NSA, FBI and CISA accuse six Chinese AI firms of industrial-scale distillation
The Tuesday advisory named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and listed Claude, GPT, Gemini and Grok as targets. Scott Bessent put sanctions and Entity List designations on the table. Beijing called the claims baseless.

Washington2 min read
Last updated
Three U.S. agencies said on Tuesday that Chinese artificial-intelligence companies have been running industrial-scale distillation campaigns against American frontier models since at least late 2024. The joint advisory from the National Security Agency, the Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The U.S. systems listed as targets were Anthropic's Claude, OpenAI's GPT family, Google's Gemini and xAI's Grok, the last of them attributed in the advisory to SpaceXAI.
Distillation, in this use, means training a cheaper model on the outputs of a more capable one. U.S. labs do it internally. The agencies' charge is that the six firms used millions of queries, routed through proxies they called transfer stations, to pull restricted functions out of models they were not licensed to copy at that depth. The advisory said the work was done "likely with Chinese government awareness" and that the method was "the core, not merely a supplement" of how those companies build.
The document went firm by firm. Alibaba is accused of distilling Claude and GPT-5 in late 2025 to improve the Qwen line. MiniMax of taking chain-of-thought and reinforcement-learning traces and of trying prompt injection against Claude Code. StepFun of lifting reasoning and coding skill across late 2025 and early 2026. Z.AI of extracting billions of tokens from GPT-5.5 and Claude Opus by mid-2026. Moonshot's Kimi line and DeepSeek's models sit in the same charge sheet. Treasury Secretary Scott Bessent wrote on X that when Chinese firms run covert, industrial-scale distillation that crosses into intellectual-property theft, "sanctions and Entity List designations will be on the table."
China's commerce ministry said on Wednesday that the allegations lacked facts and law, accused Washington of double standards, and said the United States was interfering in ordinary commercial work to suppress competition. The foreign ministry told the United States to stop unfounded accusations. Distillation is a standard training method. The fight is over volume, disguise and terms of use. American labs already restrict high-volume extraction in their contracts. The agencies say the Chinese firms evaded geographic blocks and those contracts by splitting requests across many accounts and jurisdictions.
The timing is not quiet. Xi Jinping is due in the United States later this month. Officials have also planned an AI-safety dialogue for mid-September. An advisory that names six companies and four model families two weeks before those meetings puts a police document on the same table as a summit photo. It also lands in the same week that India hosts BRICS and that Washington is sinking Iranian tankers. The AI file and the war file are separate. The diplomatic calendar is not.
What the advisory does not do is publish packet captures or name the transfer-station operators. What it does do is give U.S. firms a government letter they can take to their own abuse desks, and give the Commerce Department a public predicate for Entity List work. Chinese firms can answer with technical papers showing independent training runs. Until one side releases the underlying logs, the public argument will stay at the level of adjectives: malicious on one shore, baseless on the other. The models will keep answering queries in the meantime, which is how distillation works.