Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
CISA, NSA and FBI Name Six Chinese AI Firms in Formal Advisory Over Model-Distillation Campaign

Since the White House first raised the alarm on Chinese AI distillation campaigns in April 2026, US officials have moved from general warnings to naming names. On Tuesday, September 8, CISA, the NSA and the FBI issued a joint cybersecurity advisory accusing six Chinese companies of running what they call an "industrial-scale" theft operation against America's top AI labs.
The advisory, posted on CISA's site, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It says these firms have extracted billions of tokens across millions of exchanges from US frontier models, including versions of Anthropic's Claude, OpenAI's GPT line, Google's Gemini and xAI's Grok, going back to at least late 2024.
The technique at the center of this is called knowledge distillation. A smaller "student" model trains itself by studying the outputs of a bigger, more advanced "teacher" model. It's a legitimate and common machine-learning method. American labs use it too.
What crosses the line, according to the advisory, is scale and evasion. CISA says the Chinese firms routed requests through a "gray market of proxies" nicknamed "transfer stations," used fraudulent accounts, and violated the terms of service that govern access to the US models. "China-based AI companies are engaging in aggressive, malicious and targeted distillation activities at an industrial scale," the officials wrote, according to Reuters.
The advisory gets specific on tactics. DeepSeek allegedly targeted reasoning and agentic capabilities from GPT-4, GPT-5 and multiple Claude versions to build its R1 and V3 models, according to Quartz. The agencies say DeepSeek's widely cited $5.6 million training-cost figure is misleading because it excludes the cost of the distilled data. Moonshot AI allegedly pulled from Claude to train its Kimi K3 model.
Anthropic, separately, said three Chinese labs generated over 16 million exchanges with Claude through roughly 24,000 fraudulent accounts, according to CNN. That's Anthropic's own telemetry, not a government estimate, and it's the most concrete single data point in this story.
The agencies went further than describing a corporate scheme. They said the campaign was likely conducted "with Chinese government awareness," and Reuters reported the advisory ties the extracted capabilities to improvements in China's "military and cyberattack capabilities that could be used against the U.S. and our allies." That's a serious claim, and it's an allegation, not something the advisory backs with named evidence in the versions of the document available. Reuters also noted its own July 31 reporting that Chinese military researchers have used outputs from leading US models to train domestic defense-related systems.
Treasury Secretary Scott Bessent responded on X: "When PRC firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table." An Entity List designation would cut the named firms off from American cloud services, chips and software.
China's Foreign Ministry spokesperson Mao Ning rejected the accusations Wednesday, saying China's AI progress reflects "high-level science and technological self-reliance" and calling on Washington to "refrain from making false accusations and smearing China." A Chinese Embassy spokesperson in Washington called the US framing a "deliberate attack on China's development and progress in the AI industry." None of the six named companies responded to requests for comment from Bloomberg or CNN.
A fair question sits underneath all of this: distillation is a legal, widely used technique, and the line between aggressive-but-legitimate research and outright theft is drawn by terms-of-service violations, not by a specific law banning the practice. That makes "industrial-scale IP theft" partly a legal argument, not a settled fact, and it's the argument Beijing is making when it calls this a pretext to slow China's AI industry down. The advisory's claim of government "awareness" is also labeled "likely" by the agencies themselves, not proven with named evidence.
A Reuters report carried by KFGO listed SpaceX among the American firms whose models were targeted. Every other source, including the CISA advisory itself, identifies xAI's Grok as the fourth targeted model, not SpaceX. That appears to be an error in that write-through.
The timing isn't accidental. Trump is set to host Xi Jinping in Washington later in September, and a US-China dialogue on AI safety risks is planned for mid-September, according to Reuters. Whether Bessent actually pulls the trigger on Entity List designations, or whether this advisory becomes a bargaining chip ahead of those meetings, is the open question nobody in Washington or Beijing has answered yet.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.