NSA, FBI and CISA Allege China-Based Firms Extracted U.S. AI Capabilities

The warning treats alleged misuse of model outputs as a national-security concern and calls for defenses that reach beyond any single AI provider.

By 3 min read
NSA, FBI and CISA Allege China-Based Firms Extracted U.S. AI Capabilities
NSA, FBI and CISA Allege China-Based Firms Extracted U.S. AI Capabilities

Listen to this story

The audio brief

About 1:41
0:001:41
Read transcript
The NSA, FBI and CISA are alleging that China-based AI firms extracted capabilities from restricted U.S. frontier models at industrial scale, using billions of tokens across millions of requests. The advisory says this activity has been underway since at least late 2024, and could help narrow the technology gap without equivalent spending on compute, electricity or foundational research. The agencies draw a line between legitimate knowledge distillation—using a more advanced model’s answers to train another—and what they describe as targeted extraction of restricted capabilities. They allege that DeepSeek used outputs from four Claude versions, two Gemini versions, five ChatGPT versions and Grok 4 to train its R1 and R3 models. Moonshot AI allegedly queried 18 U.S. models while training Kimi-K2 and Kimi K3. Alibaba, MiniMax, StepFun and Z.AI are also named in the advisory. The reported tactics were designed to stay fragmented. Operators allegedly spread requests across accounts, providers and models, then routed them through proxies, remote clouds and third-party API aggregators. That could obscure user metadata and help bypass geographic restrictions, terms of use and model safeguards. The stakes extend beyond model labs. The agencies assess that resulting gains could support Chinese military and cyber operations against the United States and its allies. Their response calls for coordinated defenses involving cloud providers, infrastructure firms, API aggregators, private industry and allied governments. The key constraint is whether those groups can share intelligence and detect distributed activity before any one provider sees the full pattern.

Story brief

3 key points

A joint NSA, FBI and CISA advisory alleges China-based firms have used large-scale, fragmented querying to extract capabilities from restricted U.S. frontier models since at least late 2024. The agencies distinguish legitimate knowledge distillation from targeted extraction, citing billions of tokens across millions of requests, proxies and third-party infrastructure. The warning raises operational risks for model...

  1. 01

    DeepSeek allegedly used outputs from 12 Claude, Gemini, ChatGPT and Grok variants to train its R1 and R3 models.

  2. 02

    Moonshot AI allegedly queried 18 U.S. models while training Kimi-K2 and Kimi K3.

  3. 03

    Operators reportedly spread activity across accounts, providers, proxies and aggregators to evade detection and geographic restrictions.

The NSA, FBI and CISA released a joint cybersecurity advisory alleging that China-based AI companies systematically extracted restricted proprietary capabilities from U.S. frontier models to train their own. The agencies characterize the alleged activity as industrial-scale and say it could narrow a technology gap without comparable research costs.

Knowledge distillation is a training method in which one model queries a larger, more advanced model to learn from its outputs. The agencies explicitly say it can be legitimate and useful in AI research. Their warning draws its boundary at allegedly aggressive, targeted extraction of restricted features, rather than treating all distillation as improper.

The companies and models named in the warning

The advisory identifies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as participants in the alleged campaigns. It lists variants of Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini and xAI’s Grok as targets.

The advisory alleges DeepSeek generated synthetic training data from four Claude versions, two Gemini versions, five ChatGPT versions and Grok 4 for its R1 and R3 models. It separately alleges Moonshot AI queried 18 U.S. models to train Kimi-K2 and Kimi K3.

A pattern designed to stay fragmented

According to the advisory, operators spread queries over accounts, models and platforms, using native APIs, remote cloud providers and third-party aggregators that can obscure user metadata. It also cites proxies and gray-market technology as tools to bypass geographic restrictions, terms of use and model safeguards. The agencies say dispersing operations among providers and infrastructure was intended to avoid a single point of detection.

The response reaches beyond model labs

The agencies say such activity can help Chinese models close the technology gap without equivalent spending on compute, electricity or foundational research. They also assess that advances could enhance military and cyberattack capabilities against the United States and its allies.

The advisory’s recommended actions

  • Comprehensive detection and mitigation.
  • Targeted response changes.
  • Cross-organization intelligence sharing.

The agencies call for collaboration among government, private industry and allied nations. They specifically point to cloud providers, API aggregators and infrastructure providers as parts of a coordinated defense against industrial-scale campaigns.

Editorial analysis

Our Read

The advisory turns a familiar training method into a question of access patterns. Its concern is not simply what a model can do, but whether distributed use can reconstruct valuable behavior across commercial AI services. That is an interpretation of the agencies’ allegations, not evidence that every form of distillation is improper. The next concrete test is whether model providers, cloud services and aggregators develop shared ways to identify and respond to suspicious patterns without treating legitimate research or ordinary customer activity as equivalent.

Sources

  1. nsa.govNSA and Others Warn China-Based AI Companies are Distilling U.S. Frontier AI Models
  2. cyberscoop.comFeds accuse China of ‘systematic’ distillation of U.S. AI models
  3. nextgov.comIntelligence agencies warn of China’s large-scale AI model distillation efforts

Loading discussion...