One Advisory, Six Companies, Four Model Families

The National Security Agency, the FBI and the Cybersecurity and Infrastructure Security Agency published a joint advisory on September 8 naming six Chinese AI companies for running industrial-scale distillation campaigns against American frontier models since late 2024. The advisory, filed as AA26-251A, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and says each extracted billions of tokens across millions of requests from Claude, GPT, Gemini and Grok models by posing as ordinary paying customers.

CompanyUS Models TargetedCampaign PeriodNotable Detail
DeepSeekClaude, GPT, Gemini, GrokSince late 2024Advisory calls its 5.6 million dollar cost claim misleading
Moonshot AIClaude Fable 5, GPT-4oSince mid-2025Extraction feeds Kimi-K3 and Kimi-K2 directly
AlibabaClaude, GPT-5Late 2025Targeted software engineering and customer-service skills
MiniMaxClaude reasoning and RL data2024 to 2026Also tried prompt injection against Claude Code
StepFunReasoning and coding capabilityLate 2025 to early 2026Named without a specific cost claim
Z.AIGPT-5.5, Claude OpusBy mid-2026Billions of tokens extracted

DeepSeek and Moonshot AI draw the most specific claims. The advisory states that DeepSeek's widely quoted 5.6 million dollar training cost is misleading, because it omits the cost of the data extracted through what the agencies call malicious distillation. Moonshot AI is accused of pulling Claude Fable 5 output to train its Kimi-K3 model and GPT-4o output to train Kimi-K2, both since mid-2025. MiniMax, beyond chain-of-thought extraction, is separately accused of attempting prompt injection against Claude Code.

The Playbook Washington Wants Providers to Break

The advisory's mitigation section reads as an instruction manual for the exact behavior it just described. It tells AI providers to track the ratio between what a customer pays for and how much the account actually uses, flagging accounts whose usage-to-subscription ratio looks industrial rather than individual. It recommends providers deliberately alter responses to suspected distillation traffic, through differential privacy noise or quietly downgrading which model actually answers a flagged account, and it points to the MITRE ATLAS framework for predictive adversarial detection and aggressive rate limiting.

For enterprises running their own agents against these APIs, the advice is narrower: watch for anomalous usage patterns, flag brand-new accounts that hit maximum usage immediately, and report suspicious activity to the FBI's Internet Crime Complaint Center. The agencies' own assessment is blunt: the scale and coordination across six separate companies point to state awareness, and likely a shared national development strategy rather than six firms independently arriving at the same tactic.

The Model Your Sovereignty Plan Picked Is on This List

Three of the six named companies make the open-weight models European institutions have adopted specifically to get away from US cloud dependency: Alibaba's Qwen, Moonshot AI's Kimi, and Z.AI's GLM are all models a company or public body can download and run on its own hardware, which is exactly why they show up in European sovereign-AI shortlists as an alternative to sending data to an American API. This advisory does not accuse those specific downloadable weights of anything on its own. What it does is put on the federal record, in a document any EU compliance officer can cite, that the companies building them ran systematic extraction campaigns against the same US labs those institutions were trying to reduce their dependence on.

That record lands next to an EU obligation that is no longer theoretical. Article 53 of the AI Act already requires every general-purpose AI provider, including open-source ones, to publish a public summary of what went into training their model, using the European Commission's own template, and the AI Office has had enforcement power over that requirement since August 2 2026, with fines running up to 15 million euro or 3 percent of global turnover. This does not settle whether any of the three vendors' required summaries account for data obtained by systematically querying a rival's paid API. It gives every EU procurement and compliance team a specific, government-sourced question to put in front of them before the next contract renewal.