Raw data, clear context.

[
[
[

]
]
]

US agencies have accused six China-based AI companies of extracting capabilities from American frontier models at industrial scale. An 8 September joint advisory from CISA, NSA and FBI says the activity involved millions of requests and billions of tokens, while naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The allegation remains disputed.[1][2]

Three-panel editorial infographic: reported tactics are access through AI inference APIs, fake accounts, proxy routes and aggregators; extraction through coordinated queries, prompt injection and collected outputs; recommended responses are pattern detection, altered responses and cross-provider signal sharing. Scope note says this is the US agencies’ account, not an independent finding about each named company.
The advisory separates reported tactics from recommended provider responses. This editorial graphic is a synthesis of the cited sources, not an independent reconstruction of any company’s operations.

What the US advisory says

On 8 September, CISA published cybersecurity advisory AA26-251A with the NSA and FBI. It describes the alleged activity as systematic extraction of proprietary functions and capabilities from US AI models, and says the campaign is likely to have involved Chinese government awareness.[1]

Knowledge distillation is a legitimate machine-learning method in which a smaller model learns from the outputs of a more capable one. The advisory says the method becomes abusive when it is used to acquire restricted capabilities at scale rather than developed through a provider’s permitted access.[1]

The six named companies are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The agencies say they targeted models including Claude, GPT, Gemini and Grok, but the advisory’s attribution is an assertion by the three US agencies, not an independently adjudicated finding.[1][2]

How the alleged extraction works

The advisory describes a campaign built around access to model inference APIs rather than direct access to model weights. It says the firms used large numbers of accounts, third-party aggregators and proxy services to distribute requests and reduce traceability.[1][3]

The agencies also describe coordinated prompts, often repeated across thousands or millions of requests, and prompt-injection attempts aimed at eliciting restricted reasoning information. These details explain why the advisory treats account, network and query patterns as part of the security problem.[1][3]

The public sources do not provide a reproducible, firm-by-firm dataset of requests, responses or resulting models. They therefore support reporting what the agencies allege and how the alleged activity was organised, but not an independent calculation of how much capability or money any named company gained.[1][2]

The proposed defences have a cost

The advisory recommends three immediate actions: detect anomalous activity, make targeted changes to responses for suspected campaigns, and share intelligence across model providers, cloud platforms and API aggregators.[1]

The first measure includes watching subscription-to-usage ratios, new accounts that reach maximum usage immediately, enterprise-scale throughput and other linked signals. Those indicators are useful only when providers can distinguish a coordinated campaign from legitimate heavy use.[1]

The second measure is more contentious. CISA, NSA and FBI suggest subtly changing responses or moving suspected accounts to a less capable model, while Ars Technica reports that the agencies acknowledge possible effects on prediction quality and business usefulness.[1][3]

That creates a practical boundary for any provider adopting the advice. A false positive could give an ordinary customer shorter or less capable answers, while stronger identity checks could require more personal information. Ars Technica also reports that the agencies want safety researchers and third-party evaluators to know when model behaviour changes.[1][3]

The third measure treats the problem as distributed by design. If requests move between providers, cloud services and aggregators, one company may see only a fragment. Sharing indicators can join those fragments, although the public advisory does not set out a common reporting format or independent oversight model.[1]

What remains to be established

The central claim is still an official allegation. NBC News reports that a Chinese Ministry of Foreign Affairs spokesperson said she had not seen the specific report, defended China’s AI progress as scientific and technological self-reliance, and called the US position a groundless accusation.[2]

That response does not resolve the technical claims, but it does mark the dispute clearly. The material reviewed for this article contains the US agencies’ account, independent reporting on the advisory and China’s stated rejection; it does not contain a public technical rebuttal from each named company.[1][2][3]

A stronger public case would need firm-level evidence showing which requests were made, which outputs were collected, how they entered a training process and what controls or terms were bypassed. The advisory supplies a detailed description of alleged tactics, but the sources reviewed here do not supply that complete chain for every company.[1][2]

For now, the firm-by-firm record is the missing piece: the advisory provides a broad campaign account, while public evidence tying each named company to each listed model remains outside the material reviewed for this article.[1][2][3]

Sources

[1] China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

[2] US accuses China AI developers DeepSeek and Alibaba of copying American AI

[3] Six Chinese AI firms accused of aggressively copying US frontier models