On Sept. 10, 2026 the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released a joint advisory that directly accuses six Chinese artificial‑intelligence firms of conducting large‑scale model‑distillation attacks against U.S. AI providers.
What the advisory says
The advisory, quoted in Heise, states that the Chinese firms “in großem Stil Wissen aus US‑amerikanischen KI‑Modellen absaugen” – in other words, they are siphoning knowledge from U.S. models on a massive scale. The agencies name the firms as DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI.
According to the advisory, the targeted U.S. models belong to OpenAI, Anthropic, Google and xAI. The practice described is “large‑scale model distillation,” which the advisory defines as repeatedly querying U.S.‑origin models via APIs or other channels to harvest the underlying training data that powers those models.
Chinese firms named
All six companies are based in China and have been active in the generative‑AI market for several years. The advisory does not provide financial metrics for the firms, but the naming alone signals a shift from generic concerns about AI theft to concrete accusations against identifiable entities.
U.S. AI providers at risk
OpenAI, Anthropic, Google and xAI are among the most prominent AI developers in the United States. OpenAI, headquartered in San Francisco, is led by CEO Sam Altman and employs roughly 4,500 people. Anthropic, also based in San Francisco, is run by CEO Dario Amodei and has about 2,500 employees. Google, headquartered in Mountain View, is overseen by CEO Sundar Pichai and reports a workforce of 47,756. All three firms have released large language models that power a growing ecosystem of applications worldwide.
The advisory’s focus on these four providers reflects their market dominance. OpenAI’s GPT‑4 series, Anthropic’s Claude models, Google’s Gemini suite and xAI’s latest offerings are widely accessed through public APIs, making them attractive targets for systematic querying.
How model distillation works
Model distillation, as described by the advisory, involves feeding a large, proprietary model a series of prompts and recording the outputs. By aggregating enough responses, an attacker can approximate the original model’s behavior and, in some cases, infer aspects of its training data. The advisory warns that the Chinese firms are not merely using the distilled models for downstream applications; they are “stützten ihre Weiterentwicklung zentral darauf, um mit ihren Modellen an die Fähigkeiten US‑amerikanischer Anbieter aufzuschließen,” meaning they rely centrally on this harvested knowledge to close the capability gap with U.S. providers.
Implications for the U.S. AI ecosystem
The advisory does not quantify the volume of queries or the exact amount of data extracted. However, the language “großem Stil” (large scale) suggests a systematic, possibly automated effort that could erode the competitive advantage of U.S. firms. If successful, the practice could enable the Chinese firms to accelerate their own model development without incurring the same data‑collection costs.
For U.S. companies, the immediate concern is the potential loss of proprietary knowledge. The advisory also offers mitigation steps, such as tightening API access controls, monitoring usage patterns for anomalous query volumes, and employing watermarking techniques to detect unauthorized model replication.
Background on the companies involved
OpenAI was founded on Dec. 11, 2015, and has grown into a leading AI research lab and commercial provider. Anthropic, founded on Jan. 26, 2021, positions itself as a safety‑first AI developer. Google, established on Sep. 4, 1998, operates the world’s most widely used search engine and a broad portfolio of AI services. xAI, a newer entrant founded by Elon Musk, entered the market in 2023 and quickly released a series of large language models.
All four firms have publicly disclosed their executive leadership and employee counts, but the packet notes that these figures may lag behind the latest filings. The advisory does not mention any response from the companies, and none of the firms have issued a public statement as of the writing of this article.
What remains unknown
- The advisory does not disclose the specific methods used by the Chinese firms to evade detection.
- No quantitative estimate of the data volume extracted is provided.
- It is unclear whether any of the targeted U.S. models have already been compromised in a way that affects downstream applications.
- The advisory does not indicate whether any legal actions are being pursued against the accused firms.
These gaps leave both industry observers and policymakers with unanswered questions about the scale of the threat and the appropriate regulatory response.
Table: Chinese firms and the U.S. models they are accused of targeting
| Chinese firm | U.S. target models |
|---|---|
| DeepSeek | OpenAI, Anthropic, Google, xAI |
| Alibaba | OpenAI, Anthropic, Google, xAI |
| Moonshot AI | OpenAI, Anthropic, Google, xAI |
| MiniMax | OpenAI, Anthropic, Google, xAI |
| StepFun | OpenAI, Anthropic, Google, xAI |
| Z.AI | OpenAI, Anthropic, Google, xAI |
Source: Heise – US‑Behörden warnen vor KI‑Wissensabfluss nach China (advisory quoted in article).
Next steps
The advisory urges U.S. companies to review their API usage logs, implement stricter rate‑limiting, and consider technical safeguards such as model watermarking. It also calls on industry groups to share threat intelligence and coordinate responses.
As the geopolitical rivalry over AI intensifies, the advisory marks a rare public attribution of specific firms to a coordinated knowledge‑extraction campaign. How U.S. firms adapt their security posture and whether policymakers will introduce new regulations remain to be seen.