The US artificial intelligence landscape shifted dramatically on September 8, 2026. In an extraordinary move, three of America's most powerful security agencies jointly named six Chinese AI companies as perpetrators of what they called industrial-scale intellectual property theft — not through traditional hacking, but through a sophisticated AI technique known as knowledge distillation. For enterprise technology leaders, this isn't just geopolitical noise. It's a wake-up call that demands an immediate reassessment of your AI sourcing strategy, vendor risk posture, and data governance policies.
What Just Happened: The NSA, CISA, and FBI Advisory Explained
The National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation released a joint cybersecurity advisory on September 8, 2026, warning that China-based artificial intelligence companies are systematically extracting proprietary capabilities from U.S. frontier AI models through industrial-scale knowledge distillation campaigns running since at least late 2024.
The advisory named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI
as the companies involved. The scope of the alleged activity is staggering.
The agencies allege the companies extracted billions of tokens through millions of interactions with U.S. models and used knowledge distillation to improve reasoning, coding, and agent capabilities.
Crucially,
according to the joint advisory, the sheer scale of these efforts since 2024 indicates that distillation is a critical part of China's AI industrial policy. "China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies' models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy," the agencies wrote.
This is not the first time these allegations have surfaced.
Shortly after the launch of DeepSeek's R1 model in January 2025, both OpenAI and Microsoft claimed that it had been partially trained on ChatGPT.
But the September 2026 advisory represents the US government's most coordinated and detailed public accounting to date.
How Does Knowledge Distillation Work — And Why Does It Matter?
To understand the significance of these allegations, enterprise leaders need to grasp the mechanics at play.
Distillation is a method in AI development that enables a smaller "student" model to replicate or approximate the performance of a larger "teacher" model by learning from its outputs.
In legitimate AI development,
distillation is not uncommon in the industry, as Anthropic acknowledged that AI firms "routinely distill their own models to create smaller, cheaper versions."
The problem, according to the agencies, lies in the scale and intent.
Officials said some companies used fraudulent accounts, API proxies, and other methods to bypass geographic and usage restrictions.
The advisory also details a gray market infrastructure enabling this:
the advisory describes a "gray market of API proxies known as 'transfer stations'" that resell frontier-model access "at a fraction of the official price," letting buyers bypass regional restrictions and stripping the metadata that would otherwise identify them.
The result? Competitive capabilities built at a fraction of the cost.
The advisory challenges DeepSeek's reported $5.6 million training cost, saying the figure does not account for the true cost of data obtained through extensive distillation.
The Named Companies and What They Allegedly Targeted
The advisory is unusually specific, naming which models were targeted and for what capabilities.
DeepSeek distilled frontier U.S. models to generate synthetic training data for its R1 and R3 models, including four different versions of Claude, two versions of Gemini, five versions of ChatGPT, and Grok 4. Those models helped train DeepSeek's capabilities in areas like agentic functioning, question and answer optimization, and creative and occupational writing.
Moonshot AI allegedly distilled 18 different U.S. models — including Fable 5, Anthropic's current most advanced commercially available model — to train its Kimi-K2 and Kimi K3 models. The company used millions of queries meant to extract enhanced capabilities in areas like agentic reasoning, coding and data analysis, computer vision, and visual processing.
Alibaba, MiniMax, StepFun, and Z.AI have used U.S. models to develop capabilities ranging from coding and customer service to reasoning and AI agents.
Between late 2025 and early 2026, StepFun distilled data from Claude Opus 4.1 and 4.5, Claude Sonnet 4.5, Claude Haiku 4.5, GPT-5 Mini, GPT-5 Pro, GPT-5.1, GPT-5.1 Codex, and GPT-5.2 to improve its Step 4 model's coding and agentic functions.
China has flatly denied the allegations.
A spokesperson for the Chinese Ministry of Foreign Affairs said that US agencies should be working on strengthening AI cooperation with China "rather than making groundless accusations," while defending China's success in quickly expanding its AI capabilities as the "result of high-level scientific and technological self-reliance."
The Enterprise Fallout: Vendor Risk and Market Disruption
For enterprise technology buyers, these developments create immediate and tangible risk exposure across several dimensions.
Vendor credibility and supply chain risk.
