Senior US cyber and law-enforcement agencies have publicly accused a group of China-based artificial intelligence companies of systematically extracting proprietary capabilities from sophisticated American AI models. The agencies say the firms used a method known as distillation to train new models on the outputs of larger, more costly systems.
What the US agencies say
The statement, issued jointly by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), named five firms — DeepSeek, Moonshot AI, Alibaba, MiniMax and StepFun — as engaging in what it characterised as aggressive and targeted activity at scale. The agencies said this activity amounted to malicious copying of technology underpinning leading US frontier models.
"China-based AI companies are engaging in aggressive, malicious and targeted distillation activities at an industrial scale."
The agencies added that the allegations involve the use of model outputs from advanced systems to train lower‑cost substitutes — a process defenders describe as distillation. Distillation can reduce the expense and compute needed to build a competitive model by leveraging the behaviour of an existing, high-performing system rather than recreating its training process from scratch.
Companies named and the alleged technique
The advisory did not publish technical evidence in-depth in the public notice. It did, however, assert a pattern of behaviour across multiple China-based firms and suggested the activity occurred with likely awareness of the Chinese government, a point that escalates the allegation from commercial intellectual property theft to a matter of national strategic concern.
- Technique: Distillation — training smaller models on outputs from larger ones.
- Agencies: NSA, CISA, FBI.
- Firms named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun.
| Agency | Role |
|---|---|
| NSA | Signals and national security intelligence |
| CISA | Cyber and infrastructure security oversight |
| FBI | Law-enforcement and counterintelligence |
The advisory comes as the US prepares for high-level engagements with China. US officials flagged the allegation in the run-up to a planned late-September state visit by President Xi Jinping to the United States and ahead of a scheduled US–China dialogue on AI safety in mid-September.
Why this matters
Distillation is a legitimate technical technique widely used in research and commercial development to produce smaller, faster models. The difference the US agencies emphasise is one of intent and scale: when used to replicate protected capabilities without permission, distillation becomes a vehicle for appropriating intellectual property and potentially for bypassing export controls or safety mechanisms embedded in the original systems.
If substantiated, the agencies' claims have several consequences. They could prompt further legal and regulatory measures against accused companies, inform export and sanctions policy, and shape the terms of international talks on AI governance. For industry, the allegations underscore the tension between open scientific exchange and protecting commercial innovation in a field where model behaviour can be transferred across systems.
The public statement did not outline specific enforcement actions or immediate sanctions. Nor did it set out the technical evidence underpinning the accusations beyond describing the alleged method and naming the firms; that detail may be reserved for classified briefings or ongoing investigations.
Observers will watch whether the allegations alter the tenor of the forthcoming US–China discussions on AI safety and whether they trigger reciprocal claims or a diplomatic response from Beijing. For now, US authorities have framed the activities as both a cybersecurity and a law-enforcement concern, signalling that future responses could span policy, regulation and legal measures.
As governments and companies continue to wrestle with the dual pressures of competition and cooperation in AI, this advisory is a reminder that technical methods long accepted in research can become points of international contention when linked to commercial advantage and state interest.