US Intelligence Advisory Identifies Chinese AI Firms Targeting American Models
Three US agencies have jointly revealed details in an advisory about six Chinese Artificial Intelligence (AI) companies engaging in systematic data extraction from American frontier models since late 2024.
The Agencies and the Advisory:
- National Security Agency (NSA)
- Federal Bureau of Investigation (FBI)
- Cybersecurity and Infrastructure Security Agency (CISA)
- Advisory Title: "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies"
Named Chinese Firms and Their Activities:
-
DeepSeek: Accused of targeting American models like Claude, Gemini, GPT, and Grok since late 2024, with a notable focus on the $5.6 million training cost claim for a model, which the advisory suggests underestimates data acquired through malicious distillation.
-
Moonshot AI: Allegedly extracted millions of exchanges from Claude and GPT models for its Kimi range from mid-2025.
-
Alibaba: Distilled American models Claude and GPT-5 in late 2025 to enhance its Qwen family.
-
MiniMax: Accused of collecting chain-of-thought and reinforcement learning data, attempting prompt injection against the Claude model, and more.
-
StepFun: Allegedly stole reasoning and coding capabilities throughout late 2025 and early 2026.
-
Z.AI: Extracted billions of tokens from GPT-5 and Claude Opus by mid-2026.
Methods Used for Data Extraction:
The advisory details intricate methods used to route traffic for data extraction:
- Fraudulent account creation
- Using single accounts across multiple addresses
- Requesting data through cloud providers and third-party aggregators that remove identifying metadata
- Utilizing "transfer stations" – API proxies that bypass geographic restrictions and traceability.
Unique Techniques:
The advisory highlights innovative techniques employed:
- "Jailbreak prompts": Asking AI models to narrate their internal reasoning process, revealing hidden chain-of-thought not intended for sale.
- Automatic failover mechanisms in case one data extraction route was blocked.
Cautious Attribution:
While suggesting Chinese government awareness of these activities, the advisory avoids direct claims of direction from Beijing, emphasizing "likely" awareness. This cautious wording reflects the intricate nature of attributing AI development and espionage.
Controversial Recommendation:
The advisory recommends AI providers implement response mechanisms that subtly alter output to suspected distillers without notification. While intended to improve detection, this approach raises concerns about impacting legitimate researchers and users through degradation of service.