US accuses Chinese AI firms of industrial-scale copying

Published

The NSA, CISA and the FBI have jointly accused six Chinese companies of building their artificial intelligence models out of American ones. In an advisory published on Monday, the three agencies name DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and say that since at least late 2024 those firms have extracted billions of tokens across millions of requests from US frontier models, including variants of Claude, GPT, Gemini and Grok.

Nobody was hacked. That is the part worth holding on to.

What the agencies describe is the abuse of ordinary paid access, done at a scale they call industrial. The technique itself, knowledge distillation, is unremarkable: you train a smaller model on the outputs of a larger one, and researchers everywhere do it. The claim in the joint advisory is about volume and intent, that for these companies distillation forms the core of the development strategy rather than a supplement to it, and that the extraction targeted restricted proprietary capabilities in breach of the American vendors' terms of use. The agencies assess this was carried out likely with the awareness of the Chinese government.

A gray market of transfer stations

The routes described are mundane and hard to close. Requests went through native APIs, through remote cloud providers, and through third-party aggregators that automatically obfuscate user metadata. To get around geographic restrictions the agencies say the companies leaned on a gray market of proxies known as "transfer stations", which also breaks the traceability a provider would need to attribute the traffic. Costs were held down by buying premium subscriptions in bulk and sharing them across teams of developers.

The tradecraft on top of that is what makes the advisory read like a threat report rather than a policy complaint. It describes chain-of-thought reasoning extraction, automated failover between access pathways when one gets blocked, and quality-evaluation frameworks built specifically to notice when a provider has started returning degraded answers.

Which company took what

DeepSeek is described as running an organized campaign since at least 2024, going after reasoning capabilities, specialized optimizations and domain-specific functions to generate synthetic training data for its R1 and V3 models. The agencies argue that the company's publicly quoted training cost of 5.6 million dollars is misleading because it excludes the true cost of data acquired this way. Alibaba is said to have used the same approach to improve its Qwen family. Moonshot AI, active since at least mid-2025 on the agencies' account, is described as extracting Claude Fable 5 data to train Kimi-K3 and GPT-4o data to train Kimi-K2. MiniMax, StepFun and Z.AI are named as engaging in the same activity without the same level of detail.

Watch the billing, not the prompts

The defensive advice is aimed squarely at the model providers, and the useful part of it is not about prompts. The agencies tell companies to monitor subscription-to-usage ratios, accounts that hit maximum usage immediately after creation, and enterprise-scale throughput patterns, which is a billing and telemetry problem rather than a content-filtering one. They also suggest something more unusual: subtly altering responses to suspected distillation traffic so that the extracted data is worth less, rather than simply blocking the account and revealing the detection. The third recommendation is cross-organization intelligence sharing, correlating activity across model providers, cloud platforms and API aggregators, because no single vendor can see a campaign that has been deliberately spread across all of them.

The advisory publishes conclusions rather than the evidence behind them, so readers outside the agencies cannot check the attribution themselves. What it does establish is the shape of the concern. American AI companies now have to treat their own paying customers as a threat surface, which is a different discipline from the network defense they have been buying, and a long way from the router implants and edge-device footholds that China-linked operations are usually associated with, such as the campaign turning Cisco routers into listening posts reported last week.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions