NSA, FBI Name DeepSeek, Alibaba in Mass AI Model Theft Alert

US agencies say six Chinese AI firms, including DeepSeek and Alibaba, ran industrial-scale campaigns to copy Claude, GPT, and Gemini.

Sep 10, 2026 - 07:09
4 min read
 0
NSA, FBI Name DeepSeek, Alibaba in Mass AI Model Theft Alert

Three of America's top security agencies just put names and numbers on something the AI industry has whispered about for two years: that China's fastest-growing AI labs got there partly by quietly copying the work of US frontier models, one conversation at a time.

What the advisory actually says

On September 8, the NSA, the FBI, and the Cybersecurity and Infrastructure Security Agency (CISA) — the US government's lead cyber-defence body — jointly published advisory AA26-251A, naming six Chinese AI companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies allege these firms ran "industrial-scale" campaigns to extract billions of tokens (chunks of text an AI model processes) across millions of conversations with US models including Claude, GPT, Gemini, and Grok, going back to at least late 2024.

The technique at the centre of it is called distillation. In plain terms, instead of training a new AI model from scratch on raw data, a company can quiz an existing, more capable model with huge volumes of questions and then train its own smaller model to mimic those answers. It's a legitimate research method when used on your own models. The accusation here is that it was turned into a way of siphoning capability out of a rival's product without permission, at a scale the agencies say went well beyond normal use.

The advisory describes distillation as "the critical core" of these companies' development programs, rather than a minor shortcut used alongside other training methods.

Who's accused of what

The advisory gets specific about each company:

  • DeepSeek: running organised extraction against Claude, Gemini, GPT, and Grok since late 2024
  • Moonshot AI: pulling millions of exchanges from Claude and GPT since mid-2025 to build its Kimi models
  • Alibaba: distilling Claude and GPT-5 outputs in late 2025 to strengthen its Qwen model family
  • MiniMax: extracting chain-of-thought reasoning data and reportedly attempting prompt injection against Claude Code
  • StepFun: lifting reasoning and coding capability through late 2025 and early 2026
  • Z.AI: pulling billions of tokens from GPT-5.5 and Claude Opus by mid-2026

To help US AI providers spot this kind of abuse going forward, the agencies listed some tell-tale usage patterns: accounts running 24/7 with none of the idle gaps a real person leaves, brand-new subscriptions that immediately max out their usage limits instead of ramping up gradually, one login being accessed from a scattered mix of IP addresses and devices, and a subscription that generates far more API traffic than its billing tier should allow.

Why this matters beyond the US-China rivalry

For Indian developers and startups, this isn't just a story about two superpowers squabbling over AI bragging rights. Models like DeepSeek and Qwen have become genuinely popular in India precisely because they're cheap or free to run compared to their American counterparts, and a lot of homegrown apps and services are quietly built on top of them. If US labs respond to this advisory by rate-limiting suspicious traffic patterns or tightening API access, ordinary developers in Bengaluru or Pune building on these platforms could get caught in broader restrictions never meant for them.

There's also a data-governance angle worth watching. Under India's Digital Personal Data Protection (DPDP) Act, companies handling Indian users' data carry accountability obligations regardless of where their AI backend sits. If Indian firms are routing user queries through any of the six named platforms, this advisory is a reminder to actually check where that data ends up and what it might be used to train — a question MeitY has been pushing more actively as AI adoption grows across Indian industry.

What happens next

None of the six companies has issued a substantive public rebuttal at the time of writing, and the advisory itself doesn't name specific enforcement action — it's a warning to industry, not a legal filing. But it does put a formal, three-agency stamp on claims that were previously just industry gossip, and it gives American AI companies a documented playbook for cutting off suspected distillation traffic.

The bigger question is whether this changes anything on the ground. Distillation is hard to fully block without also blocking legitimate research use and paying customers, and the economics that make cheaper Chinese models attractive to developers everywhere, India included, aren't going away because of one advisory. Expect the real test to come from how aggressively US providers actually throttle access, not from anything written in AA26-251A itself.

Short URL: https://code24.in/e58ea072

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Code24 Team Code24 Team