US Intelligence Agencies Accuse China-Based AI Firms of 'Industrial-Scale' Knowledge Distillation
The NSA, CISA, and FBI have issued a joint advisory warning that Chinese AI companies, including DeepSeek and Alibaba, are systematically extracting proprietary capabilities from U.S. frontier models.

Key takeaways · 3
- 01
U.S. agencies state knowledge distillation forms the core of China-based AI development strategies.
- 02
Targeted models include variants of Claude, GPT, Gemini, and Grok.
- 03
Companies are utilizing proxy networks called "transfer stations" to bypass U.S. safeguards.
The Joint Advisory
The National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation released a joint cybersecurity advisory on September 8, 2026. [2] The agencies warned that China-based artificial intelligence companies are systematically extracting proprietary capabilities from U.S. frontier AI models. [2][5] This activity is described as industrial-scale knowledge distillation running since at least late 2024. [2][5] According to the advisory, designated AA26-251A, these campaigns form the core of the companies' AI development strategy, rather than merely supplementing it. [2]
CISA described knowledge distillation as a machine learning technique that trains a less capable model using the outputs of a larger, more capable one. [2] While it is a valid training method, CISA noted it can be misused to acquire capabilities from competitors in less time and with less cost than developing them legitimately. [2] CISA Acting Director Nick Andersen strongly urged AI companies to take immediate steps to safeguard their platforms against these distillation campaigns. [2]
Tactics and Targets
The agencies state that, likely with Chinese government awareness, multiple firms extracted billions of tokens across millions of exchanges and requests from U.S. models. [2][5] The targeted systems include variants of Claude, GPT, Gemini, and Grok. [2][5] The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as companies engaging in these extraction campaigns. [2][5] To gain unauthorized access, China-based AI companies route distillation requests through native application programming interfaces, remote cloud providers, and third-party aggregators that automatically obfuscate user metadata. [5] Furthermore, these companies bypass geographic restrictions and evade safeguards by using a gray market of proxies known as "transfer stations." [5]
DeepSeek specifically conducted organized campaigns targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models. [5] DeepSeek's R1 model was released in early 2025. [2] Alibaba also leveraged this industrial-scale distillation to improve its Qwen family of AI models. [5] The agencies stated that this activity violates the U.S. companies' terms of use and threatens U.S. technological leadership. [2]
What it means
This joint advisory reframes the narrative around the low development costs previously claimed by some China-based AI firms. For nearly two years, DeepSeek's $5.6 million number helped sell a story that the Chinese company built a frontier-level model for a fraction of what American firms were spending. By characterizing the distillation campaigns as aggressive and malicious, U.S. agencies indicate that these cost savings rely heavily on unauthorized extraction from competitors rather than purely legitimate breakthroughs. The advisory explicitly contrasts legitimate AI research distillation with these targeted activities that extract restricted proprietary functionalities. What the sources don't address: How U.S. frontier model developers plan to technically enforce safeguards against the obfuscated third-party aggregators and proxy transfer stations identified by the intelligence agencies.
The joint advisory highlights a significant national security and intellectual property concern regarding how offshore AI developers accelerate their roadmaps. By labeling the behavior as malicious and industrial-scale, U.S. agencies are signaling the need for stricter API governance and metadata monitoring among frontier model providers.
Why it matters
Put this to work — one session a day, built for your industry.
Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.
Start freeHow this developed
9 September 2026
US Intelligence Agencies Accuse China-Based AI Firms of 'Industrial-Scale' Knowledge Distillation
9 September 2026
Event created from source cluster.
Sources
- US Says Alibaba, DeepSeek Have ‘Systematically’ Siphoned AI ModelsBloomberg Technology
- US accuses Chinese AI firms of 'industrial-scale' theft of AI technology | Reutersreuters.com
- The NSA, CISA, and FBI issue a joint advisory warning that Chinese AI companies, including DeepSeek, are conducting "industrial-scale" distillation campaigns (Reuters)Techmeme
- NSA, CISA, FBI Warn China-Based AI Firms Distill US Frontier ModelsUnite.AI
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies | CISAcisa.gov
- China’s $5.6 Million AI Miracle Just Got a Lot Less Miraculous – PJ Mediapjmedia.com