The Cybersecurity and Infrastructure Security Agency, National Security Agency and Federal Bureau of Investigation issued a joint advisory on September 8, 2026, warning that China-based artificial intelligence companies have targeted U.S. AI companies in systematic knowledge distillation campaigns. The agencies allege that six companies extracted billions of tokens through millions of exchanges or requests involving U.S. frontier AI models since at least late 2024.

The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and says the affected models included variants of Claude, GPT, Gemini and Grok. It characterizes the activity as occurring likely with Chinese government awareness and as forming the core of China’s AI development strategy.

Knowledge distillation trains a less capable AI model using outputs from a larger, more capable model. The agencies acknowledge that it is a valid machine-learning method, but say it can be misused to acquire competitors’ capabilities in less time and at lower cost than developing them legitimately. According to the advisory, the tactics violated the U.S. companies’ terms of service, shortened research and development for the China-based companies, and undermined fair competition.

CISA Acting Director Nick Andersen urged AI companies to take immediate steps to protect their platforms, saying the campaigns threaten to narrow the gap created by advances at American companies. The advisory calls for three immediate actions by U.S. frontier AI companies:

  • Implement comprehensive detection and mitigation for anomalous or malicious prompts, accounts, networks and behaviors, while monitoring subscription-to-usage ratios, immediate maximum usage from new accounts and enterprise-scale throughput patterns.
  • Deploy targeted response changes by subtly altering responses to suspected malicious distillation attempts, reducing the potential benefit from industrial-scale campaigns.
  • Establish intelligence sharing across model providers, cloud platforms and API aggregators to identify activity distributed across multiple organizations.

The advisory presents the recommendations as urgent defensive measures for companies operating frontier models. Its focus is on detecting coordinated use patterns, limiting the value of suspected extraction attempts and combining information held by different service providers to expose campaigns that may not be visible to any single organization.