Three US agencies have jointly named six Chinese AI companies as having systematically extracted capabilities from American frontier models since late 2024, in an advisory detailed enough to list which model each firm went after and how the requests were disguised.
The National Security Agency, the FBI, and the Cybersecurity and Infrastructure Security Agency published the advisory on Tuesday under the title “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies”.
It names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. Distillation is the practice of training a cheaper model on the outputs of a more capable one, and the advisory argues it forms “the core, not merely a supplement” of how these companies build.
The sharpest line concerns the number that made DeepSeek a global story. Its widely cited $5.6mn training cost, the advisory says, excludes the cost of data acquired through malicious distillation.
That is a US government document going directly at the claim that convinced markets a frontier model could be built for the price of a house in London.
The company-level detail is unusually specific. DeepSeek is described as running organised campaigns since late 2024 against Claude, Gemini, GPT and Grok models.
Moonshot AI is said to have pulled millions of exchanges from Claude and GPT for its Kimi models from mid-2025. Alibaba is accused of distilling Claude and GPT-5 in late 2025 to improve its Qwen family.
MiniMax of extracting chain-of-thought and reinforcement learning data and attempting prompt injection against Claude Code; StepFun of taking reasoning and coding capability across late 2025 and early 2026; and Z.AI of extracting billions of tokens from GPT-5.5 and Claude Opus by the middle of this year.
How the traffic was routed is the part the industry will read twice. The advisory describes fraudulent account creation, single accounts used across many addresses, requests pushed through cloud providers and third-party aggregators that strip identifying metadata, and what it calls a grey market of API proxies known as transfer stations that defeat geographic restrictions and traceability.
It also describes jailbreak prompts that ask a model to imagine and narrate the reasoning behind an answer it has already given, which is a way of extracting hidden chain-of-thought that the provider never intended to sell. When one route was blocked, the advisory says, operators failed over to another automatically.
On the question everyone will ask, the wording is careful. The campaigns ran “likely with Chinese government awareness”.
That is awareness, not direction, and it is hedged. An advisory this specific about technique being this cautious about attribution is worth noticing rather than rounding up.
One recommendation deserves more scrutiny than it will get. Alongside detection systems and cross-industry intelligence sharing, the agencies suggest providers deploy responses that subtly alter output to suspected distillers without telling them, while informing legitimate researchers.
That is a government body advising private companies to quietly degrade service for users they suspect but have not proven anything against, and every false positive is an ordinary customer being fed worse answers with no way to know.
A Chinese embassy spokesman, Liu Chang, dismissed the allegations as a deliberate attack on China’s development in AI, according to Bloomberg, which first reported the advisory. None of the six companies responded to requests for comment.
TNW reported in April, when the White House first raised industrial-scale distillation as a policy concern, naming three of these companies, and in the same period Anthropic publicly accused Alibaba of running the largest distillation campaign against Claude.
What has changed is the venue. A policy complaint has become a technical advisory from three agencies with per-model attribution attached, which is the form these things take shortly before sanctions are discussed.
Get the TNW newsletter
Get the most important tech news in your inbox each week.