US agencies warn of Chinese AI model distillation campaigns

The NSA, CISA, and FBI issued a joint advisory accusing several Chinese AI firms of systematically extracting data from American frontier models. The agencies specifically named DeepSeek, Moonshot AI, Alibaba, and others for using distillation to train their own systems. The advisory includes recommended mitigations for US companies to counter such practices.
The advisory outlines specific model-to-model connections. DeepSeek allegedly used outputs from Claude, Gemini, GPT, and Grok to build its open-source R1 reasoning model. Moonshot reportedly drew from Claude's Fable to create Kimi K3, and also used GPT-4o data for Kimi K2. Fable was designed to publicly share capabilities from Anthropic's restricted cybersecurity model, Mythos.
This is not the first accusation of its kind. OpenAI previously banned accounts suspected of distillation, investigating DeepSeek among others. Anthropic also levied similar charges against DeepSeek, Moonshot, and MiniMax earlier this year. Furthermore, the practice is not exclusive to Chinese firms, as Elon Musk admitted during litigation that xAI used OpenAI outputs for training.
This advisory could prompt US AI providers to implement stricter rate limits, advanced monitoring, and legal measures, potentially raising costs for developers and enterprises reliant on frontier models. It may accelerate technological decoupling between the US and China, hindering collaborative research and reducing model diversity for global consumers. Conversely, these allegations could spur investment in domestic alternatives and stronger security protocols, though smaller firms might struggle to adapt to tightened access.