U.S. cybersecurity and intelligence agencies have issued serious allegations against Chinese AI companies, accusing them of large-scale exploitation of American AI models. According to a joint bulletin from the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI), these firms have been involved in ‘systematic extraction’ of proprietary functions from leading U.S. AI technologies through distillation attacks.
Industrial-Scale Exploitation of AI Models
The U.S. agencies describe these actions as integral to the development strategies of Chinese AI firms, with operations occurring on an industrial scale. While distillation is a standard technique in AI research, the agencies claim that companies in China are using it maliciously to extract restricted features from U.S. frontier AI models. The bulletin highlights that firms such as DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been involved in these activities since late 2024.
These companies allegedly saved costs by purchasing premium subscriptions from U.S. AI providers and sharing them among development teams. Their tactics include extracting chain-of-thought reasoning, employing automated failover methods during blocking attempts, and utilizing advanced quality evaluation frameworks to bypass defensive measures.
Specific Allegations Against Chinese Firms
The NSA, CISA, and FBI outlined specific instances of these distillation activities. DeepSeek reportedly targeted reasoning capabilities to develop its R1 and V3 models, while Moonshot AI extracted Claude Fable 5 data for its Kimi-K3 model and GPT-4o data for Kimi-K2. Alibaba is accused of distilling several Claude and GPT variants to enhance its models’ functionalities. MiniMax and StepFun have also been implicated in similar activities aimed at improving their respective AI capabilities.
Z.AI is noted for extracting billions of tokens from GPT-5.5 and Claude Opus 4.8 to refine its CoT reasoning features. These unauthorized access attempts violate the terms of service of the U.S. models, often involving APIs, remote cloud services, and third-party aggregators to conceal user data.
Countermeasures and Broader Implications
This ongoing situation has led U.S. agencies to advise AI companies on strengthening their security measures. Suggested actions include implementing detection systems for distillation attempts, modifying responses to potential threats, and correlating activities across various platforms to identify distributed campaigns.
Ismael Valenzuela, Vice President of Labs, Threat Research, and Intelligence at Arctic Wolf, emphasized the need for coordinated responses against these sophisticated adversaries, noting the challenges posed by the replication of advanced AI features by Chinese firms. He warned that even businesses not directly linked to frontier AI models should be aware of the potential risks, as access abuse could appear legitimate, posing broader security threats.
The situation underscores the importance of vigilant cybersecurity defenses and international collaboration to safeguard technological advancements from unauthorized exploitation.
