The US National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation issued a joint advisory, designated AA26-251A, alleging that several Chinese AI companies — including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — have conducted what the agencies described as aggressive, malicious and targeted distillation activity against leading American frontier AI models since late 2024. According to the advisory, the alleged activity involved extracting billions of tokens' worth of data across millions of exchanges with US-based AI systems.

Model distillation, in its legitimate technical form, refers to a widely used and generally accepted machine learning technique in which a smaller model is trained to replicate the outputs and capabilities of a larger, more computationally expensive model, allowing developers to create more efficient systems without the full cost of training from scratch. The advisory's characterisation of the alleged Chinese activity as 'aggressive, malicious, and targeted,' however, suggests the agencies view the scale and method of data extraction as going beyond conventional research practice, though the advisory reportedly stopped short of definitively confirming which specific American models were targeted.

The allegations arrive at a moment of intensifying US government focus on AI-related national security risk, encompassing both concerns about foreign actors accessing or replicating American AI capabilities and separate concerns about the safety and governance of frontier AI development more broadly. The joint nature of the advisory, spanning the NSA's signals intelligence expertise, CISA's civilian cybersecurity mandate and the FBI's law enforcement authority, signals the seriousness with which US authorities are treating the alleged distillation activity.

For the named Chinese AI companies, the advisory adds to an already complex and closely watched competitive and geopolitical dynamic, in which Chinese AI labs have made significant strides in delivering models that rival American frontier systems on key performance benchmarks, often at substantially lower operating costs, prompting persistent questions from US officials and industry observers about how that competitive parity has been achieved. Distillation from proprietary US models, if proven, would represent one explanation for how Chinese labs have been able to close performance gaps more rapidly than pure independent research investment alone might suggest.

image.png

The advisory is likely to intensify calls within US policy circles for stronger technical and contractual safeguards around API access to frontier AI models, potentially including more aggressive rate limiting, usage pattern monitoring and geographic access restrictions designed to make large-scale distillation efforts more difficult to conduct undetected. American AI companies may face pressure to implement additional protective measures even as they continue pursuing global commercial expansion that depends on broad international API accessibility.

As the geopolitical contest over AI capability continues to intensify, this joint advisory adds another significant data point to the broader narrative of technological rivalry between the United States and China, with implications likely to extend beyond the immediate companies named toward broader questions of export control policy, API governance standards and the future terms on which frontier AI capabilities are shared or protected across international boundaries.

The advisory's implications extend meaningfully to India's own rapidly growing AI ecosystem, where enterprises and government agencies alike are increasingly evaluating which foundation models to build upon, with questions of data sovereignty, training-data provenance and geopolitical alignment now factoring into procurement decisions in ways that were largely absent from AI vendor evaluations just two years ago.

US AI companies named as potential distillation targets in the underlying reporting have generally avoided direct public comment on specific technical findings, a common posture among frontier labs navigating the tension between transparency demands from policymakers and the competitive sensitivity of disclosing details about how their own models may have been accessed or exploited by rival organisations.

Policy responses to the advisory are likely to unfold gradually rather than immediately, given the technical complexity involved in designing API access controls that can meaningfully deter sophisticated distillation attempts without unduly restricting legitimate international developer access to frontier AI capabilities that remain commercially important to US AI companies' global growth strategies.