Stock Markets September 8, 2026 10:31 PM

U.S. Agencies Say Chinese AI Firms Conducted Large-Scale Model Extraction

CISA, NSA and FBI warn of industrialized pulls of U.S. model capabilities and recommend tighter safeguards

By Leila Farooq
Share
Twitter Reddit Facebook LinkedIn

A joint advisory from U.S. security agencies accused several Chinese AI companies of systematically extracting capabilities from advanced U.S. AI models at scale. The agencies said the operations used multiple technical and procedural workarounds to acquire billions of tokens and that the campaigns likely occurred with awareness of Chinese government actors. Companies named include DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI.

U.S. Agencies Say Chinese AI Firms Conducted Large-Scale Model Extraction
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • U.S. agencies CISA, NSA and FBI issued a joint advisory accusing several Chinese AI companies of large-scale extraction of U.S. model capabilities.
  • The firms named include DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI; agencies reported extraction of billions of tokens across millions of exchanges since at least late 2024.
  • Agencies recommended stronger monitoring, adaptive responses to suspected distillation, and enhanced intelligence sharing among model providers, cloud platforms and API aggregators - affecting AI, cloud and cybersecurity sectors.

U.S. federal agencies have publicly accused multiple Chinese artificial intelligence companies of conducting organized, industrial-scale efforts to extract capabilities from leading U.S. AI models. In a joint advisory released on Tuesday, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI) described the activity as a broad campaign aimed at reducing development costs and narrowing the technology gap.

The advisory identified a set of firms it said engaged in large-scale extraction campaigns since at least late 2024, naming DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI. According to the agencies, these actors extracted billions of tokens across millions of exchanges from U.S. models.

The notice singled out specific product development links. It said DeepSeek ran organized extraction campaigns focused on reasoning capabilities and specialized functions as part of work on its R1 and V3 models. Alibaba was cited for using industrial-scale distillation techniques to enhance its Qwen family of models.

The agencies described a variety of technical paths used to perform the extraction. These included direct API access, cloud-provider routes, third-party aggregators and a gray-market network of proxies the advisory called "transfer stations" - approaches reportedly used to bypass geographical restrictions and safety safeguards. The advisory also stated that the firms employed fraudulent accounts, bulk subscriptions and automated systems to avoid detection.

DeepSeek was specifically reported to have targeted a range of U.S. models, including Claude, Gemini, GPT and Grok. The agencies said the extraction focused on capabilities such as reasoning, coding, agentic functions and optimization for question-and-answer tasks.

To respond, the advisory urged U.S. AI companies and service providers to strengthen monitoring for anomalous usage patterns, to change responses when distillation is suspected, and to improve intelligence sharing across model providers, cloud platforms and API aggregators.


Context limitations: The advisory links the described activity to operations since at least late 2024 and states the campaigns likely occurred with Chinese government awareness. It does not provide further operational details beyond the techniques and firms named.

Risks

  • Ongoing model extraction could erode proprietary advantages for U.S. AI developers and increase competitive pressure in the AI and cloud services markets.
  • Use of proxy networks, fraudulent accounts and automated systems increases operational risk for cloud providers and API aggregators, complicating detection and mitigation efforts.
  • If campaigns occurred with government-level awareness as the advisory states, geopolitical and regulatory tensions could rise, affecting technology and security-related market segments.

More from Stock Markets

NSE Set to Cut IPO Price Range, Reduce Share on Offer as Sellers Retreat Sep 8, 2026 Flight data shows crew may have attempted to abort landing before Miami cargo jet crashed Sep 8, 2026 U.S. Futures Tepid as Brent Nears $100 and Fed Hike Odds Climb Sep 8, 2026 Evommune Shares Collapse After EVO756 Phase 2b Top-Line Readout Disappoints Sep 8, 2026 Evommune Shares Plunge After EVO756 Fails to Hit Trial Goals; Company Reprioritizes Atopic Dermatitis Program Sep 8, 2026