TITLE: US Agencies Name Six Chinese AI Firms in Industrial-Scale Model Theft Advisory DATE: 2026-09-10 COMPANY: CISA, NSA, FBI TOPIC: AI Security SUMMARY: The NSA, CISA, and FBI issued a joint advisory on September 8 naming six Chinese AI companies, including DeepSeek and Alibaba, for running industrial-scale distillation campaigns against US frontier models since late 2024. The campaigns extracted billions of tokens from Anthropic, OpenAI, Google, and xAI, specifically targeting chain-of-thought reasoning traces. US agencies are now telling AI providers to secretly downgrade responses to suspected accounts rather than banning them. WHAT CHANGED: On September 8, 2026, the NSA, CISA, and FBI jointly published cybersecurity advisory AA26-251A accusing six China-based artificial intelligence companies of conducting what they describe as industrial-scale knowledge distillation campaigns against US frontier AI models. The advisory is the first joint statement from all three agencies specifically attributing AI model extraction to named Chinese technology companies. The six named companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, are alleged to have sent billions of structured API requests to models from Anthropic, OpenAI, Google, and xAI since at least late 2024. The campaigns were not random scraping. According to the advisory, they specifically targeted chain-of-thought reasoning traces, the intermediate thinking steps exposed by modern reasoning models, with the goal of training their own systems to replicate not just outputs but reasoning behaviour. The advisory includes detection guidance for US AI providers. Indicators cited include enterprise-scale traffic volumes originating from consumer-tier account subscriptions, newly created accounts immediately saturating usage limits, round-the-clock automated request patterns, and accounts shared across multiple IP addresses. Providers are instructed to respond to suspected accounts by silently substituting a lower-quality model rather than restricting access or notifying the user. The advisory explicitly states providers should "avoid informing" suspected distillers of any change. WHY IT MATTERS: For operators using Chinese AI models, the risk profile has changed permanently. The advisory names DeepSeek specifically. Any organisation that deployed DeepSeek models in production workflows, or is considering doing so, now faces reputational, regulatory, and supply-chain risk that the cost savings do not offset. The story is no longer about whether a Chinese model performs well. It is about whether your organisation is comfortable being named alongside providers under active US government intelligence scrutiny. The silent downgrade recommendation is itself a governance problem. AI providers acting on this advisory will secretly substitute lower-quality models for accounts that pattern-match to distillers. Legitimate heavy users, enterprise operators running AI in production, agentic workflows, automated pipelines, share many of the same traffic characteristics as distillers. Organisations cannot assume they are receiving the model they contracted for, and most have no mechanism to detect a substitution. Chain-of-thought reasoning traces are now a defined attack surface. The advisory establishes that internal model reasoning, not just final outputs, has strategic value. Organisations that expose reasoning-capable models via API should review what they log, what third parties can access, and whether their own API usage patterns inadvertently create a comparable extraction profile. The advisory's language is deliberate. Across 3,585 words it never uses the terms theft, illegal, or copyright. This leaves legal action ambiguous. The US government is treating this as an intelligence and competitive matter, not a criminal one, at least for now. Operators in regulated sectors should not assume the current framing will remain stable. The geopolitical backdrop is now explicit. The agencies assess the campaigns occurred "likely with Chinese government awareness." For any organisation with Chinese customers, partners, or investors, this advisory may require internal legal review of AI infrastructure choices. DAVID & GOLIATH ANALYSIS: The advisory's detection criteria deserve more attention than most commentary has given them. CISA describes distillers as running enterprise-scale traffic from consumer accounts, hitting usage limits immediately, operating round the clock, and coordinating across IP addresses. That is also an accurate description of a sophisticated enterprise automation stack. The advice to providers to silently downgrade without notification creates a scenario where an operator's AI system degrades in quality and the operator has no way to know why or when it happened. For smaller organisations that have been drawn to DeepSeek and Alibaba AI on cost grounds, this advisory closes that conversation. The decision was always a risk trade-off. The risk side has now been officially quantified by three US intelligence agencies. No cost saving at the 10-200 person operator scale justifies that exposure. What this advisory actually points to is the next wave of AI infrastructure requirements: model provenance verification, response authenticity logging, and contractual protections against silent model substitution. These are not yet standard in enterprise AI contracts. They will be. RELEVANT SYSTEMS: Secure AI Brain SOURCE URL: https://davidandgoliath.ai/daily-ai-briefing/us-agencies-cisa-nsa-fbi-chinese-ai-distillation-advisory FEED URL: https://davidandgoliath.ai/daily-ai-briefing/feed --- Published by David & Goliath | https://davidandgoliath.ai Daily AI Briefing: one AI development per day, decoded for business operators. This is a structured companion file optimised for LLM retrieval and citation.