The US National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA) jointly published an advisory on Tuesday naming six Chinese AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Zhipu — accusing them of running industrial-scale distillation campaigns against frontier US models from Anthropic, OpenAI, Alphabet's Google, and SpaceX-owned xAI since 2024, deliberately circumventing usage restrictions. It is the first time the US government has framed organized model distillation as a coordinated security concern rather than a vendor-side abuse problem.
What the advisory actually changes: distillation defense becomes an intelligence-sharing problem
The advisory also recommends that model providers tune responses to suspected malicious distillation requests and share related signals across the industry. The implication is significant: defending against distillation moves from a per-vendor anti-abuse task to a sector-wide intelligence exchange. For providers, distinguishing a distillation request from ordinary API traffic is materially harder than catching prompt-injection or rate-limit abuse — a well-formed distillation query looks identical to a legitimate one.
Distillation is not the problem; authorization and evasion are
Distillation — training a smaller or cheaper model on outputs from a larger one — is a standard technique in academia and open-source communities. It is the publicly disclosed training path for notable open-weight models including DeepSeek-V3 and R1, and it materially reduces training and inference cost. The advisory's core allegation is unauthorized access and deliberate circumvention of usage terms, not the technique itself.
The named companies span the entire Chinese AI stack
The six companies cover the key nodes of China's large-model ecosystem — leading startups (DeepSeek, Moonshot AI, Zhipu, StepFun, MiniMax) and an internet platform (Alibaba) — spanning text, multimodal, and agent-style systems. The framing treats the "Chinese AI camp" as a single actor rather than a list of unrelated firms. On the US side, the four affected companies span closed frontier labs (Anthropic, OpenAI) and an open/xAI path (Google, xAI), suggesting the concern goes well beyond copyright and into national industrial competitiveness.
Short-term squeeze and medium-term pivot: two paths for Chinese labs
The downstream impact on Chinese model companies will play out in two layers. In the short term, any pipeline that uses US frontier APIs to generate training data or fine-tune smaller models will tighten materially — Anthropic and OpenAI have already revoked accounts flagged for suspected distillation over the past six months. Over a longer horizon, Chinese model labs will more aggressively route training data through their own models or licensed corpora, reinforcing an "internal loop" infrastructure that aligns with the regulator's recent emphasis on self-controlled compute, data, and models.
Intelligence-agency language signals more than a press release
The advisory uses very specific language — "aggressive, malicious, and targeted distillation activity" — which is intelligence-community phrasing rather than industrial-policy phrasing. That signals an ongoing mechanism: intelligence sharing, technical countermeasures, and possibly export-control follow-ups rather than a one-off statement. For practitioners tracking the AI industry, this is a milestone worth marking: the lineage between Chinese and US frontier models is being pushed from a grey zone toward two opposing poles of compliance and confrontation.