U.S. federal agencies have publicly accused multiple Chinese artificial intelligence companies of conducting organized, industrial-scale efforts to extract capabilities from leading U.S. AI models. In a joint advisory released on Tuesday, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI) described the activity as a broad campaign aimed at reducing development costs and narrowing the technology gap.
The advisory identified a set of firms it said engaged in large-scale extraction campaigns since at least late 2024, naming DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI. According to the agencies, these actors extracted billions of tokens across millions of exchanges from U.S. models.
The notice singled out specific product development links. It said DeepSeek ran organized extraction campaigns focused on reasoning capabilities and specialized functions as part of work on its R1 and V3 models. Alibaba was cited for using industrial-scale distillation techniques to enhance its Qwen family of models.
The agencies described a variety of technical paths used to perform the extraction. These included direct API access, cloud-provider routes, third-party aggregators and a gray-market network of proxies the advisory called "transfer stations" - approaches reportedly used to bypass geographical restrictions and safety safeguards. The advisory also stated that the firms employed fraudulent accounts, bulk subscriptions and automated systems to avoid detection.
DeepSeek was specifically reported to have targeted a range of U.S. models, including Claude, Gemini, GPT and Grok. The agencies said the extraction focused on capabilities such as reasoning, coding, agentic functions and optimization for question-and-answer tasks.
To respond, the advisory urged U.S. AI companies and service providers to strengthen monitoring for anomalous usage patterns, to change responses when distillation is suspected, and to improve intelligence sharing across model providers, cloud platforms and API aggregators.
Context limitations: The advisory links the described activity to operations since at least late 2024 and states the campaigns likely occurred with Chinese government awareness. It does not provide further operational details beyond the techniques and firms named.