Full Breakdown
U.S. Agencies Accuse Six Chinese AI Firms of Industrial-Scale Knowledge Distillation
By Drooid · · How we work
Core Accusation
On September 8, 2026 the NSA, CISA, and FBI issued a joint advisory naming six China-based AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The agencies allege the firms ran “industrial-scale” knowledge-distillation campaigns against U.S. frontier models, extracting billions of tokens and millions of API requests from Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini and xAI’s Grok, and incorporating the outputs into their own models.
Background & Context
Knowledge distillation lets a smaller “student” model learn from a larger “teacher.” The advisory argues the Chinese firms went beyond ordinary practice by systematically querying competitor models at scale, using fraudulent accounts, proxy services (“transfer stations”) and prompt-injection tactics to bypass safeguards. The accusations come amid heightened U.S.–China competition over AI research and supply-chain security.
Data & Statistics
- Tokens extracted: “billions of tokens.”
- API requests: “millions of exchanges/requests” since at least late 2024.
- Targeted models: Claude, GPT, Gemini, Grok.
- DeepSeek – extraction from multiple generations of the four models for its R1 and V3 models.
- Moonshot AI – use of Claude and GPT outputs for its Kimi family, including rapid shifts to new Claude releases.
- Alibaba – incorporation of Claude and GPT outputs into its Qwen series.
- MiniMax – prompt-injection attempts on Claude Code and collection of chain-of-thought data.
- StepFun – shared-account infrastructure to bypass rate limits.
- Z.AI – extraction of “billions of tokens” from GPT-5.5 and Claude Opus by mid-2025.
Official Statements & Responses
- Anthropic threat-intelligence (Jacob Klein): Moonshot AI used thousands of fake accounts to exchange more than 23 million communications with Claude between May and July, routing queries through transfer stations that obscured origin.
- Chinese Foreign Ministry (Mao Ning): Called the U.S. claims “groundless” and urged Washington to refrain from “groundless accusations.”
On-the-Ground Reports
Anthropic’s threat-intelligence report detailed how fake accounts and stolen API keys funneled queries—including a surveillance-analysis request from Chengdu—through transfer stations to Claude, allowing Anthropic to see both the query and downstream Chinese-firm usage. The report also noted instances where Claude was used to generate instructions for modifying avian-influenza viruses and to support a hacking group’s “exploit-foundry” operations.
Criticism & Opposition
Chinese officials argue the United States applies a double standard, noting that American companies also distill Chinese models. The Commerce Ministry spokesperson framed the advisory as a tool for U.S. tech hegemony.
Conflicting Reports & Gaps
- Legal status: No court finding or formal legal determination; the advisory stops short of alleging direct state direction.
- Scope of activity: Anthropic’s evidence focuses on Moonshot AI and DeepSeek, while the advisory lists all six firms, leaving gaps for MiniMax, StepFun and Z.AI.
- Intent vs. theft: Sources differ on whether the activity constitutes unauthorized extraction or aggressive research practice.
Verbatim Quote
- “In the past we thought of this type of misuse as a hypothetical risk, but now we are seeing real cases,” — Jacob Klein, head of threat intelligence at Anthropic
What’s Next
A high-level U.S.–China dialogue on AI safety is scheduled for later this month, potentially shaping diplomatic and regulatory responses. Treasury Secretary Scott Bessent warned that sanctions or blacklisting could follow if the alleged practices continue.
