Artificial Intelligence & Machine Learning,
Governance & Risk Management,
Next-Generation Technologies & Secure Development
CISA Says DeepSeek, Alibaba and Others Extracted Billions of Tokens From US Frontier AI Systems

The U.S. government has issued a stern warning regarding Chinese companies’ unauthorized extraction of American-made artificial intelligence models, marking a significant acknowledgment of ongoing allegations from leading frontier labs such as Anthropic and OpenAI. This revelation emphasizes the growing concerns among U.S. intelligence and security agencies about the potential risks posed by such actions in the realm of advanced technology.
On Tuesday, the Cybersecurity and Infrastructure Security Agency (CISA), alongside the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI), released a comprehensive advisory aimed at enhancing organizational awareness and response strategies concerning suspected model distillation activities. Organizations were specifically alerted to several firms, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.ai, which have been identified as part of this concerning trend.
According to the advisory, these companies are reported to have extracted “billions of tokens across millions of exchanges/requests from U.S. frontier models.” The techniques reportedly employed by these firms involve tapping into various sophisticated AI models, including iterations of Anthropic’s Claude, OpenAI’s GPT series, Google’s Gemini, and xAI’s Grok. By utilizing these models, foreign entities aim to enhance their own systems’ responsiveness to user prompts.
Despite the alarming insights presented in the advisory, the Trump administration has not outlined any clear potential repercussions should it be confirmed that Chinese AI laboratories are actively distilling sensitive information from American models. This lack of defined consequences raises questions regarding the U.S. government’s approach to safeguarding its technological innovations.
In the field of artificial intelligence, distillation is a recognized training methodology through which models learn from the responses provided by other models, essentially functioning as a “teacher model.” This technique allows for the efficient development of scaled-down versions of larger models without necessitating laborious datasets. While this practice is legitimate in many contexts, CISA noted that a standard ethical expectation mandates developers to disclose their intentions to relevant parties, a principle seemingly disregarded by certain Chinese firms.
CISA further emphasized that Chinese AI companies have adopted “aggressive, malicious, and targeted distillation activities at an industrial scale,” extracting proprietary functionalities and capabilities from U.S. models. It is believed that these operations significantly undermine the competitive edge of American businesses in the AI sector and result in substantial economic losses.
Structured with the likely backing of the Chinese government, the Chinese AI industry appears to be engaged in a comprehensive strategy to address technology gaps between Chinese models and those developed in the U.S. CISA has urged American AI firms to promptly implement three key measures to protect against this illicit distillation: enhancing detection and mitigation capabilities, deploying strategic response adjustments, and fostering cooperative intelligence sharing among different organizations.
The advisory highlights that Chinese companies have been accessing American AI models via application programming interfaces (APIs) and employing various strategies, including using proxy servers known as transfer stations, to circumvent geographical restrictions laid down by AI companies.
The practice of unauthorized distillation is alleged to have been ongoing since at least 2024. For instance, DeepSeek is reported to have spearheaded a distillation initiative aimed at refining its R1 and V3 models. Meanwhile, Moonshot AI has reportedly used information obtained from Claude Fable 5 and GPT 4o as part of its Kimi K3 and Kimi K2 developments, engaging with data across the American AI landscape.
Concerns regarding illicit distillation have existed in the AI community for some time. For example, in June, Anthropic urged the U.S. government to impose export controls on certain Chinese laboratories after alleging that Alibaba had improperly trained its Qwen models using responses generated by Claude models. This was just one incident amidst a series of complaints centered on the same issue, including claims made by OpenAI and Microsoft in early 2025, where they suggested that DeepSeek had inappropriately utilized output from their GPT models to enhance its own DeepSeek-R1 model.
While calls for regulatory action echo throughout the industry, Meta CEO Mark Zuckerberg has publicly defended distillation practices, arguing that embracing such technologies could help boost the development of superior open-source models in the U.S. This defense, however, carries its own implications as the discourse around intellectual property and ethical standards in AI development continues to evolve.

