The September 8 joint NSA, CISA and FBI advisory changes the evidence available to AI buyers: the allegations now appear in a government cybersecurity advisory with named companies and detection guidance. A buyer should ask for model-specific provenance and contractual answers. An API operator should review correlated account behavior. Neither decision is answered by treating the named-model list as an automatic ban.
This article uses the NSA release and the linked joint advisory, AA26-251A, read September 9, 2026. The agencies’ attributions remain their claims; we have not independently established the underlying campaigns.
- 01The source has changed.A joint government advisory adds an institutional assessment to earlier lab-issued accusations.
- 02Ask about the model you use.A company-level allegation is not a complete licence, deployment or suitability assessment.
- 03Monitor combinations of signals.High usage alone is not enough to identify malicious distillation.
- 04Keep provenance and data handling separate.Self-hosting and a permissive licence do not answer every question about how a model was trained.
01 — Practical decisionWhich companies the advisory names #
The advisory attributes high-volume distillation campaigns to six China-based companies, with activity across the group since at least late 2024. It describes extracting outputs and capabilities from US frontier models, including Claude, GPT, Gemini and Grok variants. The table summarizes the agencies’ attribution sections; it does not extend the allegations to every version or deployment sold by each company.
| Joint advisory , attribution section and Table 1, September 2026; read September 9, 2026. These are agency attributions, not our independent findings. | |
|---|---|
| Company | What the advisory attributes |
| --- | --- |
| DeepSeek | Organized extraction of specialized data and reasoning capabilities for R1 and V3. |
| Moonshot AI | Campaigns targeting reasoning, software engineering and mathematics; the text names Kimi-K2 and Kimi-K3. |
| Alibaba | Distillation to improve Qwen-family capabilities, including software engineering and dialogue. |
| MiniMax | Extraction of reasoning and development capabilities to improve M2. |
| StepFun | Distillation to improve Step 4 coding and agentic functions. |
| Z.AI | Extraction of GPT-5.5 and Claude Opus 4.8 data for reasoning capabilities. |
Joint advisory, attribution section and Table 1, September 2026; read September 9, 2026. These are agency attributions, not our independent findings.
Earlier coverage of Anthropic’s DeepSeek, Moonshot and MiniMax allegations, the Alibaba campaign allegation and the OSTP Moonshot accusation provides the chronology. The new reader decision is how to incorporate the joint advisory into supplier review and product monitoring.
02 — Practical decisionWhat the proxy mechanism means #
Knowledge distillation uses outputs from one model to help train another. The NSA release recognizes that this can be a legitimate research technique. The advisory concerns activities it describes as unauthorized, industrial-scale extraction, including evasion of provider restrictions and terms.
The advisory describes a gray market of API proxies called “transfer stations,” used to obscure the route to the underlying model and bypass regional restrictions. It also describes distributed requests across native APIs, clouds, aggregators, relays and account pools. The important defensive implication is that one visible account or endpoint may reveal only part of a coordinated pattern.
A buyer should distinguish those alleged extraction routes from its own inference route. Using an authorized hosting provider does not establish the provenance of the model’s training data. Conversely, a model’s provenance question does not establish that your current hosting provider is carrying out the described activity. Record both relationships instead of collapsing them into a single vendor label.
This distinction also helps supplier conversations. Ask who provides the weights, who operates inference, who receives prompts and who contractually answers for the service. The names may differ. A purchase order that only names the application wrapper can leave the underlying model decision undocumented.
03 — Practical decisionWhat buyers should ask before expanding use #
Start with a precise inventory: model name, version, source of the weights or endpoint, hosting arrangement and intended use. Match that inventory to the advisory’s actual claims. Do not assume that a later release is covered by a specific allegation about an earlier model, or that it is cleared because the advisory does not name it.
Ask the supplier what it can substantiate about training-data origin and authorized use of synthetic data. Ask which licence governs your use, which entity makes the contractual promises, and what support or remedy exists if a material provenance claim is challenged. Preserve answers alongside the model version and date; a generic sales assurance is hard to assess later.
Then evaluate task fitness separately. Test the safeguards, correctness and failure behavior your use case requires. The advisory raises provenance and security concerns, but it is not a substitute for a model-specific evaluation. Good task performance likewise does not resolve a provenance question.
The advisory itself is not a sanction, a procurement prohibition or a court determination about your licence. It does not settle all legal obligations that may apply to a particular organization or deployment. For a consequential purchase, give the actual model, contract and advisory to the people responsible for that decision rather than treating this article as legal advice.
A practical outcome can be a bounded continuation while a supplier answers, a restriction on a proposed new use, or selection of an alternative that satisfies the same acceptance criteria. The appropriate outcome depends on evidence and organizational requirements, not merely on whether a company appears in a headline.
04 — Practical decisionTurn the indicators into a monitoring checklist #
| Joint advisory , novel tactics and mitigations, pages 11–15; read September 9, 2026. Review questions are our operational interpretation. | ||
|---|---|---|
| Advisory signal | Question for the operator | Evidence to review |
| --- | --- | --- |
| Subscription-to-usage mismatch | Does activity fit the account’s declared use? | Plan, account history and actual consumption together. |
| Immediate maximum usage | Did a new account begin at sustained limits? | Onboarding time, request cadence and repeated quota exhaustion. |
| Enterprise throughput from individual accounts | Could several accounts form one operation? | Related activity across account pools and permitted infrastructure signals. |
| Correlated routes | Does behavior persist across access pathways? | Timing and request-pattern correlations across authorized telemetry. |
Joint advisory, novel tactics and mitigations, pages 11–15; read September 9, 2026. Review questions are our operational interpretation.
Use this as a triage checklist, not an automatic accusation rule. Legitimate batch processing, an evaluation launch or a newly migrated customer may also produce intense usage. Review the combination, the declared purpose and the account history before deciding that an incident has occurred. The advisory recommends stronger identity checks, rate and volume controls, monitoring and cross-organization correlation. It also discusses targeted response changes for high-confidence malicious extraction. Those response changes are a provider-level mitigation requiring careful evaluation; this article does not recommend silently degrading ordinary customer output because a single usage threshold was crossed.
For a smaller API product, a useful first step is to connect account-level telemetry with a documented review path. Assign an owner, retain evidence under your data policy and define how a false positive is corrected. Logging every prompt indefinitely is not an automatic requirement of this checklist.
05 — Practical decisionKeep the assessment tied to evidence #
Give the review a concrete closing condition. For procurement, that could be a supplier response addressing a named model and contractual question. For security operations, it could be an investigated cluster with a documented rationale for action or dismissal. A permanent status of concern does little to improve either decision.
Record what would reopen the review: a new advisory, a changed model version, a different hosting route or a materially changed contract. This prevents a one-time screening decision from becoming an unsupported assurance about every future deployment.
The most useful internal record is short: what you use, what the advisory says about it, what remains unanswered and who owns the next action. It should make the decision easier to inspect without reproducing a long history of public allegations.
06 — Next stepWhat to do next #
Ask specific questions and investigate correlated behavior.
Use the advisory to improve supplier evidence and API monitoring. Keep the agency attribution, the model’s licence, your data-handling arrangement and measured task fitness as separate inputs to the decision. That produces a more defensible outcome than either ignoring the advisory or converting it into a blanket ban. Our AI transformation services help teams define a useful pilot, evaluate its results and turn the findings into an implementation decision.