← BACK TO FEED
DeepSeekmodel distillationAI securityUS-China AIAlibaba

NSA, FBI and CISA Accuse Chinese AI Firms of Systematic Model Distillation at Industrial Scale

The NSA, FBI, and CISA have jointly accused several Chinese AI companies — including DeepSeek, Alibaba, and Moonshot AI — of conducting large-scale "distillation" of US AI models, allegedly extracting their capabilities in violation of terms of service by routing requests through proxies and third-party aggregators to avoid detection. The agencies claim distillation is central, not incidental, to these companies' AI development strategies, and that the Chinese government is likely aware of the activity. In response, the agencies recommend that US AI providers implement measures to detect and disrupt such campaigns, including subtly altering responses to suspected distillation attempts.

Three US government agencies have jointly accused several prominent Chinese AI companies of systematically extracting capabilities from American frontier models through large-scale distillation campaigns. The NSA, FBI, and CISA published a joint advisory this week claiming that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been running coordinated operations to harvest proprietary functionality from US models, and that China's government is 'likely' well aware of it.

Distillation, for those unfamiliar, is the process of training a smaller model by having it repeatedly query a larger one and learn from the responses. Done legitimately, it's a practical way to compress a capable model into a lighter, cheaper package. Done without authorisation, it's essentially intellectual property theft at scale. Virtually all commercial model providers prohibit it explicitly in their terms of service, for obvious reasons.

According to the advisory, Chinese firms are routing distillation requests through a patchwork of native APIs, remote cloud providers, and third-party aggregators that strip out user metadata to dodge detection. They're also allegedly using what the document calls a 'gray market' of proxy resellers, or 'transfer stations', that flog access to frontier models at knock-down prices while quietly obscuring who's actually doing the querying.

The agencies aren't just claiming this is a side hustle. They describe distillation as 'the core, not merely a supplement' of these companies' AI development strategies. That's a significant accusation, and one with real consequences for how we interpret some recent headline-grabbing claims.

DeepSeek is singled out for using distillation to generate synthetic training data, which would make its widely publicised claims about training on minimal compute look considerably less impressive. When DeepSeek dropped those efficiency numbers earlier this year, markets moved. Investors started questioning whether the billions being funnelled into AI infrastructure were actually necessary. If the advisory's allegations hold up, the answer was essentially: yes, they were, DeepSeek just quietly used someone else's.

Alibaba's Qwen models also get a mention. The advisory alleges industrial-scale distillation was used to sharpen Qwen's capabilities. Worth noting that several Qwen models are genuinely good and available to download for free, which puts direct pressure on US competitors who are spending enormous sums and still running at a loss.

The agencies recommend that AI providers try to detect and disrupt distillation attempts. Suggested measures include flagging accounts that immediately hit maximum usage limits, coordinating suspicious activity across multiple platforms and API aggregators, and, interestingly, subtly corrupting responses to accounts suspected of malicious distillation. Poisoning the well, essentially.

This isn't the first time US agencies have made these kinds of accusations, and it probably won't be the last. China's response so far has been to point the finger back, arguing American companies are equally guilty of distilling Chinese models, and hinting that export-style restrictions could trigger retaliation. Both sides claiming victim status while presumably doing roughly similar things is, at this point, fairly standard geopolitical theatre.

Comment has been sought from the named Chinese companies. Don't hold your breath.

WATCH THE SHORT
READ NEXT
NSA, CISA and FBI: China Is Systematically Looting US AI Models at Industrial ScaleAI Agents Are Eating Security Budgets — and CISOs Still Don't Have the Guardrails to Show for ItKiteworks Buys Bonfy.AI to Plug the Gap Between Knowing Where Your Data Is and Actually Controlling It