The National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI have jointly named six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, accusing them of running industrial-scale AI model distillation campaigns against US frontier models since at least late 2024. The claim appears in a joint advisory the three agencies published on Tuesday, and it marks the first time Washington has attached specific company names to the practice rather than describing it in general terms.
The advisory states that the six firms extracted capabilities from variants of Claude, GPT, Gemini and Grok, running billions of tokens’ worth of queries against the US models and using the resulting outputs as training data for their own systems. The agencies say this was done at a scale consistent with a deliberate, sustained programme rather than incidental use of public APIs, and that the companies “likely” acted with Chinese government awareness, though the advisory does not claim direct state direction of the campaigns.
How AI model distillation cuts costs
Distillation is not inherently improper. Training a smaller “student” model on the outputs of a larger “teacher” model is a standard technique, used openly by labs everywhere to compress capable models into cheaper ones. What the advisory describes is different in scale and intent: repeated, automated querying designed to reproduce a target model’s reasoning patterns and outputs closely enough to shortcut the years of pretraining and reinforcement learning that produced them in the first place. Done at industrial volume, it lets a company skip most of the expensive experimentation that separates a frontier model from a merely competent one.
The agencies put a figure on why that matters commercially. “China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model,” they said in the advisory. Ars Technica, which first laid out the full list of six named firms and the four targeted model families, reported the same quote framed around the billions in Chinese development costs the practice may have offset.
What the advisory adds beyond the headlines
The advisory itself, filed as AA26-251A, is the primary document here and worth reading directly rather than through summaries: it lays out the technical indicators the agencies used to distinguish industrial-scale distillation from ordinary API traffic, and it is aimed at AI providers and enterprise users rather than the general public. That framing matters for anyone running inference infrastructure, since the mitigations agencies typically recommend in this kind of advisory, rate limiting, output watermarking and anomaly detection on query patterns, fall on the model providers rather than governments to implement.
The advisory lands against a backdrop of rapid frontier releases on the US side, including OpenAI’s rollout of GPT-6 Astra to ChatGPT and Codex, which is exactly the kind of release cycle distillation is accused of letting competitors shortcut.
What to watch next
Watch for whether any of the six named firms issue a public response, and whether US labs follow the advisory with concrete changes to API access, such as tighter rate limits or stricter enterprise verification, aimed at slowing this kind of large-scale extraction.








