The United States government has officially accused six major Chinese artificial intelligence companies of running organized campaigns to extract proprietary capabilities from American AI models — and the implications reach every business that pays for access to AI services.
On September 8, 2026, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation released joint advisory AA26-251A. The document names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as operators of what the agencies describe as “industrial-scale knowledge distillation campaigns” running against US frontier models since at least late 2024.
What Distillation Actually Means
Distillation, in this context, is not hacking in the traditional sense. The companies did not break into OpenAI’s or Anthropic’s systems. Instead, they used their own AI models to submit millions of carefully constructed queries to US frontier models — Claude, GPT, Gemini, and Grok — and used the responses as training data to build cheaper replicas.
The advisory is specific about the scale. DeepSeek alone extracted billions of tokens across millions of API exchanges, targeting reasoning capabilities, specialized optimizations, and domain-specific functions. The stated goal was to reduce compute and research costs by learning what US models know without paying to discover it.
The companies used fraudulent accounts, bulk premium subscriptions, and proxy routing services to avoid detection and to bypass regional access restrictions.
The $5.6 Million Training Cost Problem
The most significant commercial implication buried in this advisory is a sentence that rewrites the narrative around DeepSeek’s rise.
DeepSeek’s reported training cost of approximately $5.6 million was widely cited as evidence that frontier AI was becoming cheap. That figure was real — but the advisory states it is also misleading, because it excludes the cost of data acquired through distillation campaigns against US models.
The capabilities that made DeepSeek’s R1 and V3 models impressive were not built from scratch. They were, according to the advisory, materially derived from the outputs of Claude, GPT, Gemini, and Grok — models that cost their creators billions of dollars to develop. The low price was a transfer of cost, not an elimination of it.
For businesses evaluating AI vendors on cost grounds alone, this matters. A model with suspicious pricing may carry regulatory risk, supply chain risk, or ethical complexity that a straightforward cost comparison does not surface.
What the Agencies Are Recommending
The advisory takes an unusual approach to remediation. Rather than recommending that American AI providers block suspected distillation accounts outright, it advises a policy of quiet degradation: silently returning reduced-quality responses to accounts identified with high confidence as conducting malicious distillation.
The logic is that a hard block alerts the operators and prompts them to find new methods. A quiet degradation makes the operation progressively less useful without triggering an obvious change in behavior.
For enterprise buyers, this is worth noting. If you are using a provider that has implemented this advisory, some API traffic from accounts associated with distillation activity may already be receiving degraded responses without public acknowledgment. That is a deliberate, policy-driven choice — and it underscores that AI API access is not a simple commodity transaction.
The Broader Security Shift
This advisory fits into a pattern that has been building since late 2024. The EU AI Act created transparency obligations. The Stop Rogue AI Act introduced agent inventory requirements. Now the US government is treating AI model integrity as a national security concern.
For most businesses, the immediate operational impact is limited. If you are using reputable US-based AI providers, you are a consumer of models that are actively defended, not an organization responsible for defending them.
But a few things change with this advisory.
Procurement due diligence now includes model provenance. If your business is evaluating AI tools that use Chinese models as their backbone, the advisory creates a legitimate question: was this capability built, or was it extracted? That question is now a compliance question, not just an ethical one.
The cheap AI argument has a new asterisk. The advisory does not mean Chinese AI models are illegal to use. It does mean that the economics of how those models were built are contested, and that the cost advantage may not be sustainable as access restrictions tighten.
Your AI vendor’s security posture matters. The advisory recommends quiet degradation because it is more effective than hard blocks. If your vendor has implemented these measures, they are actively managing a threat that affects the quality of what you receive. That is a feature of a mature security posture, not a bug — but it is worth knowing.
What This Means for Business Owners
The NSA, CISA, and FBI do not issue joint advisories lightly. When three agencies coordinate to name specific companies, they are signaling a level of confidence in the underlying evidence and a deliberate decision to put that information into the public domain.
Businesses do not need to change AI providers tomorrow based on this advisory. But they should factor it into their vendor evaluation process, their procurement policies, and their understanding of why certain models are priced the way they are.
The era of AI as a simple utility — plug in, pay by the token, move on — is quietly becoming more complicated. Knowing where your models come from, and what it cost to build them, is becoming part of the job.
Enterprise DNA helps businesses build AI-powered operations that are secure, auditable, and built on sound foundations. If you are evaluating AI vendors or building agent workflows, talk to us about Omni Advisory — we help leaders navigate exactly these kinds of decisions.