The open secret has a case number now. On September 8, CISA, the NSA, and the FBI jointly published advisory AA26-251A: China-based AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI named outright — have been conducting industrial-scale distillation campaigns against U.S. frontier models since at least late 2024, extracting capability from Claude, GPT, Gemini, and Grok variants at a volume the agencies describe in the billions of tokens.

The mechanics are almost banal, which is the point. Distillation — training a smaller model on a larger one’s outputs — is a legitimate technique every lab uses on its own models. The advisory’s claim is about scale and intent: targeted, high-volume extraction through millions of exchanges, structured to copy restricted capabilities from models whose terms of service forbid exactly this. The labs’ detection problem is now a national-security problem, and the government has said so in writing.

The names are the escalation. Naming DeepSeek — the company whose January 2025 release reset the efficiency conversation — alongside Alibaba’s Qwen team and four others converts a year of lab-side suspicion into an official record. The agencies say the campaigns have run since at least late 2024, which means the practice predates the advisory by nearly two years and the response is retrospective by design. Nobody is claiming the copying was covert in the sense of invisible; the claim is that it was industrial in the sense of unignorable.

The recommendations read like a capability disclosure. CISA, NSA, and FBI tell frontier labs to strengthen detection, monitor suspicious usage patterns, and alter responses to reduce the payoff from suspected distillation attempts — in plain terms, to start poisoning the well. That is the government asking American labs to degrade their service to suspected users, a request that sits awkwardly next to the neutrality these platforms are built to project. The frontier API is now officially a contested surface, not a storefront.

The commercial logic underneath is older than the technology. A frontier model is years of compute and research compressed into an interface that, from the outside, is just text going in and text coming out. Everything the model knows is on the other side of that interface, and the only thing standing between a competitor and the full inheritance is a rate limit and a terms-of-service clause. The advisory’s real content is an admission that this business model has an extraction problem it cannot litigate away.

What to watch is enforcement’s shadow. The advisory names companies but proposes no sanctions; its teeth are informational — it tells every frontier lab what the government believes is happening on their endpoints. The next move belongs to the usage policies and the classifiers. If detection starts shaping traffic — and the advisory asks for exactly that — the era of frictionless frontier access ends, and every builder downstream inherits the border controls.

6
China-based companies named in the advisory
Billions
Of tokens allegedly extracted since late 2024
4
U.S. model families targeted: Claude, GPT, Gemini, Grok
3
Agencies signing: CISA, NSA, FBI

The Takeaways