The US National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI issued a joint cybersecurity advisory on September 8, 2026 accusing six China-based AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, of running industrial-scale distillation campaigns against American frontier models since 2024. The advisory says the companies pulled billions of tokens across millions of requests from Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini and xAI’s Grok to train their own systems. It also tells US AI providers to watch account usage patterns more closely and to quietly alter responses for suspected distillers rather than simply banning them.
What the three agencies are alleging
Distillation is a standard machine learning technique: a smaller or newer model is trained on the outputs of a larger, more capable one. The advisory, published by CISA as AA26-251A and announced in a press release from the NSA, is careful to say the technique itself is legitimate. The complaint is about scale and intent. According to the agencies, the six companies systematically extracted restricted, proprietary capabilities of US models so they could close the technology gap without paying the research, compute and electricity costs that producing a frontier model requires.
The specific claims are detailed. Engadget’s summary of the advisory reports that DeepSeek is accused of drawing on multiple versions of Claude, GPT, Gemini and Grok to generate training data, including for its R1 reasoning model released in early 2025. Moonshot AI is accused of extracting significant data from Claude Fable to train Kimi K3, and of using GPT-4o output to build Kimi K2. The NSA release adds that the companies deliberately spread their activity across multiple model providers, cloud platforms and API aggregators so that no single company could see the full picture.
Anthropic made similar accusations against DeepSeek, Moonshot and MiniMax earlier this year, covered in Anthropic Claims DeepSeek and Other Chinese AI Firms Misused Claude. What changed on September 8 is that three US government agencies put their names to the claims and published a mitigation playbook for the industry.
The mitigation playbook is the part that touches ordinary users
CISA’s announcement asks US frontier AI companies to take three actions. First, build detection for anomalous prompts, accounts and networks, including monitoring subscription-to-usage ratios and enterprise-scale throughput on accounts that are not enterprise customers. Second, deploy what the agencies call targeted response changes: subtly altering the answers served to accounts suspected of malicious distillation, instead of blocking them outright, so that the distiller does not know it has been detected. Third, share intelligence across model providers, cloud platforms and API aggregators so activity can be correlated.
The advisory also describes the tactics it wants providers to look for, and this is where it stops being a story about DeepSeek and becomes a story about how many people in Pakistan and the Gulf actually reach these tools. The techniques named include fraudulent accounts, bulk purchases of premium subscriptions, and proxy routing services that pass traffic through intermediary servers to hide its origin and get around regional restrictions.
Why a freelancer in Lahore or Riyadh should read this carefully
A large share of AI tool usage in this region runs through exactly the patterns the advisory flags. Group-buy ChatGPT and Claude subscriptions sold in Facebook groups, where one premium login is shared between ten or twenty people. Reseller accounts paid for through a third party because a local card was declined. VPNs that hop between countries. Unofficial API aggregators that resell access to several models through a single key. Individually, each of these is a workaround for a payment or availability problem, and the people using them are writing proposals and client emails, not training rival models.
The problem is that from the provider’s side, a shared login with twenty users hitting the API from five countries looks a lot like the “transfer station” behaviour the agencies have just told them to hunt for. And the recommended response, rather than a ban notice, is quietly worse output. If your provider adopts the advisory’s guidance, an account that trips the detection could start receiving degraded answers with no warning and no way to appeal, because the whole point of the technique is that the target does not find out.
This sits alongside a separate risk we reported this week in Hackers Are Stealing Claude Tokens From Paying Subscribers: shared and resold credentials are already a target for theft, and now they are also a signal that providers are being asked to treat with suspicion.
The practical steps are unglamorous. Pay for your own account where the service is officially available in your country. Do not share logins. If you use a VPN for other reasons, keep your AI tool traffic on a consistent location. If you build on an API, use the official one with your own key rather than a reseller’s aggregated key, so your usage pattern reflects your actual product. And if quality drops sharply on a shared account, consider that the account, not the model, may be the cause.
The unanswered question
The advisory is guidance, not a legal order, and the agencies have not said how many providers have adopted response degradation or how accurate the detection is. Whether the industry can separate a Guangzhou training pipeline from a shared account in Faisalabad is the question that will decide how much collateral damage this policy causes outside the United States. For now, the safest assumption is that providers will err toward suspicion, and that legitimate users on the margins will need to make their usage look as ordinary as it really is.






