TL;DR
- NSA, FBI, and CISA issued a joint advisory on Tuesday accusing six Chinese AI companies of industrial-scale distillation of US frontier models.
- DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI are named directly. The agencies say distillation is ‘the core, not merely a supplement, of their AI development strategy.’
- DeepSeek is specifically accused of hiding its reliance on distilled synthetic data behind claims of using trivial compute power.
- Alibaba’s free Qwen models get singled out as a direct threat to US providers that charge for access while burning cash.
Three Agencies, One Blunt Accusation
The NSA, FBI, and CISA don’t usually issue joint advisories about AI business models. But that’s exactly what happened this week, and the language they chose wasn’t diplomatic. The agencies described what they’re seeing as aggressive, malicious, and targeted distillation activity at an industrial scale, aimed at extracting restricted proprietary functionalities and capabilities from US frontier models.
Six companies got named by name: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. That’s not a vague gesture at ‘Chinese AI’ as a category. It’s a list, and lists invite scrutiny. The advisory’s central claim is the one worth sitting with: distillation, the agencies wrote, is ‘the core, not merely a supplement, of their AI development strategy.’ Not a shortcut. Not a side hustle. The whole engine.
How is this supposedly happening? The advisory points to a familiar set of workarounds: APIs, remote cloud providers, third-party aggregators, and what it calls gray-market proxy ‘transfer stations.’ China-based companies, the agencies allege, route distillation requests through multiple pathways specifically to dodge detection and gain access they aren’t authorized to have, which violates the terms of use that US AI companies attach to their models. DeepSeek gets a harsher spotlight than the rest. The advisory accuses the company of using distillation to manufacture synthetic training data while publicly insisting its models were built on minimal compute. That claim, when DeepSeek first made it, rattled infrastructure investors. This advisory suggests the rattling might have been based on a story that wasn’t the whole truth.
What This Means
Here’s the uncomfortable question underneath all of this: if distillation is genuinely the foundation of six major Chinese AI companies’ strategy, what exactly is the US supposed to do about it? Terms of service already ban distillation. Commercial model providers write that prohibition into every contract specifically to protect what they spent hundreds of millions of dollars building. But a contract clause doesn’t mean much to a company routing requests through a proxy in a country that isn’t going to enforce it on your behalf.
I’ve read a fair number of these joint advisories over the years, and most of them read like warnings. This one reads more like an admission that the warnings haven’t worked. The agencies mention ‘transfer stations’ as if they’re describing a smuggling route, and honestly, that’s not far off. Picture a delivery truck that keeps getting flagged for stopping at an unmarked warehouse halfway through its route, where the cargo gets quietly repacked into different boxes before continuing on to its final buyer. Nobody at the destination can prove where the goods actually came from anymore. That’s roughly the shape of the problem the advisory is describing, except the cargo is model weights and API outputs instead of freight.
The competitive angle is the part that should worry US model providers most. Alibaba’s Qwen models are free. Free, while American labs are charging per token and still operating at a loss on inference costs. If Qwen’s improvements are genuinely built on distilled US model outputs, as the advisory alleges, then American companies are effectively subsidizing the free alternative that’s eating into their own paid customer base. That’s not a hypothetical competitive threat. That’s a business model getting undercut by the thing it’s trying to protect against.
The advisory also mentions a defensive tactic some US companies are apparently already using: subtly altering responses when they suspect malicious distillation attempts, specifically to reduce the payoff for whoever’s harvesting the outputs. That’s a quiet admission that detection, not just legal language, has become the real front line.
A Fight That’s Been Building for a While
None of this comes out of nowhere. US labs and government officials have raised distillation concerns before, and China has pushed back with its own version of the accusation, claiming American firms distill Chinese models too. The DeepSeek compute-cost controversy from earlier in its rise already shook confidence among infrastructure investors once. This advisory reopens that wound and adds five more names to the list.
What’s different this time is the source. This isn’t a lab’s blog post or a leaked internal memo. It’s NSA, FBI, and CISA speaking jointly, which tends to happen when a technical dispute has started drifting into national security territory. Export controls, model-access rules, and API restrictions have all been tools the US has reached for before when it decided a technology gap mattered strategically. An advisory naming six specific companies by name looks like the groundwork for exactly that kind of policy shift, even though the advisory itself doesn’t announce new restrictions.
What Comes Next
Watch whether this advisory turns into actual policy: tighter API access requirements, new export control language, or contractual enforcement mechanisms aimed specifically at the ‘transfer station’ proxies described here. Watch too whether the named companies respond directly. DeepSeek in particular has a track record of pushing back hard on compute-cost skepticism, and a public rebuttal wouldn’t be a surprise.
And keep an eye on Alibaba’s Qwen pricing and adoption numbers over the next few months. If the free-model pressure the advisory describes is real, US providers charging for access will feel it in usage data long before any policy response catches up.
Editor's Note
What gets me here isn't the accusation itself, it's that three agencies felt the need to say the quiet part out loud: distillation isn't a workaround for these companies, it's the strategy. I'm watching whether US labs start treating API access the way banks treat fraud detection, because that subtle-response-altering tactic buried in the advisory tells me they already are. My bet: this becomes a licensing fight before it becomes an export control fight.
– Sanket Chaukiyal, founder, SmartChunks
FAQ
Which Chinese AI companies did US agencies name in the advisory?
The joint advisory from NSA, FBI, and CISA named six companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
What is model distillation and why does it matter here?
Distillation is a technique where a smaller or newer model is trained using outputs from a larger, more capable model, effectively learning from its behavior. The advisory alleges Chinese firms are doing this at an industrial scale using unauthorized access methods, which violates the terms of service that US AI companies attach to their models.
Why is DeepSeek singled out specifically?
The advisory accuses DeepSeek of using distillation to generate synthetic training data while publicly claiming its models were built with minimal compute power, a claim that previously caused volatility among infrastructure investors when it first surfaced.
Could this advisory lead to new export controls or policy changes?
The advisory itself doesn't announce new restrictions, but joint statements from NSA, FBI, and CISA naming specific companies have historically preceded policy action on export controls and model-access rules, so it's a reasonable thing to watch for.
Source: The Register
