The U.S. National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly identified six Chinese AI companies for large-scale model distillation from commercial large language models. The named firms are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The agencies say the activity targeted models such as Claude, GPT, Gemini and Grok and occurred since late 2024.
Allegations and responses
According to the agencies, the distillation was carried out at industrial scale and may have taken place with the knowledge of the Chinese government; the Chinese side has called the accusations groundless. The public advisory issued by the agencies also acknowledges significant detection limitations: current methods cannot reliably distinguish malicious extractors from legitimate paying customers.
Because of this limitation, the advisory recommends covert mitigation techniques for affected labs. Examples include deliberately degrading or ‘‘poisoning’’ responses for suspected abusive requests, or quietly routing suspected abusers to weaker models, rather than openly blocking traffic. The agencies’ guidance does not instruct labs to notify customers when such measures are applied.
Practical and commercial implications
The recommended mitigations present a dilemma for AI labs. Running an unmodified, high-quality API makes models vulnerable to being copied; applying hidden degradations protects intellectual property but risks misleading or harming legitimate customers who pay for the advertised level of service. The advisory can be read as an admission that the lead on preventing large-scale extraction cannot be fully regained — only the value of the models can be reduced to limit their usefulness to abusers.
Political fallout
The technical problem is already being handled as a policy issue. The announcement raises the possibility of sanctions, coordination with allied states, and other diplomatic measures. The timing and framing of the advisory were noted alongside the upcoming U.S.–China leader-level meeting scheduled for September 24, 2024, where such security and economic concerns are likely to be discussed.
Conclusion
The joint advisory from NSA, CISA and the FBI signals that industrial-scale distillation of advanced LLMs is a practical and unresolved threat. With detection unable to separate malicious actors from ordinary customers, the burden of mitigation falls on AI labs and their paying clients, and the solutions available—covertly degrading services or routing traffic—pose commercial and ethical challenges.



