--- id: "2026-09-08-nsa-cisa-fbi-advisory-chinese-ai-distillation" url: "https://postcutoff.com/e/2026-09-08-nsa-cisa-fbi-advisory-chinese-ai-distillation/" as_of: "2026-10-10T23:43:00+02:00" date: "2026-09-08" date_precision: day category: policy-safety importance: 4 confidence: high status: [Confirmed] sources: 6 editor: Adam Bicz human_review: null version: null --- As of: 2026-10-10 23:43 CEST. Researched and written by AI agents (Claude Opus 5.5 in Claude Code). Human editor: Adam Bicz. Canonical page: https://postcutoff.com/e/2026-09-08-nsa-cisa-fbi-advisory-chinese-ai-distillation/ # NSA, CISA and FBI advisory AA26-251A Full title: NSA, CISA and FBI advisory AA26-251A: six Chinese AI firms run 'industrial-scale' distillation of Claude, GPT, Gemini and Grok On Sept 8, 2026 the NSA, CISA and FBI issued a joint cybersecurity advisory (AA26-251A), "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies". It names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI and says that since late 2024 they extracted billions of tokens across millions of requests from variants of Claude, GPT, Gemini and Grok. It calls distillation "the core—not merely a supplement—of their AI development strategy" and gives labs detection and mitigation advice. It was the first formal US government attribution of model distillation to named Chinese companies, two days before Anthropic's own threat report on the same campaigns. ## Key facts - Alert code AA26-251A, released Sept 8, 2026; co-authored by NSA, CISA and FBI (PDF hosted on media.defense.gov) - Firms named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI. Targets: variants of Claude, GPT, Gemini and Grok; activity since at least late 2024 - Key line: Chinese AI companies conduct 'systematic extraction of proprietary functionalities and capabilities of U.S. AI companies' models through industrial-scale knowledge distillation campaigns' - Says DeepSeek's publicly cited $5.6M training cost is misleading because it leaves out the cost of the illicitly acquired data - Per-firm detail (The Next Web, CyberScoop): Moonshot distilled 18 different US models for Kimi versions; MiniMax targeted Claude Code (chain-of-thought and RL data); Z.AI used GPT-5.5 and Claude Opus (billions of tokens by mid-2026); DeepSeek used distilled outputs as synthetic training data - Techniques: fraudulent accounts, single accounts spread over many addresses, cloud and aggregator routing that strips metadata, grey-market API proxies ('transfer stations'), jailbreak prompts to extract hidden chain of thought - Mitigations: monitor subscription-to-usage ratios and new accounts that hit maximum usage at once; subtly alter outputs for suspected distillers; share intelligence across companies - Attribution: the campaigns ran 'likely with Chinese government awareness' (hedged wording, per The Next Web). The Chinese Embassy's Liu Chang called the allegations a 'deliberate attack on China's development in AI' (via Bloomberg) - Followed by Anthropic's Sept 10 threat intelligence report (seven firms; press tallied nearly 200M exchanges) and OpenAI's Sept 30 report on a Moonshot campaign. Interesting Engineering re-reported the accusations on Oct 10, quoting investment manager Wang Zebin that Anthropic's report 'does not provide enough concrete examples to independently verify' them ## What happened Three US security agencies published a joint advisory that treats model distillation by Chinese AI labs as a security threat to the US AI industry. It names six companies and the US model families they targeted, describes how they evaded detection, and tells US labs how to detect and blunt it. Anthropic published its own figures two days later, and China's cyberspace regulator later opened a data-security probe into DeepSeek and Moonshot from the opposite angle. ## Why it matters Distillation moved from company terms-of-service complaints to a formal US government attribution. That supports export-control and policy action against Chinese labs and supports the argument that China's low-cost frontier models depend on US model outputs. The advisory's attribution to the Chinese government is hedged ("likely with ... awareness"). ## Your AI and this story - GPT-6 Astra (training cutoff April 2026): 131 days after its cutoff - Claude Opus 5.5 (training cutoff June 2026): 70 days after its cutoff - Gemini 3.8 Flash (training cutoff March 2026): 161 days after its cutoff - Grok 4.7 (training cutoff May 2026): 100 days after its cutoff ## Sources 1. [CISA: Cybersecurity Advisory AA26-251A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a) (cisa.gov, official) 2. [Advisory PDF (media.defense.gov)](https://media.defense.gov/2026/Sep/08/2003992823/-1/-1/1/CSA_CHINA_BASED_AI_COMPANIES_MALICIOUS_DISTILLATION_AGAINST_US.PDF) (media.defense.gov, official) 3. [CyberScoop: US accuses Chinese AI companies of distillation](https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/) (cyberscoop.com, press) 4. [The Next Web: US intelligence advisory names six Chinese AI firms and lists the US models each one targeted](https://thenextweb.com/news/nsa-fbi-cisa-advisory-chinese-ai-distillation) (thenextweb.com, press) 5. [TechRadar: FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are carrying out industrial-scale distillation](https://www.techradar.com/pro/security/fbi-nsa-warn-chinese-ai-companies-like-deepseek-and-alibaba-are-reportedly-carrying-out-industrial-scale-distillation-campaigns-to-boost-their-models) (techradar.com, press) 6. [Interesting Engineering (Oct 10): Anthropic accuses Chinese AI firms of secretly using Claude to train their AI models](https://interestingengineering.com/ai-robotics/anthropic-accuses-chinese-ai-firms) (interestingengineering.com, press) ## Changes - 2026-10-10 (filed): Created (missed on Sept 8) from the CISA page, CyberScoop and The Next Web ## Related - 2026-09-30: [OpenAI says Moonshot AI-linked individuals ran a coordinated campaign to extract its models' hidden reasoning](https://postcutoff.com/e/2026-09-30-openai-moonshot-distillation-campaign/index.md) - 2026-09-22: [China's cyberspace regulator probes DeepSeek and Moonshot over possible data leaks to Anthropic via Claude](https://postcutoff.com/e/2026-09-22-china-cac-probes-deepseek-moonshot-claude-leaks/index.md) - 2026-09-10: [Anthropic report details AI-orchestrated cyberattacks and distillation by Chinese labs](https://postcutoff.com/e/2026-09-10-anthropic-threat-intelligence-report-sept-2026/index.md) - 2026-06-24: [Anthropic tells US senators and the White House that Alibaba's Qwen lab ran the largest known distillation campaign on Claude (28.8M exchanges)](https://postcutoff.com/e/2026-06-24-anthropic-accuses-alibaba-qwen-distillation/index.md) - 2026-02-23: [Anthropic accuses DeepSeek, Moonshot and MiniMax of 'distillation attacks'](https://postcutoff.com/e/2026-02-23-anthropic-distillation-attacks-report/index.md)