# US Intelligence Agencies Accuse Six Chinese AI Firms of Systematically Copying American Models

A joint advisory from the National Security Agency (NSA), the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) says the companies pulled billions of tokens from Claude, GPT, Gemini and Grok since late 2024.

- Published: 2026-09-09T05:13:49.099Z
- Canonical: https://polylog.news/2026-09-09/us-intelligence-agencies-accuse-six-chinese-ai-firms-of-syst
- Publisher: Polylog (Global desk)
- Section: tech
- Sources: [CoinDesk](https://www.coindesk.com/tech/2026/09/09/moonshot-s-kimi-rattled-markets-u-s-agencies-now-say-it-was-trained-on-american-models), [NBC News](https://www.nbcnews.com/tech/tech-news/us-accuses-china-ai-developers-deepseek-alibaba-copying-american-ai-rcna596696), [Bloomberg](https://www.bloomberg.com/news/articles/2026-09-09/us-says-alibaba-deepseek-have-systematically-siphoned-ai-models)

The NSA, the FBI and CISA issued a joint advisory on Tuesday accusing six China-based artificial intelligence companies of extracting proprietary capabilities from American models at industrial scale. The named firms are DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.AI, [Bloomberg reported](https://www.bloomberg.com/news/articles/2026-09-09/us-says-alibaba-deepseek-have-systematically-siphoned-ai-models).

The agencies describe a technique called distillation, in which one model is trained on the outputs of another. They say the companies pulled billions of tokens across millions of requests from Claude, GPT, Gemini and Grok since at least late 2024, often through proxy services and multiple accounts to avoid detection, [according to NBC News](https://www.nbcnews.com/tech/tech-news/us-accuses-china-ai-developers-deepseek-alibaba-copying-american-ai-rcna596696). Moonshot, whose Kimi model moved markets earlier this year, is separately accused of using data from American systems to train later versions, [CoinDesk reported](https://www.coindesk.com/tech/2026/09/09/moonshot-s-kimi-rattled-markets-u-s-agencies-now-say-it-was-trained-on-american-models). The agencies said the activity likely occurred with the Chinese government's awareness. The named companies have not publicly accepted the characterization, and the advisory presents conclusions rather than published evidence.

There is also a commercial question behind the security one. If a competitive model can be built largely from another model's outputs, the cost advantage of spending tens of billions of dollars on training runs is smaller than the capital being deployed assumes. That is a claim about returns on capital, and it applies to every company financing an AI buildout on the expectation that scale alone protects its lead.

## What this means

The advisory challenges the assumption that frontier training budgets buy a durable competitive edge. If distillation reproduces most of a model's capability at a fraction of the cost, the American firms spending heavily on computing power face shorter payback periods on that spending, which is the single most important input to valuations across the chip and platform complex. The likely policy response, tighter controls on model access and application programming interfaces, raises compliance costs for cloud providers and speeds the split of AI into two incompatible technology stacks.

## What to watch

- Whether American AI companies restrict programmatic access or add licensing conditions in response, which would immediately raise costs for legitimate overseas developers too.
- Responses from Beijing and the named firms, since a detailed technical rebuttal would carry more weight than a general denial.
- Whether Washington converts the advisory into export controls or sanctions, the step that would turn a security warning into a market event.
