U.S. Intelligence Agencies Warn of Industrial-Scale AI Model Distillation Campaigns by China-Based Firms
NSA, CISA, and FBI issue joint advisory detailing systematic extraction of proprietary U.S. AI capabilities by Chinese companies
Key Takeaways
- NSA, CISA, and FBI issued joint advisory AA26-251a on industrial-scale AI model distillation by China-based firms.
- Since late 2024, companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens from U.S. frontier models including Claude, GPT, Gemini, and Grok.
- Distillation is described as the core of these companies' AI development strategies, enabling cost savings and shorter timelines.
- Actors used native APIs, cloud providers, third-party aggregators, and gray-market "transfer station" proxies to bypass restrictions and evade detection.
Related Security News
CISA Adds CVE-2026-86950 to Known Exploited Vulnerabilities Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability affects Apple Multiple Products and involves an out-of-bounds write flaw. Evidence of active exploitation has been confirmed, prompting CISA to require Federal Civilian Executive Branch agencies to prioritize rapid remediation on publicly exposed assets per Binding Operational Directive 26-04.




