News · 2026-09-09
US agencies name six Chinese AI firms and say copying American models is their core strategy
The National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI jointly published an advisory, numbered AA26-251A and dated 8 September 2026, stating that China-based AI companies are systematically extracting capabilities from US frontier models through what the agencies call industrial-scale knowledge distillation campaigns. The advisory names six firms and says the practice is not a side channel but the centre of their development strategy. Its most unusual recommendation is that American labs should quietly degrade the answers they give suspected copiers rather than shut them out.
Key facts
- The core finding: distillation campaigns "form the core—not merely a supplement" of the named companies' AI development strategy.
- When: advisory AA26-251A, published 8 September 2026.
- Who: NSA, CISA and the FBI jointly; six named Chinese firms; four named US model families.
- Primary source: CISA advisory AA26-251A.
Distillation is ordinary machine-learning practice. You take a big, expensive model, ask it a great many questions, and train a smaller model on its answers. The student ends up imitating the teacher at a fraction of the cost. Labs do this to their own models constantly — it is how most small fast models get made.
What the agencies describe is that technique aimed outward at scale. Named in the advisory are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The US models said to have been harvested include variants of Anthropic's Claude, OpenAI's GPT, Google's Gemini and xAI's Grok. Of DeepSeek specifically, the advisory states that the company "has conducted organized campaigns since at least 2024 targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models."
The routing is the security part. According to the agencies, requests are pushed through native APIs, cloud resellers and third-party aggregators that strip identifying metadata, plus a grey market of proxy services described as "transfer stations" that exist to launder access past restrictions. The economic asymmetry is the point of the whole exercise: answering a question costs the frontier lab a fraction of a cent, while the capability those answers encode cost hundreds of millions of dollars to create.
A reasonable analogy is a research library with a photocopier. Any individual visitor copying a page is unremarkable and permitted. The advisory's claim is that a coordinated operation has been copying the collection page by page, through a rotating cast of library cards, and rebinding it as a competing edition.
The mitigation advice is where this gets genuinely novel, and it is why the advisory is interesting to people who do not care about geopolitics. The agencies recommend three things: detect anomalous prompts, accounts and behaviours; establish intelligence sharing across model providers, cloud platforms and API aggregators; and "deploy targeted response changes: subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs."
That third recommendation is a government body advising private companies to feed deliberately degraded output to users they suspect but have not proven anything against. It is defensible on its own terms — a blocked account tells the operator to try again from a new one, whereas a subtly poisoned one wastes their training run. It is also a meaningful change in what an API response is understood to be. Every user of a frontier model now has a small new reason to wonder whether the answer they received was the best one available, and there is no way for an ordinary customer to tell the difference. The advisory does not address false positives.
This is a well-established beat rather than a bolt from the blue. Ground Truth has covered attackers sending more than 100 million prompts to copy Google's models, Anthropic closing the hole distillers used to read Claude's reasoning, Treasury floating sanctions over distillation and White House allegations against Moonshot. What is new here is that it is now a numbered joint advisory from three agencies with companies named in it, rather than an anonymous accusation or a lobbying filing.
The honest caveat: this is a government document making an attribution claim, and it is a one-sided one. The advisory says the campaigns were carried out "likely with the knowledge of the Chinese government" — "likely" is doing real work in that sentence. The named companies have not had their response recorded in the advisory, and the underlying evidence is not published, which is normal for this document type and also means the public cannot check it. Beijing has previously made the mirror-image accusation, alleging that US firms distilled Chinese models. Terms of service violations and espionage are also not the same thing, and the advisory blends the vocabulary of both.
Independent coverage is available from The Register and Help Net Security.
Key questions
What is knowledge distillation, and why is it treated as a security issue here?
Which companies does the advisory name?
What do the agencies tell US labs to do about it?
Cite this
APA
Ground Truth. (2026, September 9). US agencies name six Chinese AI firms and say copying American models is their core strategy. Ground Truth. https://groundtruth.day/news/nsa-cisa-and-fbi-name-six-chinese-ai-firms-in-a-distillation-advisory.html
BibTeX
@misc{groundtruth:nsa-cisa-and-fbi-name-six-chinese-ai-firms-in-a-distillation-advisory,
title = {US agencies name six Chinese AI firms and say copying American models is their core strategy},
author = {{Ground Truth}},
year = {2026},
month = {sep},
url = {https://groundtruth.day/news/nsa-cisa-and-fbi-name-six-chinese-ai-firms-in-a-distillation-advisory.html}
}
Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.