AI: Washington accuses six Chinese groups of industrial “distillation” of American models
The NSA, FBI, and CISA accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of having extensively extracted capabilities from American models. The agencies present these practices as a national security risk, while noting that distillation is a legitimate technique when authorized.

SUMMARY
The main American cybersecurity and investigative agencies accused six Chinese artificial intelligence companies on Tuesday, September 8, 2026, of conducting large-scale “distillation” campaigns against leading American models since at least late 2024. In a joint advisory, the NSA, FBI, and CISA named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
According to the three agencies, these companies would have extracted billions of tokens during millions of exchanges with models such as Claude, GPT, Gemini, and Grok in order to train or improve their own systems. The document states that these operations constitute not merely a supplement, but a central element of their development strategy. This assessment comes from the American authorities, and the accusations have not been established by a court decision.
“Distillation” is a common machine learning technique: a less powerful model is trained based on the responses of a more advanced model in order to replicate some of its capabilities at a lower cost. The NSA, FBI, and CISA acknowledge that this method is legitimate in many applications. Their alert targets practices they describe as unauthorized, notably the use of networks of accounts, cloud providers, and intermediaries intended to circumvent access restrictions and the terms of use of American providers.
Reuters reported on Tuesday the publication of the notice and the American accusations of “aggressive” industrial-scale distillation activities. The case is part of an already intense technological confrontation between Washington and Beijing. In July, China had rejected similar accusations of intellectual property theft in AI, denouncing what it called American “hegemonism.”
American agencies now present the issue as a matter of national security, considering that access to advanced AI capabilities can have effects in the cyber, military, economic, and critical infrastructure sectors. They recommend that AI companies and cloud providers improve the detection of abnormal usage, increase the sharing of indicators between platforms, and reduce the effectiveness of suspicious distillation attempts.
DeepSeek, Alibaba and four other companies named
The joint notice attributes to DeepSeek campaigns organized since late 2024 targeting, in particular, reasoning capabilities and specialized functions for its R1 and V3 models. The American agencies also claim that Alibaba used large-scale distillation techniques to improve the Qwen family. Moonshot AI, MiniMax, StepFun, and Z.AI are also mentioned in the document.
The report states that operators distribute requests among several model providers, cloud platforms, and API aggregators in order to limit the risk of detection. It also describes the use of intermediary services, sometimes referred to as “transfer stations,” which would allow the origin of connections to be concealed and certain geographical restrictions to be bypassed.
A technological and legal battle still ongoing
The debate over distillation goes beyond this new official statement. In February, Anthropic accused DeepSeek, Moonshot AI, and MiniMax of creating approximately 24,000 fraudulent accounts and generating more than 16 million exchanges with Claude. In July, the Washington Post also reported accusations from Anthropic targeting a campaign linked to Alibaba and its Qwen team.
These precedents illustrate an important distinction: distillation itself is not a practice prohibited by nature and is widely used in the industry. The dispute concerns access authorization, compliance with contractual conditions, and the alleged extraction of proprietary features. The companies and authorities involved have been contesting for several months the way Washington presents this technological competition.
In its opinion of September 8, the NSA recommends three immediate measures: strengthening detection and mitigation mechanisms, modifying the responses provided when a malicious extraction is suspected, and organizing intelligence sharing between model developers, cloud platforms, and API aggregators.

Comments