China Did Not Need the Model Weights. U.S. Agencies Say It Took the Capabilities Through the API.
Stealing an AI model does not always require breaking into the data centre or downloading its weights. A sufficiently organised customer can try to extract valuable behaviour one answer at a time.
NSA, CISA and the FBI allege that six China-based AI companies used industrial-scale knowledge distillation campaigns to collect restricted capabilities from U.S. frontier models. The joint advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and says they extracted billions of tokens across millions of exchanges since at least late 2024.
China’s government rejects the accusation. Its foreign ministry described the U.S. claims as unfounded and called for cooperation between the two countries on AI. The named companies did not provide responses in the initial Associated Press report.
The geopolitical dispute is impossible to separate from the source. The operational lesson does not depend on accepting every allegation: frontier-model APIs have become high-value extraction surfaces, and ordinary anti-fraud controls may not recognise a campaign distributed across accounts, clouds and intermediaries.
Distillation is not automatically an attack
Knowledge distillation is a legitimate machine-learning technique. A smaller model is trained using outputs from a more capable model, allowing some of the teacher’s behaviour to be reproduced with less compute and lower operating cost.
Model developers can use distillation with their own systems, licensed teachers or authorised data. Researchers also use it to study efficiency and transfer capabilities between models. The security issue begins when access is unauthorised, violates service conditions, bypasses geographic or account controls, or deliberately evades detection to collect restricted behaviour at scale.
This is distinct from the model-provenance problem BlackTree previously examined. Provenance asks what a released model inherited from upstream systems. This advisory alleges that companies deliberately collected a rival model’s capabilities through distributed commercial access.
The U.S. advisory presents the activity as systematic extraction rather than ordinary product use. That is a government assessment, not a technical fact independently proven by the public document. Providers and customers should keep the distinction visible instead of treating every high-volume AI user as an adversary.
The alleged campaigns hid inside the AI supply chain
According to the agencies, the campaigns did not rely on one direct API connection. Requests moved through native model APIs, cloud platforms, third-party aggregators, account pools and a grey market of proxy services described as transfer stations.
That architecture serves two purposes. It increases available capacity, and it prevents any one provider from seeing the entire pattern. A single account may resemble an aggressive developer. Thousands of related accounts across several companies can become an extraction pipeline without creating one obvious bottleneck.
The advisory says teams bought premium subscriptions in bulk, shared them across developers and used central routing systems to move traffic between providers when blocking or pricing changed. It also describes automated removal of organisational markers, coordinated prompt templates and quality-control systems able to detect degraded responses.
The alleged collection was targeted rather than random. The agencies say prompts sought reasoning patterns, coding and agentic behaviour, mathematical capability, visual processing and specialised domain functions. Outputs could then become synthetic training data for another model.
The economics are the strategic prize
Frontier models require expensive compute, electricity, engineering and research. Distillation does not reproduce the entire training process or guarantee an equivalent model, but it can reduce the cost of teaching specific behaviours.
This is why the alleged scale matters. Millions of API exchanges are not only a data-loss problem. They can shift part of one company’s research cost into another company’s training pipeline. The attacker pays for inference and infrastructure while trying to avoid the much larger cost of discovering the behaviour independently.
The same logic applies outside geopolitics. A commercial rival, a model reseller or a criminal service could use distributed access to copy a valuable capability, build a substitute product or remove safeguards. Providers therefore need to treat behavioural extraction as a security and revenue-abuse problem, not merely a breach of contract.
Normal fraud signals look different at model scale
A stolen payment card or account takeover often creates a sharp change from a user’s established behaviour. A distillation account may be created for high-volume use from the beginning. The suspicious pattern exists across the campaign rather than inside one customer’s history.
The joint advisory highlights several signals providers can combine:
- new subscriptions that immediately consume the maximum available capacity;
- individual plans producing enterprise-scale throughput;
- continuous use without ordinary human idle periods;
- shared accounts appearing across many addresses, devices or user agents;
- similar prompts and timing across separate account pools;
- rapid switching between models, clouds, aggregators and proxy paths;
- usage optimised for cache efficiency rather than diverse user tasks;
- sudden removal of metadata after a provider shares detection information.
None of those indicators proves distillation by itself. A legitimate enterprise evaluation, accessibility service, benchmark or security study can produce unusual traffic. High-confidence detection requires identity, payment, network, prompt, timing and cross-provider context.
Silent model degradation is a powerful but risky defence
The agencies recommend more than blocking accounts. For high-confidence malicious collection, they suggest subtly reducing response quality, varying reasoning depth or routing suspected requests to a less capable model without alerting the operator.
The logic is economic. A hard block tells the collector which account or pattern was detected. Quiet degradation can contaminate the collected dataset, waste validation effort and make it harder to identify which path is returning useful output.
The approach also creates governance risk. A false positive could silently reduce a paying customer’s service, undermine a benchmark or corrupt legitimate research. Providers need documented confidence thresholds, human review for consequential cases, audit trails and a clear separation between adversarial response and ordinary product experimentation.
The advisory makes one useful exception explicit: legitimate safety researchers and third-party evaluators should be told when model behaviour changes. A security control that makes evaluation results unknowingly incomparable can create a second trust failure while trying to prevent the first.
No provider can see a distributed campaign alone
If requests move between a model company, cloud platform, API aggregator and proxy network, each organisation sees a fragment. The model provider sees prompts. The cloud sees infrastructure. The aggregator sees customer routing. The payment provider sees subscriptions and funding relationships.
Cross-organisation intelligence can join those fragments, but it must respect privacy, competition law and contractual boundaries. Useful sharing can focus on campaign infrastructure, correlated timing, fraudulent account patterns and abuse indicators rather than exposing every user’s prompts.
Providers should also preserve enough telemetry to investigate later. Rate limiting without durable logs can interrupt one path while losing the evidence needed to connect the next one.
What AI providers should do now
- Define the difference between authorised distillation, prohibited extraction, benchmarking and ordinary high-volume use.
- Strengthen account and payment verification for plans that can sustain large-scale collection.
- Monitor subscription-to-usage ratios, immediate quota saturation and continuous multi-session activity.
- Correlate prompts, timing, infrastructure and payment relationships across account pools.
- Apply per-account, per-key, per-network and campaign-level rate controls rather than relying on one quota.
- Require aggregators and cloud partners to preserve abuse telemetry and support rapid investigations.
- Test extraction attempts through AI red-team exercises and measure what capabilities can be reproduced from public outputs.
- Use response alteration only under a governed, high-confidence process with safeguards for legitimate research and customers.
- Keep model weights, logits, hidden reasoning and internal evaluation data separated from interfaces that do not need them.
- Build a lawful information-sharing route before a distributed campaign forces improvised coordination.
The advisory is written through the lens of U.S. strategic competition with China, and its attribution should be reported as such. China’s denial and the absence of publicly disclosed underlying evidence limit what an independent reader can verify about each named company.
What the document makes clear is the shape of the defensive problem. An AI provider can protect its servers, encrypt its model weights and still expose valuable behaviour through the product it sells.
The API is not merely the front door to the model. At industrial scale, it can become the extraction interface.
Sources
- NSA: U.S. agencies warn about industrial-scale model distillation, published 8 September 2026. The primary page provides a date but no publication time.
- NSA, CISA and FBI joint Cybersecurity Advisory AA26-251A, released 8 September 2026. The primary advisory provides a date but no publication time.
- Associated Press: China rejects the U.S. distillation allegations, published 9 September 2026 at 09:44:51 UTC.
Continue the series: APAC Cyber & Digital Law Series index


