The most striking detail buried in this story is not that Chinese companies are accused of copying American AI models. It is that US intelligence agencies are now naming specific models, specific companies, and specific training runs. That is a significant escalation.
According to Engadget, the NSA, CISA, and FBI issued a joint cybersecurity advisory accusing DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of running what they call “distillation activities at an industrial scale.” The agencies say these companies extracted “billions of tokens across millions of exchanges” from Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini, and xAI’s Grok, starting in 2024.
Distillation, for those unfamiliar, is a legitimate AI training technique where a smaller or newer model learns by studying the outputs of a larger, more capable one. The problem is doing it without authorization against commercial APIs. That crosses from technique into theft, at least under US law and the terms of service these providers enforce.
The advisory gets specific. DeepSeek allegedly used outputs from multiple Claude, Gemini, GPT, and Grok models to train its R1 reasoning model, which was released in early 2025 and made a major splash when it topped the App Store charts. Moonshot AI’s Kimi K3, widely considered one of the most capable models built by a Chinese lab, is accused of being trained on data extracted from Claude Fable, Anthropic’s public-facing version of its Mythos cybersecurity model. Moonshot’s Kimi K2 reportedly pulled from GPT-4o as well.
None of this is entirely new ground. OpenAI and Microsoft said early last year that they had banned accounts suspected of distillation, with DeepSeek named as a target of that investigation. Anthropic made similar allegations against DeepSeek, Moonshot, and MiniMax earlier this year. But a formal joint advisory from the NSA, CISA, and FBI carries a different weight. It signals that the US government now treats model distillation as a national security issue, not just a terms-of-service dispute.
The advisory also includes mitigation guidance for American AI companies, which points to a real gap. Right now, there is no standard industry playbook for detecting or blocking large-scale distillation campaigns. That is likely to change. Expect API rate limiting, behavioral fingerprinting, and output watermarking to get much more attention from security teams at major AI labs.
And there is one uncomfortable footnote worth keeping in mind. The advisory focuses on Chinese companies, but the same Engadget report notes that Elon Musk admitted during cross-examination to using OpenAI’s outputs to train xAI models. So the practice is not unique to one geography. The geopolitical framing here is real, but the underlying problem, AI companies training on each other’s outputs without permission, is an industry-wide issue that no one has fully solved.




