Timeline

US agencies accuse six Chinese labs of distilling US AI models

A joint NSA/CISA/FBI advisory named DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.AI as running systematic distillation campaigns against Claude, GPT, Gemini and Grok since late 2024; China's Commerce Ministry rejected it and threatened countermeasures.

  • Security & misuse
  • Government & policy
  • Major

The US National Security Agency, Cybersecurity and Infrastructure Security Agency and FBI issued a joint cybersecurity advisory (AA26-251A) accusing six Chinese AI companies — DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.AI (Zhipu) — of running systematic “distillation” campaigns against leading US models since late 2024. Distillation, in this usage, means querying a rival’s model at scale to capture its outputs and train a cheaper competitor on them; the advisory said the campaigns targeted Claude, GPT, Gemini and Grok. It was the first time the US government had jointly named specific Chinese labs in such a document.

The advisory framed the activity as both a commercial and a national-security concern and sat alongside the existing regime of chip export controls and anti-distillation measures. It offered mitigations for US model providers — usage monitoring, rate limits and account controls — rather than announcing new penalties directly.

China’s Commerce Ministry rejected the accusations the following day, with a spokesperson calling distillation “a normal technical and commercial issue” and warning of “resolute countermeasures” if the US used the claims to suppress Chinese AI firms. The advisory followed Anthropic’s February accusation that several of the same labs had distilled Claude, and preceded by two days Anthropic’s own September threat report documenting a far larger volume of such activity — the three landing in the same week as an escalating, multi-sourced account of one dispute.