U.S. Agencies Issue Stern Rebuke of China-Based AI Companies Over Alleged Distillation The U.S. National Security Agency, Cybersecurity and Infrastructure Security Agency, and FBI accused China-based AI companies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of conducting 'industrial-scale distillation campaigns' against U.S. frontier AI models, extracting billions of tokens since late 2024. The agencies allege the efforts were 'aggressive, malicious, and targeted,' and the statement comes ahead of U.S.-China AI safety talks scheduled for mid-September. The U.S. National Security Agency NSA , Cybersecurity and Infrastructure Security Agency CISA , and the FBI all released a statement on Tuesday https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a accusing China-based AI companies of “Industrial-Scale Distillation Campaigns Against U.S. AI Companies.” “Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024,” the statement alleges. It calls the efforts “aggressive, malicious, and targeted.” The timing lines up with a big U.S.-China meeting-of-the-minds happening soon. Reuters reported last week https://www.reuters.com/legal/litigation/us-china-gear-up-mid-september-ai-safety-dialogue-2026-09-04/ that sometime this month, Treasury Secretary Scott Bessent would meet with Chinese officials for talks on AI security. Distillation is a legitimate and widely-accepted technique in AI development. In distillation, a more powerful “teacher” model can confer the ability to generate more useful and accurate results to a smaller “student” model, resulting in a compressed, but effective model. But frontier AI labs like Anthropic historically go to great lengths https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks to prevent distillation of their models by other labs. “Illicitly distilled models lack necessary safeguards, creating significant national security risks,” Anthropic writes. Last year, OpenAI was at the vanguard of the fight against distillation, at one point telling the Financial Times it had gathered its own evidence https://www.ft.com/content/a0dfedd1-5255-4fa9-8ccc-1fe01de87ea6 that China-based DeepSeek had performed distillation against its wishes. But in his more recent statements about distillation, OpenAI CEO Sam Altman has started to sound less worried than his company’s past behavior suggested. “I would rather people not distill from us, for sure. But this is not in my top ten list of worries,” he said in a July interview. https://x.com/patrick oshag/status/2082104296175198361 Mentally time traveling to the dusty, forgotten past of two years ago is a fascinating exercise in this context. Dialing your DeLorean to 2024—the height of “plagiarism machine” discourse—you’ll find that OpenAI submitted testimony to the U.K. Parliament https://committees.parliament.uk/writtenevidence/126981/pdf/ saying, “Because copyright today covers virtually every sort of human expression—including blog posts, photographs, forum posts, scraps of software code, and government documents—it would be impossible to train today’s leading AI models without using copyrighted materials.”