China AI Distillation Advisory: What It Means
The headline is a geopolitics story. The mitigations section is about the shape of your API traffic, not your intentions.
China AI Distillation Advisory: What It Means
On 8 September 2026 the NSA, CISA and the FBI published joint advisory AA26-251A, alleging that six China-based AI companies have run industrial-scale knowledge distillation campaigns against US frontier models since late 2024. The headline is a geopolitics story. Buried in the mitigations section is something that affects anyone paying for model APIs: the agencies recommend that providers "subtly alter responses for suspected malicious distillation attempts". If you run high-volume automated traffic against a model API, that recommendation is about the shape of your traffic, not your intentions.
What the advisory alleges
CISA's announcement names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and says they extracted billions of tokens across millions of requests from variants of Claude, GPT, Gemini and Grok.
Two specific campaigns are described in the reporting on the advisory:
Company | Period | Models allegedly distilled from | Result |
|---|---|---|---|
DeepSeek | Late 2024 to mid-2025 | Claude 3.7, Claude Sonnet 4, Claude Sonnet 4.5, Claude Opus 4.1, Gemini 2.5 Pro Preview, Gemini 2.5 Flash Preview, GPT-4, GPT-4o, GPT-4 Mini, GPT-4 Nano, GPT-5, Grok 4 | R1 and V3 |
Moonshot AI | Since at least mid-2025 | Claude Fable 5, GPT-4o | Kimi-K3, Kimi-K2 |
The access routes named are native APIs, cloud providers reselling model access, and third-party aggregators that obscure user metadata by design. Bloomberg's coverage reported the same allegations the following day.
Worth being precise about the vocabulary. Distillation itself is an ordinary, published technique: you train a smaller model on the outputs of a larger one. We have an explainer on how it works. What the advisory alleges is not that distillation happened but that it was done at scale against models whose terms of use forbid it, through routes chosen to avoid detection.
The mitigation that has a cost for legitimate users
The advisory's recommendations to model providers fall into three groups: detect anomalous usage, respond to suspected abuse, and share intelligence across providers, cloud platforms and aggregators.
The detection signals named are worth reading closely, because they describe ordinary automation as much as they describe espionage:
Anomalous subscription-to-usage ratios, meaning an account paying a small amount while pulling a large volume of tokens.
Near-maximum throughput from new accounts.
Enterprise-scale request patterns from accounts that do not look like enterprises.
Now put that next to the recommended response: subtly alter responses for suspected campaigns, to reduce the value of what an attacker extracts. That is a deliberate, quiet quality reduction applied to accounts a classifier has flagged.
If you are a two-person team running a batch pipeline that hammers an API overnight from a new account on a modest plan, you match all three detection signals. There is no suggestion in the advisory that providers should tell you when they apply the response, and by design the response is meant not to be obvious.
How you would notice, and what to do about it
The practical defence is unglamorous: have a fixed evaluation set you re-run on a schedule, so that a quiet degradation shows up as a number rather than a hunch.
Keep a golden set. Thirty to fifty prompts with known-good outputs, covering your real task mix. Score them the same way every time.
Run it on a schedule, not on suspicion. Weekly is enough for most people. The point is to have a baseline from before anything changed.
Record the model version and date with every run. Without that, you cannot tell a degradation from a routine model update. We wrote about the general version of this problem in why an AI model seems worse after an update.
Keep your account's traffic profile explainable. A billing plan that matches your throughput, a stable account age, and traffic that goes through the provider's own API rather than an anonymising aggregator all reduce the odds you look like the thing the advisory describes.
Read your provider's terms on training and outputs. Restrictions on using outputs to train competing models are now enforcement priorities, not boilerplate. Our checklist on whether an AI tool trains on your data covers the reciprocal question.
The second-order effect worth watching
The advisory asks providers, cloud platforms and API aggregators to coordinate on identifying distributed campaigns. Coordination of that kind tends to produce shared blocklists, and shared blocklists tend to produce collateral damage at the edges. Aggregators and routers, which many small teams use precisely because they smooth over provider differences, are named as a route of concern.
That does not mean routing through an aggregator is now risky in itself. It does mean the category is under more scrutiny than it was last week, and that a vendor's answer to "how do you handle provider abuse-detection signals" is a reasonable thing to ask about. The broader map of what can go wrong when you depend on someone else's model sits in our overview of AI risks, and the narrower question of what your tooling transmits upstream is covered in what your AI coding assistant sends to the vendor.
FAQ
What is advisory AA26-251A?
A joint cybersecurity advisory published 8 September 2026 by the NSA, CISA and the FBI, alleging industrial-scale knowledge distillation campaigns by China-based AI companies against US frontier models.
Which companies are named?
DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The models allegedly targeted include variants of Claude, GPT, Gemini and Grok.
Is model distillation illegal?
Distillation is a standard machine learning technique and is not illegal in itself. The advisory's allegation concerns doing it at scale in violation of providers' terms of use, using access routes designed to avoid detection.
Could my own API traffic be flagged?
The detection signals the advisory recommends, low subscription-to-usage ratios, near-maximum throughput from new accounts, and enterprise-scale patterns from non-enterprise accounts, can describe legitimate batch workloads. Keeping a regularly scored evaluation set is the cheapest way to detect a quiet change in output quality.
How did this land?
About the author

Senior Editor, AI & Product
Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.


