Future TechnologyFuture Technology
AI

NSA and CISA tell AI firms to quietly serve worse models to distillers

· 4 min read · By Future Technology

Key takeaways

  • Joint advisory AA26-251A, published 8 September, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI
  • The agencies say the six extracted billions of tokens from Claude, GPT, Gemini and Grok since at least late 2024, likely with Chinese government awareness
  • It recommends serving downgraded or altered responses to suspected distillers, varying them between requests, and not telling the accounts affected
  • Distillation is a standard training technique, so the case rests on scale and intent rather than the method itself

The NSA, CISA and the FBI published a joint cybersecurity advisory on 8 September naming six Chinese AI companies and accusing them of extracting billions of tokens from US frontier models since at least late 2024. The advisory, AA26-251A, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and says the activity was likely conducted with the awareness of the Chinese government.

The accusation is not the most interesting part of the document. The recommended response is.

Serve them a worse model and say nothing

The agencies tell US providers to deploy what they call targeted response changes: subtly altering answers to suspected distillation requests, including serving downgraded models or applying differential privacy, and varying those alterations between requests so the attacker's own quality evaluation cannot detect the pattern.

The advisory then explicitly recommends against telling users suspected of malicious distillation that their responses have been changed. Notice, the logic runs, would only help them improve their evasion. Safety researchers and third-party evaluators, by contrast, should be told when a model changes.

That is a public instruction from three federal agencies to degrade a paid product for a class of customer identified by behavioural signal, without disclosure. It is a defensible security position and also a meaningful change in what a model provider is expected to guarantee about the thing you are paying for.

What the advisory alleges, company by company

The specifics are unusually granular. Between late 2024 and mid-2025, the agencies say, DeepSeek distilled from Claude 3.7, Claude Sonnet 4, Claude Sonnet 4.5, Claude Opus 4.1, two Gemini 2.5 preview models, five GPT versions and Grok 4 to generate synthetic training data for R1 and V3. The advisory adds that DeepSeek's widely quoted $5.6 million training cost is misleading because it excludes the cost of data acquired this way.

Moonshot AI is accused of extracting significant Claude Fable 5 data to train Kimi K3 and GPT-4o data for Kimi K2, targeting supervised fine-tuning, reinforcement learning, software engineering and maths. Alibaba is said to have distilled Claude and GPT-5 output in late 2025 to improve software engineering and dialogue in its Qwen family.

MiniMax draws the strangest allegation. The agencies say it used Claude Code for internal software development and deployed prompt injections attempting to convince Claude Code that it was a MiniMax product. They also say MiniMax redirected exchanges to each new Claude model within 24 hours of release.

How they say it was done

The described tradecraft is procurement more than intrusion. Requests were routed through native APIs, remote cloud providers and third-party aggregators that obscure user metadata, plus a grey market of API proxies the advisory calls transfer stations, used to bypass geographic restrictions and undermine traceability.

Cost savings came from bulk purchases of premium subscriptions shared across developer teams. More advanced tactics included chain-of-thought extraction, automated failover between access paths when one was blocked, and quality evaluation frameworks built to detect defensive countermeasures.

The detection indicators are the practical takeaway for anyone running an API business: shared accounts appearing from multiple IP addresses and user agents, sustained around-the-clock usage with no human variation, anomalous subscription-to-usage ratios, and new subscriptions immediately running at maximum quota.

Distillation is not exotic

CISA concedes in its own announcement that knowledge distillation is a valid training method. Training a smaller model on a larger one's outputs is standard practice, and US labs have done it to each other. Elon Musk acknowledged under cross-examination in April that xAI had distilled OpenAI output. White House OSTP head Michael Kratsios made a narrower version of this claim about Moonshot in June.

So the case rests entirely on scale and intent. The agencies argue that for these six companies distillation forms the core of model development rather than a supplement to it, and that the volume and evasion tactics move it from research practice to industrial extraction. That is an argument about degree, and reasonable people will disagree about where the line sits.

It also lands while the same US labs being defended here are in court over the provenance of their own training data. An advisory that treats unauthorised use of someone else's output as a national security matter is going to be quoted back by plaintiffs, and the agencies do not address that tension.

What actually changes

Nothing legally. This is an advisory, not an enforcement action, and it carries no penalties. It directs affected organisations to file complaints with the FBI's Internet Crime Complaint Center and calls for coordinated intelligence sharing across model providers, cloud platforms and API aggregators.

The practical effect will show up as friction. Expect tighter identity checks on new API accounts, more aggressive rate limiting, and more accounts flagged on usage patterns rather than content. Legitimate high-volume users running automated pipelines look, on the metrics the advisory lists, a great deal like the behaviour it describes. That is the cost worth watching.

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.

Enjoyed this? Get the briefing.

One email, every weekday: the top story, a useful tool, and what matters in tech - in under 3 minutes.

More from Future Technology

AI

Ten thousand AI agents, 88 hours, and a fight over who got there first

AI

AI reads brain MRIs in seconds with 97.5% accuracy

AI

Google ships the Gemini 3.6 Flash family and starts Gemini 4

AI

Meta's Muse agent wants your inbox, your calendar and your card