On September 8, 2026, the NSA, FBI, and CISA—rarely acting in sync—simultaneously named six Chinese AI companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.ai. The agencies accused them of distilling capabilities from American models on an industrial scale since 2024, with a particular focus on boosting math and coding performance. Distillation itself is legal; the controversy lies in the bulk extraction that circumvented access rules. By upgrading an intellectual property dispute into a national security matter, the three agencies have crossed a significant line. None of the six companies has responded.
Six Chinese AI companies, all named by three U.S. intelligence agencies at once
On September 8, 2026, the NSA, FBI, and CISA jointly released a cybersecurity advisory, putting DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.ai at the same table. They accused the six of running "industrial-scale" knowledge distillation(using one model's outputs to train or compress another model) of American frontier models since 2024.
The agencies used a heavy word in the advisory: for these companies, distillation isn't a "supplement" to R&D—it's the "core." The U.S. position is that these Chinese companies aren't building models from scratch, but treating American model capabilities as raw material to strip-mine.
The scope of the allegations is quite specific. The advisory claims that since late 2024, these companies have made millions of requests to American frontier models—including Claude, GPT, Gemini, and Grok—through channels such as account rotation, APIs, proxies, cloud service providers, and third-party aggregation platforms, accumulating "billions" of tokens(the smallest unit a model processes text in, which can be a single character or a word fragment) extracted. The targets are highly concentrated: math and coding capabilities.
The intelligence agencies elevated the framing to the state level. The advisory states plainly that the distillation activities "likely" had the Chinese government's knowledge. With that one sentence, a corporate intellectual property dispute gets repackaged as a national security issue.
After the six Chinese companies were named, none issued an immediate response as of publication. CISA Acting Director Nick Andersen, in the accompanying press release, directly called on American AI companies to "take immediate action to protect your platforms." The advisory also urged U.S. developers to share relevant intelligence.
How these companies buried their requests in massive traffic flows, what level of evidence the U.S. side holds, and what countermeasures America is preparing—those three threads are all still hanging.
Distillation is legal—the fight is over the front door
The intelligence agencies aren't targeting the technical act itself. They're targeting the door that precedes it: who pushed it open, how, and whether they had permission.
Of the nine Chinese AI companies [mentioned in coverage], six were named: DeepSeek, Moonshot AI (whose product is Kimi), Alibaba, MiniMax, StepFun, and Z.ai. The allegations point to late 2024 onward, when these six bypassed access rules through multiple channels to bulk-extract capabilities from American frontier models. The advisory separates two things: authorized distillation is an industry-standard training method; the controversy lies in the access path and whether consent was obtained.
This is the most counter-intuitive part: the named distillation蒸馏(using one model's outputs to train another model, commonly used to teach smaller models the problem-solving abilities of larger ones) technique itself isn't illegal.
Moonshot is alleged to have distilled 18 American models to train Kimi K2 and K3—a practice that, under compliant authorization, happens between major labs every day. What turned it into a national security matter was the "multi-channel bypass" prefix: unauthorized API access, bulk-registered throwaway accounts, proxy chains, and third-party aggregation platforms. One legitimate "ask a question" became a million-scale capability transfer.
The impact has two layers. The first is industry rules: the advisory is calling on domestic U.S. AI developers to tighten their platforms and share intelligence. Access controls scattered across individual companies will likely be upgraded into unified standards—stricter API identity verification, call-frequency auditing, and compliance whitelists for third-party interfaces are all likely moves in the coming months.
The second is the geopolitical narrative: an intellectual property dispute has been packaged in intelligence-agency language. Similar incidents going forward will no longer be resolved solely in court but will go through export controls and entity lists.
None of the six companies responded immediately after the incident. In the coming weeks, two paths are likely: a formal investigation, or the matter remaining at the deterrent level of a joint advisory.
The stakes just went from courtroom to statecraft.