TechNewsReel
Live

US Accuses Six Chinese AI Firms of Industrial-Scale Model Distillation

The FBI, NSA, and CISA claim Chinese companies extracted billions of tokens from US frontier models to accelerate development and slash costs.

TechNewsReel Newsroom · September 9, 2026

The FBI, NSA, and CISA issued a joint cybersecurity advisory on September 8, 2026, accusing six Chinese AI firms of conducting industrial-scale distillation attacks against US frontier models. The US government asserts these activities, which began in late 2024, were likely carried out with the awareness of the Chinese government.

According to the advisory, the six firms—Alibaba, DeepSeek, MiniMax, Moonshot AI, StepFun, and Z.AI—extracted billions of tokens through millions of requests targeting models including GPT, Claude, Gemini, and Grok. To bypass geographic restrictions and avoid detection, the firms allegedly employed "transfer stations," which are gray market proxies, and utilized automated failover between different pathways. The US government also identified the use of chain-of-thought (CoT) reasoning extraction to capture the internal logic of the targeted models.

The Mechanics of Malicious Distillation

Knowledge distillation is a common industry practice where a large "teacher" model is used to train a smaller, more efficient "student" model. However, the US government distinguishes these specific cases as malicious because they involved the systematic violation of terms of service and the use of evasive techniques to target proprietary capabilities. By extracting this data, the firms were able to bypass the massive compute requirements and research expenditures typically necessary to build frontier-level AI.

Implications for the AI Arms Race

This activity represents a significant escalation in the global AI competition, shifting the focus from traditional intellectual property theft to the industrial-scale extraction of model capabilities. The joint advisory from CISA, the NSA, and the FBI noted that China-based AI companies conducting these attacks see "significantly shorter AI development timelines and reduced financial expenditures in training a frontier model."

For the US AI industry, this shift prompts a fundamental change in security posture. Leading AI labs are now encouraged to treat model distillation not as simple API abuse, but as a major security event. This has led to increased calls for coordinated defense efforts through industry bodies like the Frontier Model Forum to protect proprietary weights and reasoning patterns.

Future Outlook

As the US government continues to monitor these activities, the focus will likely shift toward more robust detection methods for distillation patterns. It remains to be seen how the named Chinese firms or the Chinese government will respond to these specific accusations. For now, the incident underscores a growing vulnerability in the API-driven delivery of frontier AI, where the model's own outputs can be weaponized to build its competitors.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.