The named companies face escalating US scrutiny and potential restrictions on model access, partnerships, and cloud distribution. Even if China denies wrongdoing, the market will price higher compliance costs and slower commercialization for AI products tied to US-model distillation allegations.
The rapid penetration of Chinese AI models into enterprise workflows is also alarming.
Chinese-origin AI models made up roughly 4.5 percent of enterprise token usage on the OpenRouter marketplace in the first half of 2025. By the first week of July 2026, that share had climbed to 63 percent.
This dramatic shift means many enterprises may already be running workflows on models whose underlying capabilities are, according to US agencies, derived from improperly extracted US model outputs.
Regulatory and compliance exposure.
Distillation technology is neutral and innovative, with the potential to promote technological advancement, but its legality remains unclear under the current legal framework.
Enterprises integrating Chinese-origin AI models into sensitive workflows — particularly in regulated industries like finance, healthcare, and defence contracting — face compounding uncertainty.
Geopolitical volatility.
US-China relations face further pressure as both nations prepare for a mid-September dialogue concerning AI safety risks, complicating bilateral negotiations.
Policy shifts resulting from these talks could rapidly alter what AI tools are legally permissible for US-based enterprises.
Practical Tips: What Enterprise AI Leaders Should Do Right Now
The threat landscape has changed. Here is what you can do immediately to protect your organisation's AI strategy.
1. Audit Your Current AI Model Stack
Conduct a full inventory of every AI model, API, and third-party AI service your organisation currently uses. Flag any tools built on or powered by the six named Chinese firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
Security teams need an inventory of models, resellers, and service accounts; clear ownership for API keys; thresholds for unusual consumption; and logs that connect user identity with model calls.
2. Review Your AI Vendor Contracts
Companies such as OpenAI, Anthropic, Mistral, and xAI include strict "anti-competitive distillation" clauses in their terms of use, prohibiting users from using their services or outputs to develop competing models.
Ensure you understand whether your own use of AI APIs could expose you to liability — and verify that your vendors are actively policing these terms.
3. Monitor for Anomalous API Behaviour
Detection indicators listed in the advisory include shared accounts used from multiple IP addresses and user agents, sustained usage around the clock without human variation, anomalous subscription-to-usage ratios, and new subscriptions immediately running at maximum usage.
Implement telemetry and alerting around these patterns across your enterprise AI infrastructure.
4. Diversify Your AI Supply Chain Thoughtfully
Don't panic-replace every model, but do build a diversification strategy that accounts for geopolitical risk. Understand which models underpin your most critical business processes and ensure you have viable, vetted alternatives that don't carry the regulatory and reputational risks now associated with the named Chinese providers.
5. Establish a Cross-Functional AI Governance Committee
The intersection of AI, cybersecurity, legal compliance, and geopolitics now demands board-level attention.
Establish cross-organisation intelligence-sharing to correlate activity across model providers, cloud platforms, and API aggregators.
Internally, this means bringing together your CISO, General Counsel, and Chief AI Officer to create a unified response framework.
6. Stay Ahead of Regulatory Changes
The three federal agencies specified that the named companies used "aggressive, malicious, and targeted distillation" tactics to extract billions of tokens from the exchanges within U.S. frontier AI models, likely with Chinese government awareness, since 2024.
Given the severity of that language, regulatory action — including potential access restrictions on named models — could follow quickly. Engage your government affairs team now.
Conclusion: A Strategic Inflection Point for Enterprise AI
The September 2026 NSA-CISA-FBI advisory is not just a cybersecurity warning — it is a signal that enterprise AI strategy must now account for geopolitical risk as a first-class concern alongside performance and cost. The line between AI vendor selection and national security policy has blurred in ways that demand your immediate attention.
The good news is that enterprises who act now have the advantage of clarity. You know which companies are named. You know which capabilities are at risk. And you now have government-issued guidance on what detection and mitigation look like. The question is whether your organisation will treat this as background noise or as the strategic inflection point it truly is.
Is your enterprise AI strategy geopolitically resilient? If you're unsure, now is the time to find out. Reach out to our team today for a comprehensive AI vendor risk assessment — and build the kind of future-proof AI infrastructure your business deserves.


