The US authorities NSA, CISA, and FBI accuse six Chinese AI companies in a joint security warning of copying US leading models on an industrial scale. The warning from September 8 names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI and estimates the outflow at billions of tokens over millions of requests since the end of 2024. China rejects the allegations.
Advisory names methods and affected models
The warning published as AA26-251A describes so-called distillation: companies extract the response behavior of foreign models through massive queries to train their own systems. Several variants of Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini, and xAI’s Grok are affected. The six mentioned companies allegedly used fake user accounts, mass-purchased premium subscriptions, and disguised proxy services, which the authorities refer to as “transfer stations.” Individual campaigns reportedly ran for days to months and included thousands to millions of requests per knowledge domain. The campaign attributed to DeepSeek reportedly dates back to at least the end of 2024 and is thus considered one of the longest-running. Specific token and campaign numbers for each individual company are independently unverified. As an example, the warning additionally mentions Alibaba: the company allegedly used responses from Claude 4, Claude Opus, Claude Sonnet, and GPT-5 at the end of 2025 to improve the programming capabilities, customer dialogue, and image and character creation of its Qwen model family. According to the advisory, the campaigns not only formed a supplement but the core of the AI development strategy of the mentioned companies.
Moonshot case receives official confirmation
Already in July, a White House advisor accused Moonshot AI of developing its model Kimi K3 through distillation of Anthropic’s Fable – the company denied this at the time, citing only fifteen days between the launch of Fable and K3. The new advisory now confirms the case with technical details at the agency level: Kimi K3 is said to originate from Fable versions, while the older model Kimi K2 comes from responses of GPT-4o. Unlike the former government advisor, NSA, CISA, and FBI now speak together and with technical evidence – a step that elevates the allegations from a political statement to an official security warning. Similar disputes had previously occurred between Anthropic and Alibaba regarding Claude Code, where hidden tracking code was supposed to identify Chinese users while Alibaba simultaneously prohibited its employees from using the tool. The new warning now officially integrates both cases into a larger pattern that is operated with the knowledge of the Chinese government.
Beijing rejects allegations
China rejects the allegations. Foreign Ministry spokesperson Mao Ning stated literally: “We reject unfounded accusations,” and referred to technological independence as the basis of Chinese AI development. The ministry instead called for increased cooperation between both countries. The named companies themselves initially did not respond to press inquiries. The warning comes a few weeks before planned talks in September between the government of Donald Trump and China’s head of state and party Xi Jinping, where AI governance is expected to be a topic. The authorities also recommend that affected US providers monitor suspicious account patterns and query ratios, deliberately alter responses to alleged distillation attempts, and share insights across providers. For IT managers in companies, this primarily means one thing: access to Chinese AI services could be more strictly scrutinized or additionally documented in the coming months if US providers implement the recommendations.
It will be crucial whether concrete consequences follow from the warning – such as new export restrictions or entries on US trade lists – or whether it remains a political gesture for now. So far, neither the US Department of Commerce nor the State Department has announced plans to impose sanctions on the advisory. It also remains open how US providers will technically implement the recommended targeted response distortion without unfairly disadvantaging regular users from China.


