A Playbook for Quietly Making AI Worse
The National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI jointly told American AI companies on September 8 to secretly degrade service for accounts they suspect of stealing their models, rather than block them outright. The joint advisory, alert AA26-251A, names six China-based companies - DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI - and accuses them of running organized campaigns since late 2024 to extract capabilities from Claude, GPT, Gemini and Grok through what the industry calls distillation: training a cheaper model to copy a stronger one's outputs. The agencies say the campaigns pulled billions of tokens across millions of queries and were likely carried out with the knowledge of the Chinese government, using fraudulent accounts, bulk premium subscriptions shared across teams of developers, and a gray market of API proxies the advisory calls transfer stations.
The advisory builds on ground Anthropic had already covered. In a report published February 23, 2026, the company said it caught DeepSeek, Moonshot and MiniMax running campaigns that generated more than 16 million exchanges with Claude through roughly 24,000 fraudulent accounts, routed through commercial proxies because Anthropic does not sell Claude access inside China for export-control reasons. Anthropic caught one of the three labs still mid-campaign and, when it shipped a new model days later, watched the same operation redirect nearly half its traffic to the new release within 24 hours - a live look at how fast a distillation campaign adapts once it is already inside a provider's usage logs.
The Detection Signal Is Also a Growth Story
The advisory tells providers to watch for three things: subscription-to-usage ratios that look too high for the plan, immediate maximum usage from brand-new accounts, and enterprise-scale throughput patterns. None of those three signals is unique to theft. A European software company that signs an enterprise contract and migrates a full production pipeline in its first week produces the same shape in the logs as a distillation account working through its target list, and so does a startup whose proof-of-concept suddenly goes live during a launch weekend.
| Signal in the advisory | What it also matches |
|---|---|
| Subscription-to-usage ratio too high for the tier | A small team on one enterprise seat, running batch jobs |
| Immediate maximum usage from a new account | Day-one migration of an existing pipeline to a new vendor |
| Enterprise-scale throughput patterns | A product launch or a sudden spike in customer demand |
The advisory does not describe a way for a provider to tell the two apart before acting - it recommends acting on high-confidence matches, but confidence is built from exactly these usage-shape signals, not from proof of who is on the other end of the account.
Told Not to Tell You
The advisory's most consequential line is not about detection - it is about what happens after a provider decides an account looks suspicious. Providers are told to alter what a flagged account receives - reducing reasoning depth, presenting correct information through different reasoning, or introducing stylistic inconsistencies - while avoiding changes obvious enough to trigger alarm. The advisory is explicit that the account should not be told: informing a suspected distiller of a downgrade would let it improve its evasions and know when to stop. Nowhere in the published text is there a carve-out for the case where the account is not a distiller at all.
That silence is the point of the design, not an oversight - a provider that explained every downgrade would hand real distillers a map of what trips the alarm. But the same silence means a European business flagged by mistake has no signal that anything changed, no channel to dispute it, and no way to distinguish a policy-driven downgrade from ordinary model drift or a bad day on the API. An SLA promises uptime and latency; nothing in a standard enterprise AI contract today promises that the model behind the endpoint hasn't been quietly told to think less carefully about your queries.
What This Changes for a Company Scaling on AI
A company that expects to ramp AI usage fast - a migration, a launch, a new integration going from pilot to production in days - now has a reason to keep its own record of that ramp before it happens, not after something looks wrong. Documented reasons for a usage spike (a signed contract date, a deployment ticket, a support conversation with the vendor about scaling up) are the only evidence a customer will have if answer quality quietly degrades during exactly the window the advisory's own signals would flag. The advisory was written to catch a real, serious campaign of industrial-scale theft against American AI companies. It was not written with a European enterprise customer's audit trail in mind, and right now, nothing requires it to be.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: DeepSeek Adds Vision to V4-Flash, Nears Opus 4.8 | No Human Chose the Exploit, CISA Sets 2 Days



