cd /news/ai-policy/u-s-agencies-issue-stern-rebuke-of-c… · home topics ai-policy article
[ARTICLE · art-124305] src=gizmodo.com ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

U.S. Agencies Issue Stern Rebuke of China-Based AI Companies Over Alleged Distillation

The U.S. National Security Agency, Cybersecurity and Infrastructure Security Agency, and FBI accused China-based AI companies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of conducting 'industrial-scale distillation campaigns' against U.S. frontier AI models, extracting billions of tokens since late 2024. The agencies allege the efforts were 'aggressive, malicious, and targeted,' and the statement comes ahead of U.S.-China AI safety talks scheduled for mid-September.

by read2 min views3 publishedSep 9, 2026
U.S. Agencies Issue Stern Rebuke of China-Based AI Companies Over Alleged Distillation
Image: Gizmodo (auto-discovered)

The U.S. National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the FBI all released a statement on Tuesday accusing China-based AI companies of “Industrial-Scale Distillation Campaigns Against U.S. AI Companies.”

“Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024,” the statement alleges. It calls the efforts “aggressive, malicious, and targeted.”

The timing lines up with a big U.S.-China meeting-of-the-minds happening soon. Reuters reported last week that sometime this month, Treasury Secretary Scott Bessent would meet with Chinese officials for talks on AI security.

Distillation is a legitimate and widely-accepted technique in AI development. In distillation, a more powerful “teacher” model can confer the ability to generate more useful and accurate results to a smaller “student” model, resulting in a compressed, but effective model. But frontier AI labs like Anthropic historically go to great lengths to prevent distillation of their models by other labs. “Illicitly distilled models lack necessary safeguards, creating significant national security risks,” Anthropic writes.

Last year, OpenAI was at the vanguard of the fight against distillation, at one point telling the Financial Times it had gathered its own evidence that China-based DeepSeek had performed distillation against its wishes. But in his more recent statements about distillation, OpenAI CEO Sam Altman has started to sound less worried than his company’s past behavior suggested. “I would rather people not distill from us, for sure. But this is not in my top ten list of worries,” he said in a July interview.

Mentally time traveling to the dusty, forgotten past of two years ago is a fascinating exercise in this context. Dialing your DeLorean to 2024—the height of “plagiarism machine” discourse—you’ll find that OpenAI submitted testimony to the U.K. Parliament saying, “Because copyright today covers virtually every sort of human expression—including blog posts, photographs, forum posts, scraps of software code, and government documents—it would be impossible to train today’s leading AI models without using copyrighted materials.”

── more in #ai-policy 4 stories · sorted by recency
── more on @nsa 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/u-s-agencies-issue-s…] indexed:0 read:2min 2026-09-09 ·