Morning Edition · Wednesday, September 9, 2026Published at 1:13 AM EDT · New York
A joint advisory from the National Security Agency (NSA), the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) says the companies pulled billions of tokens from Claude, GPT, Gemini and Grok since late 2024.

The NSA, the FBI and CISA issued a joint advisory on Tuesday accusing six China-based artificial intelligence companies of extracting proprietary capabilities from American models at industrial scale. The named firms are DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.AI, Bloomberg reported.
The agencies describe a technique called distillation, in which one model is trained on the outputs of another. They say the companies pulled billions of tokens across millions of requests from Claude, GPT, Gemini and Grok since at least late 2024, often through proxy services and multiple accounts to avoid detection, according to NBC News. Moonshot, whose Kimi model moved markets earlier this year, is separately accused of using data from American systems to train later versions, CoinDesk reported. The agencies said the activity likely occurred with the Chinese government's awareness. The named companies have not publicly accepted the characterization, and the advisory presents conclusions rather than published evidence.
There is also a commercial question behind the security one. If a competitive model can be built largely from another model's outputs, the cost advantage of spending tens of billions of dollars on training runs is smaller than the capital being deployed assumes. That is a claim about returns on capital, and it applies to every company financing an AI buildout on the expectation that scale alone protects its lead.
Part of a tracked trend
China Builds a Parallel Technology Stack
United States export controls push China to develop its own chips, computing hardware and artificial-intelligence systems, accelerating a split of global technology into competing spheres that reshapes supply chains and standards.
American frontier labs gain a security argument for restricting programmatic access to their models and for tighter export rules, which protects the valuation premium attached to large training budgets, and Beijing gains a grievance to cite as technological containment.
The advisory exists and names the six firms, as CISA published it as AA26-251A, but the agencies released conclusions rather than forensic evidence, distillation through interface terms is a contract violation rather than an established intrusion, and China's commerce ministry rejects the finding while asserting American firms distill Chinese models.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The advisory challenges the assumption that frontier training budgets buy a durable competitive edge. If distillation reproduces most of a model's capability at a fraction of the cost, the American firms spending heavily on computing power face shorter payback periods on that spending, which is the single most important input to valuations across the chip and platform complex. The likely policy response, tighter controls on model access and application programming interfaces, raises compliance costs for cloud providers and speeds the split of AI into two incompatible technology stacks.
Start a discussion in Townsquare.
More from this edition
What to watch
Observations to monitor, not financial advice.
Comments
0No comments yet.