NSA, FBI and CISA Accuse Chinese AI Firms of Systematic Model Distillation at Industrial Scale
Three US government agencies have jointly accused several prominent Chinese AI companies of systematically extracting capabilities from American frontier models through large-scale distillation campaigns. The NSA, FBI, and CISA published a joint advisory this week claiming that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been running coordinated operations to harvest proprietary functionality from US models, and that China's government is 'likely' well aware of it.
Distillation, for those unfamiliar, is the process of training a smaller model by having it repeatedly query a larger one and learn from the responses. Done legitimately, it's a practical way to compress a capable model into a lighter, cheaper package. Done without authorisation, it's essentially intellectual property theft at scale. Virtually all commercial model providers prohibit it explicitly in their terms of service, for obvious reasons.
According to the advisory, Chinese firms are routing distillation requests through a patchwork of native APIs, remote cloud providers, and third-party aggregators that strip out user metadata to dodge detection. They're also allegedly using what the document calls a 'gray market' of proxy resellers, or 'transfer stations', that flog access to frontier models at knock-down prices while quietly obscuring who's actually doing the querying.
The agencies aren't just claiming this is a side hustle. They describe distillation as 'the core, not merely a supplement' of these companies' AI development strategies. That's a significant accusation, and one with real consequences for how we interpret some recent headline-grabbing claims.
DeepSeek is singled out for using distillation to generate synthetic training data, which would make its widely publicised claims about training on minimal compute look considerably less impressive. When DeepSeek dropped those efficiency numbers earlier this year, markets moved. Investors started questioning whether the billions being funnelled into AI infrastructure were actually necessary. If the advisory's allegations hold up, the answer was essentially: yes, they were, DeepSeek just quietly used someone else's.
Alibaba's Qwen models also get a mention. The advisory alleges industrial-scale distillation was used to sharpen Qwen's capabilities. Worth noting that several Qwen models are genuinely good and available to download for free, which puts direct pressure on US competitors who are spending enormous sums and still running at a loss.
The agencies recommend that AI providers try to detect and disrupt distillation attempts. Suggested measures include flagging accounts that immediately hit maximum usage limits, coordinating suspicious activity across multiple platforms and API aggregators, and, interestingly, subtly corrupting responses to accounts suspected of malicious distillation. Poisoning the well, essentially.
This isn't the first time US agencies have made these kinds of accusations, and it probably won't be the last. China's response so far has been to point the finger back, arguing American companies are equally guilty of distilling Chinese models, and hinting that export-style restrictions could trigger retaliation. Both sides claiming victim status while presumably doing roughly similar things is, at this point, fairly standard geopolitical theatre.
Comment has been sought from the named Chinese companies. Don't hold your breath.