US Intelligence Agencies Charge Six Chinese AI Firms With Systematic Model Theft
The NSA, CISA and FBI have accused major Chinese artificial intelligence companies of conducting large-scale extraction campaigns against leading US AI systems, potentially accelerating their development timelines by years.

While American AI developers have invested years and billions of dollars to create frontier models, US government agencies contend that six Chinese companies have taken a shortcut: querying those models at massive scale. On Tuesday, the NSA, CISA and FBI publicly named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as perpetrators of large-scale knowledge-distillation operations targeting US frontier AI models beginning in late 2024.
The agencies' advisory details how these companies collectively harvested billions of tokens by submitting millions of queries to models developed by Anthropic, OpenAI, Google and xAI. While the agencies indicated the activity occurred "likely with Chinese government awareness," they stopped short of claiming direct involvement by Chinese intelligence services.
China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale.
US officials
Knowledge distillation represents a standard AI methodology in which a smaller model absorbs insights from a more sophisticated system's outputs. The US complaint focuses on the manner of application—specifically the sheer volume of requests, use of multiple accounts, deployment of proxy infrastructure and circumvention of geographic and usage controls.
How the alleged campaigns worked
According to the advisory, DeepSeek executed systematic extraction operations concentrating on reasoning capabilities, specialized functions and other features incorporated into its R1 and V3 models.
Moonshot AI allegedly leveraged multiple US-based models to strengthen its Kimi systems. The advisory separately identified Alibaba as targeting software engineering, customer-service and agentic capabilities; MiniMax as extracting reasoning and software-development capabilities; StepFun as focusing on coding and agentic functions; and Z.AI as harvesting chain-of-thought reasoning data.
The agencies documented infrastructure mechanisms designed to conceal the operations. The companies purportedly employed "transfer stations," or gray-market proxy services, to redirect requests through varying routes and mask their source. Additional indicators included accounts operating across multiple IP addresses, round-the-clock activity patterns and new subscriptions immediately utilizing maximum allowances.
The defensive move that could change AI services
A striking recommendation in the advisory suggests AI providers modify responses directed toward suspected distillation operations. Vendors could decrease reasoning complexity, alter solution pathways or redirect questionable users to lower-capability models without explicit notification.
Such countermeasures risk affecting legitimate users if detection mechanisms generate false alarms. The agencies therefore advise restricting response modifications to confirmed malicious campaigns, contingent upon enhanced identity verification, behavioral analysis and coordinated information exchange among model providers, cloud infrastructure operators and API intermediaries.
The bigger AI race
These accusations carry significance because effective distillation might substantially compress both development duration and financial investment required for competitive model creation. The US agencies noted that organizations executing these operations can realize "significantly shorter AI development timelines and reduced financial expenditures" during frontier system training.
This dynamic presents a complex challenge for US AI companies: safeguarding proprietary innovations while maintaining usability for legitimate customers.
The implications transcend commercial competition. US officials cautioned that capabilities derived from the alleged activity could augment Chinese military strength and cyberattack potential.
China rejects the allegations
China has dismissed the accusations. Its Foreign Ministry characterized the allegations as factually baseless and legally unfounded, while asserting that distillation constitutes a widely recognized technical approach.
We hope the US will earnestly implement the important consensus reached by the leaders of both countries and refrain from making false accusations and smearing China.
Chinese Foreign Ministry spokesperson Mao Ning, according to Reuters
The disagreement emerges as a planned September 24 meeting between President Donald Trump and Chinese President Xi Jinping approaches, according to Reuters, introducing another technology dispute to an already tense US-China relationship.
What enterprise AI customers should do
For organizations utilizing enterprise AI services, this conflict may extend beyond diplomatic considerations. Vendors may institute stricter identity verification, more restrictive account-sharing policies, reduced usage thresholds or undisclosed model downgrades upon detecting questionable behavior. Such measures could generate inconsistent results or service interruptions for companies managing legitimate high-volume operations.
Technology leaders should deploy dedicated enterprise accounts, prohibit shared login credentials, establish baseline API-consumption patterns and inquire with vendors regarding how suspected distillation activity influences model selection and output characteristics. Organizations should additionally confirm which underlying models support third-party AI services, particularly when those services process confidential information or support mission-critical processes.


