Three U.S. intelligence agencies just put their names on paper accusing DeepSeek, Alibaba and four other Chinese AI companies of systematically stripping capabilities from Claude, ChatGPT, Gemini and Grok.
On September 8, the FBI, the NSA and the Cybersecurity and Infrastructure Security Agency published a joint advisory, numbered AA26-251A, naming DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI as the companies behind what the agencies called "aggressive, malicious, and targeted" distillation campaigns running since at least late 2024. The agencies say the six firms extracted billions of tokens across millions of exchanges with frontier American models, and that Beijing was likely aware the whole time.
This isn't the government explaining a technical concept. It's naming names.
Distillation itself is not illegal. It's not new. Training a smaller model on a bigger one's outputs is standard practice at every major lab, including the American ones now crying foul. What the advisory alleges is different: DeepSeek allegedly queried four separate versions of Claude, two versions of Gemini, five versions of ChatGPT and Grok 4 to generate synthetic training data for its R1 and R3 models, according to the CISA advisory. MiniMax, per the same document, spent late 2025 pulling chain-of-thought reasoning and reinforcement learning signals - plus software engineering capability itself - straight out of Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro and Gemini 3 Pro to build its M2 model.
The mechanism matters here, because it's the whole case. Providers like Anthropic, OpenAI, Mistral and xAI all ban this kind of high-volume extraction in their terms of service. That clause, not any copyright statute, is the actual legal hook behind the accusation. According to CyberScoop's reporting on the advisory, the Chinese firms routed their requests through native APIs and remote cloud providers, often via third-party aggregators that scrub user metadata - making the traffic harder to trace back to its source.
AI Model Distillation Becomes the New Battleground Between the US and China A White House official has accused China's Moonshot AI of building its new Kimi K3 model by distilling Anthropic's Fable, the latest flashpoint in a widening dispute over AI model distillation. OpenAI and Anthropic have separately accused DeepSeek, Moonshot, and MiniMax of extracting capabilities from US models through millions of queries, and... - how to distill AI models cheaply - US China AI model competition regulations
The Labs Said This First #
The joint advisory formalizes something Anthropic, OpenAI and Google had already been saying on their own.
Back in February, all three published evidence of what they described as systematic extraction campaigns targeting their frontier models. OpenAI went further. It sent Washington an open letter describing activity it called "indicative of ongoing attempts by DeepSeek to distill frontier models of OpenAI and other US frontier labs, including through new, obfuscated methods," as CNBC reported at the time.
What's changed is that the claim now carries the FBI's signature, not just a startup's blog post.
Not everyone buys the framing. Microsoft CEO Satya Nadella has pointed out, in comments covered by The Decoder, that the same labs banning distillation in their terms of service built their own models by training on data scraped from across the internet, largely without asking. It's a fair jab. But it misses the point the agencies are making. Nobody disputes that DeepSeek's queries violated Anthropic's and OpenAI's contracts. The real question is bigger: does that contract violation, at this scale and with apparent state awareness, amount to a national security matter, or just a business dispute?
A Genuine Reframe #
DeepSeek's R1 was treated, when it launched, as proof that a lean Chinese lab could match American frontier labs on a fraction of the compute budget. That story just took a hit. For anyone trying to make sense of the open-weight Chinese models flooding Hugging Face this year, this advisory is a genuine reframe. The government's version of events suggests a chunk of that gap wasn't some independent leap in efficiency. It was closed by querying the American labs' own models millions of times.
It also raises the stakes for anyone building on top of these models. If US labs start enforcing their terms of service more aggressively, rate limits and licensing terms for API access could tighten across the board, not just for accounts flagged as suspicious. That's the real cost. Pricing and access to Claude, GPT, Gemini and Grok could get stricter simply because six Chinese firms allegedly abused the open door, and that's a bigger problem for American startups than any policy fight in Washington.
None of the six named companies has publicly responded to the advisory. Neither DeepSeek nor Alibaba has a track record of engaging with U.S. government accusations, and there's no indication either intends to start now.
Trump Meets AI Giants While Senate Democrats Call His AI Policy Unpredictable The White House met with OpenAI, Anthropic, Google and Meta on a new AI safety framework this week, while Senate Democrats accused the administration of unpredictable AI governance and officials flagged cheap Chinese models like DeepSeek and Qwen as a growing security risk. Founders and investors are now pricing in both risks at once. - Trump AI safety framework pilot - Senate Democrats criticize Trump AI policy
Also read: How Does Prompt Caching Work for LLMs, and Why It Cuts Bills in Half • Pony.ai's CEO Says Robotaxi Tech Is Solved, Only Regulators Stand in the Way • AI Data Centers Have Doubled Hard Drive and SSD Prices in a Year
This article is filed under AI News. Check it for more stories.
Join the discussion #
Open in the community → Almost there. Sign in and your reply posts straight away.