# Intelligence agencies warn of China’s large-scale AI model distillation efforts

> Source: <https://www.nextgov.com/artificial-intelligence/2026/09/intelligence-agencies-warn-chinas-large-scale-ai-model-distillation-efforts/415851/>
> Published: 2026-09-08 21:52:00+00:00

# Intelligence agencies warn of China’s large-scale AI model distillation efforts

## Three agencies issued a joint statement warning that Chinese companies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI have used the tactics to extract billions of tokens from U.S. models.

Three federal national security and intelligence agencies issued a [joint advisory](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a?utm_source=ChinaAICompaniesDistillation&utm_medium=GovDelivery) on Tuesday warning U.S. artificial intelligence developers that their Chinese counterparts are targeting American-made models with distillation campaigns, where one model queries a larger, more advanced model to learn from it.

The National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation specified that Chinese companies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI used “aggressive, malicious, and targeted distillation” tactics to extract billions of tokens from the exchanges within U.S. frontier AI models, likely with Chinese government awareness, since 2024.

“China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use,” the advisory said. “These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection.”

Leading models, including variants of Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini and SpaceXAI’s Grok, were all listed as targeted models.

While AI model distillation is a legitimate and useful training technique used to save costs and reduce development timelines, adversarial companies can use it to steal intellectual property.

“China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection,” the advisory said. “They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership.”

The agencies recommended three remediating steps for U.S. AI developers: implement comprehensive detection and mitigation; deploy targeted response changes; and establish cross-organization intelligence sharing.

White House Office of Science and Technology Director Michael Kratsios in July [called out](https://www.nextgov.com/artificial-intelligence/2026/07/white-house-accuses-chinese-ai-developer-ip-theft/414948/) Chinese distillation efforts — specifically on the part of Moonshot AI — that have sought to steal proprietary functions from Anthropic’s advanced Fable model. Anthropic made [the same accusations in February](https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks).

Advocacy groups have also requested the White House take stronger action to ban the sale of AI system components, [specifically semiconductor chips](https://www.nextgov.com/artificial-intelligence/2026/04/experts-call-halt-ai-chip-exports-china-after-white-house-distillation-warning/413132/), to China.
