The NSA, CISA and FBI issued a joint advisory on September 8 accusing China-based AI companies, named as DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, of running what the agencies call industrial-scale distillation campaigns against US frontier AI models since late 2024. The advisory says the companies extracted “billions of tokens across millions of exchanges” from Claude, GPT, Gemini and Grok variants, using distillation techniques to train competing models on the outputs of the American systems. The agencies describe this extraction as “the critical core” of the Chinese firms’ development strategy rather than a supplementary shortcut, and say the companies route around geographic access restrictions through gray-market API proxies the advisory calls “transfer stations.”
For security leaders, the operational takeaway sits with anyone running or exposing an AI model API: distillation at this scale depends on sustained, high-volume querying that behavioral monitoring can catch even when individual requests look legitimate. The advisory’s recommended mitigations, behavioral monitoring for distillation patterns, altering responses to suspected extraction attempts, and cross-organization intelligence sharing among US AI providers, are a direct acknowledgment that API rate limits and terms-of-service enforcement alone have not been sufficient.
The advisory also makes a pointed claim about the economics behind this: it calls DeepSeek’s widely publicized $5.6 million training-cost figure “misleading,” on the grounds that it excludes the cost of data acquired through the extraction campaign the agencies describe. Whether or not that figure holds up, the agencies are drawing a direct line between reported AI development costs and unauthorized model access, a link that changes how a training-cost claim should be read going forward.
Source: CISA
Related coverage: AI Systems Have Become the Target, Not Just the Tool and A Private Vendor Sold Beijing Its Hacking Tools.