The agencies said the companies collected billions of pieces of model output through millions of requests, likely with the Chinese government’s awareness.
Three U.S. security agencies accused six China-based AI companies of systematically extracting capabilities from leading American AI models to accelerate development of their own products.
The National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI in a joint cybersecurity advisory.
The agencies said the companies had collected billions of units of AI-generated text and code through millions of exchanges with Claude, GPT, Gemini, and Grok models since at least late 2024. This process is called ” distillation,” a method in which developers train a smaller or less advanced model on the outputs of a more capable system.
They assessed that the activity occurred “likely with Chinese government awareness.” The advisory did not detail the evidence supporting that assessment or allege that the Chinese government directed the individual operations. This isn’t the first time the US government has accused Chinese companies of distillation activities. In April, the U.S. State Department launched a global diplomatic effort to warn allied governments about alleged intellectual property (IP) theft by Chinese AI companies.
Companies allegedly concealed millions of requests
While some distillation practices are legitimate, the agencies said this activity was improper because the companies allegedly conducted it secretly on an industrial scale, bypassed access restrictions, and violated U.S. providers’ terms of use.
Rather than obtaining the underlying American models, the companies allegedly sent large numbers of carefully coordinated questions designed to draw out valuable capabilities. The resulting answers could then be assembled into datasets used to train Chinese models to perform similar tasks.
Some requests allegedly attempted to make the American models reveal the step-by-step processes they used to reach an answer. That information could help another model learn how to complete complex tasks, rather than merely copying individual answers.
The companies reportedly spread the requests across ordinary subscriptions, cloud services, and businesses that resell access to multiple AI models. The agencies said some of these intermediary services concealed where requests originated, allowing users to evade geographic restrictions and making the activity harder to trace.
The companies also allegedly bought premium subscriptions in bulk, shared accounts among teams of developers, and automatically moved requests to another service when one access route was blocked.
DeepSeek allegedly used four U.S. model families
The advisory said DeepSeek conducted an organized operation beginning in late 2024 to generate training material for its R1 and V3 models.
DeepSeek allegedly collected answers and capabilities from versions of Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini, and xAI’s Grok.
The agencies also challenged DeepSeek’s widely cited claim that training its V3 model cost $5.6 million. They said that figure excluded the cost and value of training material obtained through the alleged distillation activity. The advisory did not provide its own estimate of that value.
The agencies said Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI also used outputs from U.S. models to improve their own AI systems.
According to the advisory, this approach allowed the companies to reduce the time and expense required to develop advanced AI models while reproducing capabilities that had required substantial investment by U.S. companies.
Agencies recommend quietly reducing the value of answers
After describing the alleged activity, the agencies urged U.S. AI companies to look for accounts that begin using the maximum available capacity immediately, operate continuously without normal breaks, or generate unusually large numbers of similar requests.
When a company has strong evidence that an account is being used for improper distillation, the advisory recommends quietly making its answers less useful for training another model. That could include providing less detailed explanations or directing the requests to a less capable model.
The agencies said suspected operators should not be told when such changes are made because that information could help them adjust their methods. Legitimate AI safety researchers and outside evaluators, however, should be informed when they receive results from a different model.
The advisory also called on AI developers, cloud companies, and services that provide access to multiple models to share information. Activity that appears unremarkable to one provider could reveal a coordinated operation when compared with similar requests seen by other companies.
China rejects the allegations
China’s Commerce Ministry rejected the U.S. allegations, saying they lacked factual and legal support.
The ministry described distillation as a commonly used technical method and accused the United States of applying a double standard. It also claimed that American companies have used Chinese models in their own distillation work.
The ministry said China would respond if the United States used the allegations to impose restrictions on Chinese AI companies.

