Policy

US Names Six Chinese AI Firms in Model Distillation Crackdown

NSA, CISA, and FBI detail industrial-scale attacks on Claude, GPT, Gemini, and Grok, urging American companies to secretly degrade service for suspected bad actors.

Omega Editorial· September 9, 2026· 3 min read

US Intelligence Agencies Detail Systematic AI Model Theft

The National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation publicly identified six Chinese AI companies allegedly conducting large-scale attacks to extract capabilities from leading American AI models. In a joint statement released Tuesday, the agencies named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as firms that have been targeting US models since late 2024.

According to the agencies, these companies have distilled capabilities from variants of Claude, GPT, Gemini, and Grok, potentially saving billions in development costs while compressing timelines for creating competitive models. The statement suggests the firms likely acted with Chinese government awareness.

The attacks exploit API access through bulk purchases of fake accounts that execute coordinated queries—sometimes numbering in the millions—on similar topics. Chinese firms also employ prompt injection techniques to jailbreak models, including forcing systems to reveal hidden chain-of-thought reasoning by instructing them to articulate internal logic step by step.

Controversial Defense Recommendations

The agencies outlined mitigation strategies that could significantly affect legitimate users. They recommend that US AI firms secretly switch suspected attackers to inferior models without notification, subtly degrade response quality by altering reasoning or adding stylistic inconsistencies, and strengthen identity verification across all accounts.

These measures present technical challenges. The agencies acknowledge that Chinese firms deploy automated systems capable of detecting when a superior model becomes available and switching within 24 hours. They also use quality assurance tools that can distinguish between ordinary service issues and intentional output degradation.

The guidance raises privacy concerns for legitimate users, who might find themselves downgraded to less capable models or experience withheld capabilities without explanation. The agencies suggest firms should balance security with user experience while accepting that some trade-offs may be inevitable, though they recommend informing AI safety researchers and third-party evaluators of model changes.

Specific Allegations Against Named Firms

DeepSeek allegedly conducted extensive distillation on multiple US models to extract specialized training data and capabilities including agentic functions, writing optimization, and chain-of-thought reasoning. Moonshot AI reportedly switched between models from leading American firms to copy fine-tuning techniques, reinforcement learning, and software engineering capabilities.

Alibaba, MiniMax, StepFun, and Z.AI appeared focused on copying particular models from Anthropic and OpenAI, according to the statement. The agencies characterized stolen capabilities as forming the core—not merely a supplement—of China's AI development strategy.

Why It Matters

This represents the Trump administration's most detailed accusation yet in an escalating technology conflict. The recommended defenses could fundamentally alter how AI companies verify users and deliver services, potentially degrading experiences for paying customers caught in broad security sweeps. The approach also tests whether competing American firms can coordinate on shared threats while maintaining commercial rivalries. With a meeting between President Trump and Chinese President Xi Jinping scheduled for September 24, these allegations add technical specifics to broader geopolitical tensions over AI leadership.

China Rejects Claims

Chinese Ministry of Foreign Affairs spokesperson Mao Ning called the accusations groundless on Wednesday, characterizing China's AI progress as the result of scientific self-reliance. A Chinese Embassy spokesperson accused the US of operating a smear campaign rooted in prejudice, while the People's Daily noted that many American AI companies have used Chinese models for distillation and that US startups seek access to more affordable Chinese alternatives.

China warned it will take necessary measures in response to actions causing material harm to its interests. The statement comes as China's Ministry of Industry and Information Technology released plans to sharply expand the country's intelligent computing capacity over the next five years.

These details were first reported by Ars Technica.

#ai security#model distillation#deepseek#us-china tech#nsa#cybersecurity

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Policy

Policy· 3 min read

AI-Generated Political Ads Erode Voter Trust in 2026 Campaigns

Synthetic campaign content creates new challenges for discerning truth, even when voters recognize manipulation.

Via AI Watch · Sep 9, 2026
Policy· 4 min read

Agentic AI Demands New Accountability Model Beyond Cloud Security

As AI systems take autonomous actions across business processes, the industry must define who can stop them, prove what happened, and pay when things go wrong.

Via AI Watch · Sep 9, 2026
Policy· 3 min read

California Launches AskCA, AI Assistant for State Services

Governor Newsom's pilot program uses Anthropic's Claude model to help residents navigate 200+ state agencies starting October 1.

Via AI Watch · Sep 9, 2026