US accuses DeepSeek, Alibaba and four others of model distillation

In a joint release published Tuesday, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) named six Chinese AI companies as having run industrial-scale attacks against US frontier AI models since at least late 2024: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The agencies allege the six firms have been distilling capabilities out of variants of Claude, GPT, Gemini and Grok, and that they likely did so with Chinese government awareness. Agencies say Chinese companies that pull off industrial-scale distillation against US models get significantly shorter development timelines and spend significantly less to train a frontier model of their own, a shortcut that could spare them billions in development costs.
The agencies describe two main attack methods. The first exploits AI model inference APIs: firms allegedly bulk-buy fake accounts not tied to real registered users, then run swarms of those accounts through highly coordinated queries using identical or near-identical prompt text, anywhere from thousands to millions of queries on a single topic. The second is prompt injection used to jailbreak models, including prompts engineered to force a model to reveal its hidden chain-of-thought reasoning. As a specific example, the agencies say DeepSeek used prompts that told models to imagine and articulate the internal reasoning behind an already-completed response, then write that reasoning out step by step.
The agencies say all American AI firms must work with the government and US allies to end the alleged theft, which they cast as a threat to the US lead in the AI race. Their first recommendation: AI firms must get better at detecting these campaigns, which allegedly rely on tens of thousands of accounts routed through what the agencies call 'a gray market of proxies' to evade geographic restrictions and channel distillation requests through multiple pathways to gain unauthorized access. The release carries a subheading warning that the fixes themselves may frustrate AI users in the US, though the piece does not spell out what that friction would look like in practice.
Key facts
- NSA, CISA and FBI jointly named six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, as having attacked US frontier AI models since at least late 2024.
- The agencies say the six firms likely acted with Chinese government awareness while distilling capabilities out of variants of Claude, GPT, Gemini and Grok.
- Alleged methods include bulk-bought fake accounts running highly coordinated, identical or near-identical prompts, from thousands to millions of queries on a single topic.
- A second method is prompt injection to jailbreak models into exposing hidden chain-of-thought reasoning; the agencies cite DeepSeek specifically for prompts that made models write that reasoning out step by step.
- The agencies' first recommendation is for US AI firms to improve detection of campaigns that reportedly use tens of thousands of accounts routed through a 'gray market of proxies' to dodge geographic restrictions.
Why it matters
This is not an anonymous leak or a single company's complaint: three of the US government's top security and law-enforcement agencies put their names to a joint statement naming specific competitors. That escalates the US-China contest over frontier AI models into an intelligence and cybersecurity matter, and it comes with an explicit call for the whole US AI industry to coordinate a response rather than each firm fending for itself. The agencies frame the stakes bluntly: if the alleged distillation works as described, it lets competitors approach frontier-model capability while skipping much of the time and money that training one from scratch requires, which the agencies say threatens the US lead in the AI race.
Who it affects
Six Chinese AI companies are now named by the US government: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The models the agencies say were targeted are variants of Claude, GPT, Gemini and Grok. More broadly, the recommendations are addressed to every American AI firm that runs a public inference API, since the proposed fix is about tightening account and access controls industry-wide, which in turn touches the legitimate users of those APIs who could face stricter verification as a result.
How to use it
There is no product, price or license here: this is an attack advisory, not a release. The practical takeaway is the agencies' first recommendation, that AI firms improve detection of large, coordinated query campaigns that rely on proxy-routed, bulk-bought accounts. For a company running a frontier model's API, that reads as a prompt to review rate limits, account verification and anomaly detection against exactly the pattern described: swarms of near-identical prompts on the same topic, arriving from accounts that trace back to a proxy network rather than a registered user.
How solid is it
The source is about as strong as this kind of claim gets: a joint statement from three named federal agencies, not a rumor or a single anonymous source. But the underlying accusation stays framed as allegation throughout. The agencies call the government-awareness link only 'likely', and the piece itself refers to 'the alleged theft' rather than a proven one. Key figures are left unquantified: the 'billions' in spared development costs carries no currency or exact number, and the release itself is dated only to a day of the week, with no calendar date given. Nothing in the material says whether any of the six named companies have responded, or what, if anything, the US government plans to do beyond issuing recommendations.
Risks and caveats
The agencies' own release carries a subheading warning that the recommended fixes 'may frustrate AI users in US', but the piece does not explain the mechanism, so it is unclear how much friction legitimate customers of US inference APIs should expect if firms act on the advice. The financial claim is an estimate embedded in the framing, not a sourced figure: 'billions' with no amount attached. And because every quote in the release is attributed to the three agencies collectively rather than to a named official, there is no individual spokesperson on record to press for specifics if any of the claims are disputed.
“China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model”
— NSA, CISA and FBI, joint statement