- The NSA, FBI, and CISA issued a joint advisory Tuesday formally accusing six Chinese AI companies — DeepSeek, Moonshot AI (Kimi), Alibaba, MiniMax, StepFun, and Z.AI — of using AI distillation techniques “at an industrial scale” since at least 2024 to extract proprietary knowledge from US AI models, detailing specifically which US systems each Chinese company distilled and for what purposes (improving math reasoning, code review capabilities, and other benchmarks).
- The advisory went further than prior accusations by stating the Chinese firms “route distillation requests through multiple pathways to gain unauthorized access” in deliberate violation of US companies’ terms of service, and that the activity is likely occurring “with knowledge of the Chinese government” — a designation that frames IP theft as state-sponsored economic espionage rather than corporate misconduct.
- The advisory lands weeks before President Trump is scheduled to host Chinese President Xi Jinping in Washington for a high-stakes summit, immediately complicating bilateral preparations and creating pressure on the administration to signal consequences — Treasury Secretary Bessent had already warned in July of potential sanctions for Chinese firms engaging in IP theft.
- US AI developers are advised to take “immediate action” including altering their models’ responses to suspected distillation attempts and sharing intelligence on distillation campaigns with each other — a call for coordinated industry-level defense that has no clear enforcement mechanism and may prove difficult to implement given competitive dynamics between American AI labs.
What Happened?
Three US security agencies — the NSA, FBI, and CISA — jointly published an advisory Tuesday formally accusing six Chinese AI firms of systematically using “distillation” to steal proprietary AI capabilities from US companies. Distillation is a technique where a smaller model is trained using outputs from a more capable model; it is legitimate when a developer uses their own models, but constitutes IP theft when done without authorization to access and exploit another company’s model. The advisory specified that Chinese firms routed requests through multiple pathways to evade detection and bypass US AI companies’ terms of service. Anthropic publicly accused Alibaba of large-scale illicit access to its Claude model via thousands of fraudulent accounts in June; Tuesday’s advisory formalizes and extends those accusations across six named firms.
Why It Matters?
This is the US government’s most direct and specific accusation of AI-sector economic espionage to date. The detail level — naming specific companies, specific targets, specific purposes — signals that US intelligence agencies have significant visibility into Chinese AI development pipelines and are prepared to use that visibility publicly. For the named Chinese companies, the advisory creates significant reputational and regulatory risk: formal designation as IP thieves by the NSA and FBI sets the legal foundation for sanctions, export controls, or market access restrictions. For US AI companies, the advisory validates what OpenAI and Anthropic have been saying privately for months and creates pressure for both defensive measures and policy responses. The summit timing is particularly significant: naming Chinese companies at state-actor level just before a Xi visit is either deliberate pressure or a security disclosure that the White House failed to delay — either reading is significant.
What’s Next?
The immediate policy question is what consequences follow the advisory. Bessent’s July warning about sanctions gives the administration a pre-stated tool; whether it’s deployed depends partly on how the Trump-Xi summit goes and whether the Chinese government responds to the advisory with cooperation, defiance, or counter-accusations. US lawmakers considering legislation to penalize Chinese AI distillation may use the advisory as justification to accelerate those efforts. For the named companies, stock impact will be most direct for Alibaba (US-listed, BABA) and others with international exposure. The longer-term implication is that the AI competition between the US and China is now explicitly a national security matter in both governments’ framing — making commercial decoupling of AI supply chains increasingly likely regardless of summit outcomes.
Source: Bloomberg












