, AI attack staging, collection, exfiltration and impact.

Government Response and Implications
“We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies,” said CISA Acting Director Nick Andersen. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models.
The advisory represents the most detailed public accounting to date of alleged intellectual property theft in the AI sector. Alibaba, MiniMax, StepFun and Z.AI have used U.S. models to develop capabilities ranging from coding and customer service to reasoning and AI agents. The operations identified in the advisory date back to late 2024 and continued through at least mid-2026, spanning multiple model generations and capabilities.
Key Facts
- NSA, CISA, and FBI released joint advisory AA26-251A on September 8, 2026
- Six China-based AI firms named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI
- Billions of tokens extracted from Claude, GPT, Gemini, and Grok models since late 2024
- Anthropic reported over 16 million exchanges through approximately 24,000 fraudulent accounts
- Activities allegedly conducted with likely Chinese government awareness
- Distilled capabilities include coding, reasoning, customer service, and AI agent development
Sources
- The Hacker News: U.S. Agencies Accuse China AI Firms
- Unite.AI: NSA, CISA, FBI Warn China-Based AI Firms Distill US Frontier Models
- IBTimes UK: US Names Six Chinese AI Firms Accused of Stealing Claude, GPT and Gemini Capabilities
- Help Net Security: Chinese AI firms are siphoning capabilities from American models
Sources
- NSA, CISA, FBI Warn China-Based AI Firms Distill US Frontier Models – Unite.AI
- US Names Six Chinese AI Firms Accused of Stealing Claude, GPT and Gemini Capabilities | IBTimes UK
- China’s $5.6 Million AI Miracle Just Got a Lot Less Miraculous
- Chinese AI firms are siphoning capabilities from American models, CISA warns – Help Net Security
- US Agencies Accuse China-Based AI Firms of ‘Malicious’ Copying of American Models | The Epoch Times