US Federal Alert on “AI Model Distillation”: China Is Copying American AI Brains
Three of America’s top security agencies just sent out a warning. They say Chinese AI companies have been secretly copying the “brains” of top American AI systems. This includes tools like Claude, ChatGPT, Gemini, and Grok. The warning came out on September 8, 2026. It was a joint notice from the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the FBI.
What Is “Distillation,” in Simple Words?
To understand this story, you need to know one word: distillation.
Think of a smart teacher and a new student. The student asks the teacher many questions. The student writes down every answer. Over time, the student learns to think and answer almost like the teacher, without doing all the hard original work.
In AI, this is called distillation. A smaller, newer AI model sends huge numbers of questions to a bigger, more advanced AI model. It studies the answers closely. Slowly, the smaller model starts to copy the skills of the bigger one. This includes skills like solving hard problems, writing code, or reasoning step by step.
The agencies were clear about one thing: distillation itself is not a crime. Many companies use it in normal, honest ways. The real problem is when someone does it secretly, breaks the rules, and steals value on a massive scale.
What the US Agencies Found
The warning names six China-based AI companies. They are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
According to the advisory, these companies sent millions of requests to American AI systems. Together, they pulled in billions of pieces of text, called “tokens,” from models made by four major US companies: Anthropic (maker of Claude), OpenAI (maker of ChatGPT), Google (maker of Gemini), and SpaceXAI (maker of Grok).
The agencies said this activity did not happen by accident. They called it “aggressive, malicious, and targeted.” They also said the campaigns have been running since at least late 2024, and that China’s government was likely aware of them.
How the Copying Was Done
The advisory explains that these companies used clever tricks to hide what they were doing. Some of the methods included:
- Using official app connections (APIs): The companies allegedly used normal API access but at a huge and unusual scale.
- Renting cloud computers: Cloud infrastructure in other countries was allegedly used to make it harder to identify the true source of requests.
- Using “transfer station” services: These middleman services can mix up and hide user details, making it more difficult to trace where a request originally came from.
- Spreading activity across thousands of accounts: One report from Anthropic found that just three of these six companies used about 24,000 fake accounts to generate more than 16 million conversations with Claude.
- Trying to copy “chain of thought”: This means attempting to capture not just an AI’s final answer, but information about the reasoning process behind it. Such reasoning capabilities are among the valuable components of modern AI systems.
- Switching paths after getting blocked: When one method was shut down, the campaigns allegedly moved to new accounts or different access routes.
By doing all this, the agencies say, the six companies were able to gain powerful reasoning, coding, and task-planning skills without paying the huge cost of building those skills from scratch.
Why This Counts as Breaking the Rules
Every AI company has a “terms of use” agreement. This is basically a rulebook that says how people are allowed to use the AI. Most of these agreements clearly say you cannot use the service to train a rival AI model.
The federal advisory says the Chinese companies broke these rules repeatedly, using fake accounts and hidden paths specifically built to dodge detection. That is the heart of the complaint: not that they learned from American AI, but that they allegedly misrepresented who they were and what they were doing to obtain access.
Where This Warning Came From
This September advisory is not the very first US move on this topic. Back on April 23, 2026, the White House Office of Science and Technology Policy sent out an earlier notice called NSTM-4. Its full title was “Adversarial Distillation of American AI Models.” That memo was the first time the US government officially called this kind of copying a national security threat.
Since then, lawmakers introduced a bill called the Deterring American AI Model Theft Act of 2026. If passed, it would let the Commerce Department punish companies caught doing this. Punishments could include freezing assets or placing companies on a restricted trade list, similar to rules used for other national security threats.
Anthropic Raised the Same Concern Earlier This Year
This is not just a government claim out of nowhere. Anthropic, the company behind Claude, had already flagged this problem back in February 2026. It said it caught DeepSeek, Moonshot, and MiniMax running large-scale copying attempts using tens of thousands of fake accounts.
Anthropic shared these findings publicly and explained the steps it was taking to catch and block this kind of abuse.
China’s Response
China pushed back against the US claims. On September 9, 2026, China’s Ministry of Commerce gave an official response. It said the American accusations had no solid facts or legal basis.
China also argued that distillation is simply a normal, widely used method in AI development, used by companies around the world, not just in China.
China further warned that if the US uses these distillation claims as an excuse to block or punish Chinese AI companies, China would respond with its own countermeasures.
What the Agencies Are Telling Companies to Do
The advisory does not just warn people. It also gives AI companies a list of steps to protect themselves. The recommended actions include:
- Watch for strange usage patterns: Sudden spikes in traffic or accounts that use far more of the service than they paid for are warning signs.
- Check accounts more carefully: Companies should look for fake sign-ups, shared logins, or accounts that keep rotating.
- Connect the dots across systems: Account details, payment records, network data, and request logs should all be checked together, not separately, to catch hidden patterns.
- Watch for repeated attempts to extract high-value skills: This includes reasoning, coding, or step-by-step task planning.
- Add stronger limits and controls: Companies should control how quickly and how much any single source can use the AI.
- Practice for these situations in advance: Companies can run drills for account abuse and proxy-based attacks so teams are ready before a real event happens.
- Share information with other companies and infrastructure partners: A pattern that looks small on one platform might be part of a larger campaign when combined with data from other organizations.
The agencies also warned that simply seeing “high usage” is not proof of wrongdoing. Big, honest business customers can also send huge volumes of requests. The real signal comes from patterns: fake accounts, hidden paths, and repeated attempts to pull out an AI’s most valuable reasoning skills.
Why This Story Matters to Everyone, Not Just Tech Companies
Building a top AI model today costs huge amounts of money. Companies spend on powerful computer chips, huge amounts of electricity, and years of research. If another company can copy most of that skill just by asking millions of questions and studying the answers, it can catch up at a much lower cost.
US officials worry this could hurt American AI companies financially. They also worry it could let copied AI systems spread more easily around the world, without the same safety checks and rules that the original AI companies built into their systems.
At the same time, this event shows how AI access itself is now treated like a security border. Just like companies protect computer networks and buildings, they are now being told to protect their AI systems with identity checks, usage monitoring, and shared threat alerts.
Quick Summary
| Detail | Information |
|---|---|
| Advisory date | September 8, 2026 |
| Agencies involved | NSA, CISA, FBI |
| Companies named | DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI |
| Targeted AI models | Claude, ChatGPT, Gemini, Grok |
| Activity started | At least late 2024 |
| Scale reported | Billions of tokens and millions of requests |
| Earlier US policy | NSTM-4 memo, April 23, 2026 |
| Proposed law | Deterring American AI Model Theft Act of 2026 |
| China’s response | Denied wrongdoing, September 9, 2026 |
This story is still developing. The US has laid out its case and its advice. China has firmly denied the claims. What happens next may depend on whether the proposed law moves forward, and whether more evidence or countermeasures appear in the months ahead.