US agencies accuse six Chinese AI firms of stealing American model capabilities at massive scale

The US government doesn’t usually call out specific companies in joint cybersecurity advisories. So when the NSA, FBI, and CISA do exactly that, it’s worth paying close attention. According to Engadget, the three agencies have issued a joint advisory accusing six Chinese AI companies of running what they describe as “distillation activities at an industrial scale” against America’s most powerful AI systems.

The companies named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The advisory claims these firms extracted “billions of tokens across millions of exchanges” from models including Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini, and xAI’s Grok, starting in 2024. Distillation, for those unfamiliar, is when you use the outputs of a large, capable model to train a smaller or newer one. Done without permission, it’s essentially copying someone else’s work through the back door.

The specifics are striking. The advisory says DeepSeek used data from Claude, Gemini, GPT, and Grok to train several of its models, including the R1 reasoning model it released in early 2025. That model caused a significant stir in the AI industry when it appeared to rival top US systems at a fraction of the reported cost. Moonshot AI allegedly pulled substantial data from Claude’s Fable model to train Kimi K3. Anthropic built Fable to bring some capabilities of its restricted cybersecurity model, Mythos, to a broader audience. Moonshot’s earlier Kimi K2 model, the agencies add, was also trained using GPT-4o data.

None of this is entirely new territory. OpenAI flagged suspected distillation of its systems shortly after DeepSeek shot to the top of the US App Store charts in early 2025, saying it had banned accounts it believed were scraping its model outputs. Anthropic made similar accusations earlier this year. But a formal, joint advisory from three federal agencies carries a different weight than a company’s press statement. It signals that the US government now views this as a national security issue, not just a commercial dispute.

And the advisory isn’t entirely clean on the American side either. It references OpenAI’s public statement about Elon Musk admitting, during cross-examination in his lawsuit against OpenAI, that xAI used OpenAI’s outputs to train its own models. So the practice isn’t limited to Chinese firms. Still, that detail is unlikely to slow the political momentum building around Chinese AI development and data practices.

For users, the deeper question is what this means long-term. If AI companies can’t protect their training pipelines, the competitive pressure to cut corners on security and access controls will only grow. That pressure tends to fall hardest on the people using these systems, whose queries and interactions are often the data at stake.