The NSA, CISA, and FBI said China-based AI firms have been running industrial-scale distillation campaigns against U.S. frontier models since at least late 2024, extracting billions of tokens across millions of requests. The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, and says the targets included Anthropic Claude, OpenAI ChatGPT, Google Gemini, and xAI Grok.
The method is repeated querying, not model theft: the firms push huge volumes of prompts, collect the answers, and train their own systems on that output. They route traffic through native APIs, cloud providers, third-party aggregators, and proxy “transfer stations” to hide metadata, evade geographic restrictions, and keep the activity looking like ordinary usage while turning a public API into a source of proprietary behavior.
For providers and operators of frontier models, the exposure sits in the service layer itself: rate patterns, account controls, and routing paths become part of the IP perimeter. If a model’s best behaviors are available through an API, this advisory says those behaviors can be copied without touching the underlying weights or training environment.