Three US federal agencies have accused Chinese artificial intelligence companies of conducting "aggressive, malicious, and targeted distillation activities at an industrial scale" to extract protected capabilities from American frontier AI models. A joint advisory issued Tuesday by the National Security Agency, Federal Bureau of Investigation, and Cybersecurity and Infrastructure Security Agency claims that distillation isn't just a supplementary technique but rather the core of Chinese AI companies' development strategy. The agencies allege that China's government is likely aware of these campaigns targeting US models.
The advisory identifies six Chinese companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—as participants in what the agencies describe as systematic distillation operations. According to the agencies, these firms route distillation requests through multiple channels to gain unauthorized access and violate US AI companies' terms of service, including native APIs, remote cloud providers, and third-party aggregators that automatically hide user metadata to avoid detection. The advisory also describes a gray market of proxies called "transfer stations" that resell access to frontier models at a fraction of official prices, creating what the agencies call a scalable mechanism for evading provider safeguards and undermining traceability. The document specifically accuses DeepSeek of using distillation to generate synthetic data for training its models, and alleges that Alibaba used industrial-scale distillation to enhance its Qwen family of AI models.
The agencies claim that Chinese AI companies breach US providers' geographic restrictions, violate terms of use, evade safeguards, and erode traceability through these transfer station proxies. The advisory notes that DeepSeek's claim of creating models with minimal computing power is false, an accusation that carries weight because DeepSeek's original assertions caused investor panic over whether billions in infrastructure spending were necessary. The document also points to Alibaba's Qwen models as a direct challenge to US-based AI companies, since some Qwen models offer very high quality for free while American firms charge for access yet continue posting massive losses.
Distillation works by having a smaller model repeatedly query a larger one to learn its response patterns, improving performance over time without the lengthy and expensive training process required to build a model from scratch. While distillation can be legitimate when a company creates a smaller version of its own model, commercial model providers typically prohibit the practice in their terms and conditions to protect substantial technology and training investments. The agencies recommend that AI companies attempt to detect and deflect distillation attacks, suggesting that immediate maximum usage from new accounts signals potential malicious activity. They also propose subtly altering responses for suspected distillation attempts to reduce the payoff for companies running industrial-scale campaigns, and recommend correlating activity across different model providers, cloud platforms, and API aggregators to reveal distributed distillation operations.
The advisory follows a pattern of similar accusations from US government agencies in recent months, while China has countered that American companies are the real offenders distilling Chinese models and has issued veiled threats of retaliation if the US bans Chinese technology based on distillation allegations. The agencies' recommendations center on detection and disruption rather than policy changes, leaving AI companies to implement technical defenses against what the advisory frames as a core national security threat. The underlying tension isn't likely to ease without either diplomatic resolution or significant shifts in how frontier models are protected and accessed globally.

