U.S. Intelligence Links Six Chinese AI Firms to Industrial-Scale Model Distillation

A joint advisory from U.S. cybersecurity and intelligence agencies reveals that six Chinese AI companies, including DeepSeek and Alibaba, conducted large-scale distillation attacks on frontier models from OpenAI, Anthropic, Google, and xAI. The attackers used sophisticated techniques such as chain-of-thought extraction and automated failover to bypass defenses, extracting billions of tokens since late 2024. The agencies believe these operations were likely supported by the Chinese government as a core development strategy.
The joint advisory from CISA, NSA, and FBI identifies DeepSeek and Moonshot AI as the most active offenders, while Z.AI specifically targeted GPT-5.5 and Claude Opus 4.8. These operations have been ongoing since late 2024, involving millions of requests to extract billions of tokens.
The attackers employed proxies, shared accounts, and automated failover to evade detection. The advisory suggests defenders watch for new accounts immediately maxing out usage, identical prompts across providers, and coordinated switching between access routes, recommending modified responses and improved behavioral monitoring.
This advisory could reshape the AI landscape by prompting stricter access controls, which may hinder legitimate researchers and smaller developers who rely on frontier APIs. Consumers might see slower innovation or higher costs if US firms invest heavily in defensive measures. Additionally, the alleged state backing could intensify regulatory scrutiny and international tech competition, potentially leading to fragmented AI ecosystems where models are developed in isolated regional silos.