cd /news/artificial-intelligence/fbi-nsa-and-cisa-accuse-six-chinese-… · home topics artificial-intelligence article
[ARTICLE · art-123938] src=startupfortune.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

FBI, NSA and CISA Accuse Six Chinese AI Firms of Stealing US Models

On September 8, the FBI, NSA, and CISA issued a joint advisory accusing DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI of conducting aggressive distillation campaigns that extracted billions of tokens from US frontier models like Claude, ChatGPT, Gemini, and Grok since late 2024. The advisory formalizes earlier accusations by Anthropic, OpenAI, and Google, and cites terms-of-service violations as the legal basis, while Microsoft CEO Satya Nadella has noted the irony of US labs complaining after training on scraped internet data.

by read5 min views4 publishedSep 8, 2026
FBI, NSA and CISA Accuse Six Chinese AI Firms of Stealing US Models
Image: Startupfortune (auto-discovered)

Three U.S. intelligence agencies just put their names on paper accusing DeepSeek, Alibaba and four other Chinese AI companies of systematically stripping capabilities from Claude, ChatGPT, Gemini and Grok.

On September 8, the FBI, the NSA and the Cybersecurity and Infrastructure Security Agency published a joint advisory, numbered AA26-251A, naming DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI as the companies behind what the agencies called "aggressive, malicious, and targeted" distillation campaigns running since at least late 2024. The agencies say the six firms extracted billions of tokens across millions of exchanges with frontier American models, and that Beijing was likely aware the whole time.

This isn't the government explaining a technical concept. It's naming names.

Distillation itself is not illegal. It's not new. Training a smaller model on a bigger one's outputs is standard practice at every major lab, including the American ones now crying foul. What the advisory alleges is different: DeepSeek allegedly queried four separate versions of Claude, two versions of Gemini, five versions of ChatGPT and Grok 4 to generate synthetic training data for its R1 and R3 models, according to the CISA advisory. MiniMax, per the same document, spent late 2025 pulling chain-of-thought reasoning and reinforcement learning signals - plus software engineering capability itself - straight out of Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro and Gemini 3 Pro to build its M2 model.

The mechanism matters here, because it's the whole case. Providers like Anthropic, OpenAI, Mistral and xAI all ban this kind of high-volume extraction in their terms of service. That clause, not any copyright statute, is the actual legal hook behind the accusation. According to CyberScoop's reporting on the advisory, the Chinese firms routed their requests through native APIs and remote cloud providers, often via third-party aggregators that scrub user metadata - making the traffic harder to trace back to its source.

AI Model Distillation Becomes the New Battleground Between the US and China A White House official has accused China's Moonshot AI of building its new Kimi K3 model by distilling Anthropic's Fable, the latest flashpoint in a widening dispute over AI model distillation. OpenAI and Anthropic have separately accused DeepSeek, Moonshot, and MiniMax of extracting capabilities from US models through millions of queries, and... - how to distill AI models cheaply - US China AI model competition regulations

The Labs Said This First #

The joint advisory formalizes something Anthropic, OpenAI and Google had already been saying on their own.

Back in February, all three published evidence of what they described as systematic extraction campaigns targeting their frontier models. OpenAI went further. It sent Washington an open letter describing activity it called "indicative of ongoing attempts by DeepSeek to distill frontier models of OpenAI and other US frontier labs, including through new, obfuscated methods," as CNBC reported at the time.

What's changed is that the claim now carries the FBI's signature, not just a startup's blog post.

Not everyone buys the framing. Microsoft CEO Satya Nadella has pointed out, in comments covered by The Decoder, that the same labs banning distillation in their terms of service built their own models by training on data scraped from across the internet, largely without asking. It's a fair jab. But it misses the point the agencies are making. Nobody disputes that DeepSeek's queries violated Anthropic's and OpenAI's contracts. The real question is bigger: does that contract violation, at this scale and with apparent state awareness, amount to a national security matter, or just a business dispute?

A Genuine Reframe #

DeepSeek's R1 was treated, when it launched, as proof that a lean Chinese lab could match American frontier labs on a fraction of the compute budget. That story just took a hit. For anyone trying to make sense of the open-weight Chinese models flooding Hugging Face this year, this advisory is a genuine reframe. The government's version of events suggests a chunk of that gap wasn't some independent leap in efficiency. It was closed by querying the American labs' own models millions of times.

It also raises the stakes for anyone building on top of these models. If US labs start enforcing their terms of service more aggressively, rate limits and licensing terms for API access could tighten across the board, not just for accounts flagged as suspicious. That's the real cost. Pricing and access to Claude, GPT, Gemini and Grok could get stricter simply because six Chinese firms allegedly abused the open door, and that's a bigger problem for American startups than any policy fight in Washington.

None of the six named companies has publicly responded to the advisory. Neither DeepSeek nor Alibaba has a track record of engaging with U.S. government accusations, and there's no indication either intends to start now.

Trump Meets AI Giants While Senate Democrats Call His AI Policy Unpredictable The White House met with OpenAI, Anthropic, Google and Meta on a new AI safety framework this week, while Senate Democrats accused the administration of unpredictable AI governance and officials flagged cheap Chinese models like DeepSeek and Qwen as a growing security risk. Founders and investors are now pricing in both risks at once. - Trump AI safety framework pilot - Senate Democrats criticize Trump AI policy

Also read: How Does Prompt Caching Work for LLMs, and Why It Cuts Bills in HalfPony.ai's CEO Says Robotaxi Tech Is Solved, Only Regulators Stand in the WayAI Data Centers Have Doubled Hard Drive and SSD Prices in a Year

This article is filed under AI News. Check it for more stories.

Join the discussion #

Open in the community → Almost there. Sign in and your reply posts straight away.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @fbi 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/fbi-nsa-and-cisa-acc…] indexed:0 read:5min 2026-09-08 ·