On September 8, the US National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI jointly issued a cybersecurity advisory naming six Chinese artificial intelligence companies, accusing them of using "distillation" to extract proprietary capabilities from advanced US models at scale in order to speed up training of their own products. Public reporting has explicitly named three of the six: DeepSeek, Moonshot AI, and Alibaba.
The advisory says the targeted models come from Anthropic, OpenAI, Google, and SpaceX; that the activity "was likely conducted with the knowledge of the Chinese government"; and that the companies involved took steps to avoid detection by spreading the activity across platforms rather than concentrating it on one. The agencies also wrote that the resulting capability gains could further strengthen China's military and cyberattack capabilities.
Distillation itself is not the accusation
Distillation is a standard training technique: you take the outputs of a bigger, more expensive model and use them to train a smaller one, saving time and money. Academia has used it for years, and every lab uses it internally — it's basically how large models get compressed into smaller, on-device ones.
The advisory's actual target isn't the method, it's the authorization and the scale. The accusation is that these companies did this without authorization, at industrial scale. That distinction is spelled out explicitly in the text, and it's the part most likely to get lost in retelling. Strip it out, and the story becomes "using distillation is theft" — which doesn't hold up.
What's missing
The public version of the advisory does not include the technical evidence behind the accusation — no call logs, no account attribution, no concrete figures on the scale of the extraction. The phrase "likely conducted with the knowledge of the Chinese government" is stated as a probability, not a finding. As of publication, neither the named companies nor Chinese officials have issued a public response, and the document itself outlines no follow-up enforcement or sanctions.
For businesses, there's only one thing that's certain: the terms of service for US model providers have long banned using their outputs to train competing models. What's changed is where that rule lives — it used to be a contract clause enforced by a platform banning accounts; now it appears in a joint advisory from national security agencies, which is a different order of seriousness.
Timing
The advisory lands just ahead of two events: the US and China are expected to discuss AI safety risks in mid-September, and Xi Jinping is expected to visit the US in late September. On the same day, US Treasury Secretary Scott Bessent said publicly that if the US loses the AI race to China, the consequences would be severe.
For domestic model makers, the direct impact isn't the advisory itself — it carries no legal force. The impact is downstream. For products going overseas that connect to US cloud services, list on US app stores, or sign US enterprise customers, it's an easy thing for procurement teams to add a line to their compliance questionnaires: "does your model's training data include outputs from third-party models?" Several leading domestic model makers have spent the past couple of years pushing into overseas enterprise markets, and that line won't be easy to fill in cleanly — when it comes to the provenance of training data, if you can't clearly account for it, that itself becomes the problem.
There's also the evidence problem. Traces of distillation live in the weights, not in files, and there's currently no accepted method for a third party to prove or disprove it. Academic proposals for watermarking or fingerprinting model outputs have circulated for a few years, but they remain confined to papers — none has been accepted as evidence. That's also why accusations like this tend to stop at a warning and rarely make it to litigation.
The visible impact on domestic users right now is close to zero: the named products are running as usual, and there's no change to their APIs or apps at home. What's worth watching is the other side — US model providers may tighten detection and enforcement around how their outputs are used, and teams doing secondary development that rely on overseas APIs face somewhat higher account risk than before.
Sources: joint NSA, CISA and FBI cybersecurity advisory, Reuters, CocoLoop, United Daily News, Sing Tao Headline; the number of companies named follows the advisory text — public reporting has explicitly identified three, with the remaining three undisclosed.