The joint advisory, designated AA26-251A, alleges that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI systematically queried US frontier AI models to extract proprietary functionality including reasoning capability, software-engineering performance and agentic task execution, training their own systems on the outputs, activity the agencies say occurred likely with Chinese government awareness. The agencies describe tactics including proxy transfer stations used to bypass geographic access restrictions, prompt injection and jailbreak techniques aimed at extracting chain-of-thought reasoning that model providers do not intend to expose, and fraudulent accounts with obfuscated metadata spread across platforms and cloud providers to avoid detection. The advisory frames this as systematic extraction of proprietary capability threatening US technological leadership, rather than an incidental byproduct of publicly available AI services, and recommends that US frontier AI companies build detection systems, alter outputs served to suspected malicious accounts, and share intelligence across the industry. The advisory does not announce new sanctions or enforcement action against the named companies, and Chinese authorities have publicly disputed the US allegations as unfounded.
US · CN Cybersecurity and Data 10 Sept 2026
NSA, CISA and FBI Name Six Chinese AI Firms in Advisory on Frontier Model Distillation
The NSA, CISA and FBI alleged on September 8 that six China-based AI companies, including DeepSeek and Alibaba, have conducted industrial-scale knowledge-distillation campaigns since at least late 2024 to extract capabilities from US frontier models including Claude, GPT, Gemini and Grok. The advisory calls the activity a core strategy rather than a supplementary shortcut; China's government has publicly rejected the characterization.
Source: CISA, September 8, 2026
Comments
0 commentsNo comments yet — be the first.