Washington names six Chinese AI companies and says they trained on American models' answers. Beijing calls it baseless.

A joint NSA, CISA and FBI advisory accuses DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.AI of "industrial-scale" distillation; China's commerce ministry says the claim has no basis and promises countermeasures if the US acts.

· 4 min read

What happened

On 8 September three US agencies, the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI, published a joint advisory that names six Chinese AI companies. It says that "likely with Chinese government awareness", DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI "extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024". The technique is called distillation: asking an existing model many questions and training a new model on its answers. The advisory calls distillation "a legitimate and useful technique in AI research" but describes these campaigns as "aggressive, malicious, and targeted".

The advisory is specific about who did what, in its own account. It says Moonshot "extracted significant Claude Fable 5 data to train its Kimi-K3 model" and that MiniMax "redirected exchanges to a new Claude model within 24 hours of release". It also says DeepSeek's "publicly quoted training costs of $5.6M are misleading" because they exclude the cost of distilled data.

China answered within a day. The Ministry of Commerce said the allegation "has no basis in fact and no basis in law" and that if the US "takes actions to contain and suppress Chinese AI companies" in the name of fighting distillation, China "will resolutely take measures to counter them". It added that the two presidents have agreed to hold an intergovernmental dialogue on AI. The foreign ministry's spokesperson, Mao Ning, said China hoped the US would "not make untrue accusations against or smear China" and that the two countries "should strengthen cooperation".

Why it matters

The advisory lands on a stack this site already tracks. MiniMax, one of the six, built the 428 billion parameter Arabic model that Saudi Arabia's HUMAIN put into research preview on 3 September. Moonshot is on this site as the lab behind the largest open-weight model of the year.

A worked example from prices on this site. OpenAI's GPT-6 Astra charges 50 dollars per million output tokens. One billion output tokens at that list price would cost 50,000 dollars, our arithmetic, and the advisory says the volume ran to "billions of tokens". The day after China's reply, DeepSeek published a new model, V4.1-Flash, priced at 1.20 dollars per million output tokens at peak.

The models named as targets, the price gap, and an earlier US move on Chinese AI.
  1. Guidance: US chip licence rules reach Chinese firms' overseas arms (our reading: an earlier US action on Chinese AI was about chips; this one is about model outputs)
  2. $50: GPT-6 Astra output price per million tokens (stated: the advisory names GPT, Claude, Gemini and Grok as the models distilled)
  3. 6 companies: NSA, CISA, FBI advisory named for distillation (our reading: a named company's newest model, priced two days after the advisory)
  4. $1.20: DeepSeek V4.1-Flash output, per million, peak (announced: another named company built a Gulf state's Arabic model)
  5. 428B params: HUMAIN's Arabic model built by MiniMax

What would change it, and when

The advisory itself imposes nothing. It "recommends" that US AI companies take three immediate actions, including monitoring "subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns", and it advises them to alter responses to confirmed distillers without informing them. What would change the picture is a US government move beyond advice, the trigger China's commerce ministry named for countermeasures, or the AI dialogue it mentioned producing something. No date is given for either.

What we do not know

The advisory does not publish its evidence; it describes campaigns and lists models in a table. None of the six companies' own statements were found in this sweep, and none of the US labs named as targets has published a matching account. We read the advisory through an archived copy because cisa.gov blocks this environment. Whether US agencies have named companies this way before is not something the advisory says, and we did not check. And "likely with Chinese government awareness" is the agencies' own hedge, which we keep.

What this changes for you

If you use an American frontier model through an API and your provider adopts the advisory's recommendations, expect more monitoring of your usage, especially on a new account. If you use a Chinese model, nothing changes today; one of the named companies published cheaper prices this morning.

Sources

Everything above is written from these. Each line says what that document proves.

  1. cisa.gov: The advisory, AA26-251A, release date 8 September 2026: the six companies, the models, "billions of tokens", "since at least late 2024", the three recommended actions. Read via the archived copy at web.archive.org because cisa.gov returns 403 to this environment.
  2. mofcom.gov.cn: China's Ministry of Commerce spokesperson, 9 September, Chinese text: no basis in fact or law, the countermeasures warning, the presidents' AI dialogue.
  3. fmprc.gov.cn: China's foreign ministry press conference, 9 September: Mao Ning's answer on the advisory, a second ministry speaking for itself.
  4. api-docs.deepseek.com: DeepSeek's price list: the $1.20 peak output price for V4.1-Flash.
  5. openai.com: The $50 output price already on this site from 3 September. openai.com returned 403 to this run; the figure rests on the published 3 September item.

Strata, the whole AI stack, explained simply. Every number carries a source and a confidence label.

Today · The Stack · Latest issue · Archive · Glossary · Break the Chain · Focus

Privacy · Terms · Corrections · Report an error

Also from Dheeco: Dheeco · AP Fact Check

Published by dheeco.com · © 2026 Dheeco