WASHINGTON — The NSA, FBI, and Cybersecurity and Infrastructure Security Agency issued a rare joint advisory Monday accusing Chinese artificial intelligence companies of conducting industrial-scale distillation of American frontier AI models, a technique that allows a less capable model to learn from a more powerful one without direct access to its training data or code.
The advisory, coordinated with intelligence partners in the United Kingdom, Australia, Canada, and New Zealand, named DeepSeek and Moonshot AI as companies engaged in the practice. CISA Director Jen Easterly described the activity as “a systematic effort to replicate the capabilities of US-developed frontier models while avoiding the export controls and licensing frameworks that govern direct technology transfer.”
Model distillation works by feeding a target model enormous volumes of outputs generated by a more capable source model, effectively teaching the smaller system to behave like the larger one. It requires no access to source code, no theft of model weights, and no breach of any computer system, making it difficult to prohibit under existing frameworks and almost impossible to detect in real time. The technique is widely used in legitimate AI development; what the advisory alleges is that Chinese firms have applied it at scale against US commercial models without authorization.
The advisory described what the agencies called a “distributed distillation” approach, in which Chinese firms organized queries to US models across thousands of accounts in multiple countries, no single one of which would generate enough traffic to trigger automated detection systems. The result, the agencies said, was a sustained, coordinated data collection effort that looked from the outside like ordinary consumer use.
According to the document, one unnamed Chinese firm generated tens of millions of model queries through this distributed method over an 18-month period, systematically covering technical domains including chemistry, materials science, software development, and military logistics. The advisory said the effort was organized across front companies in multiple jurisdictions to further obscure its origin.
The findings build on a report published earlier this year by Anthropic, which identified evidence that DeepSeek, Moonshot AI, and MiniMax had used outputs from leading US models to improve their own systems. The Anthropic report described the practice as widespread and said it was difficult to prevent without changes to terms of service enforcement that would require identifying and blocking accounts connected to the effort. TechCrunch reported on the Anthropic findings when they were published in July.
The White House had signaled in July that it was considering sanctions against Chinese AI companies engaged in distillation, citing Treasury Department authority to designate entities that threaten national security. Monday’s joint advisory stops short of announcing sanctions but is widely read as the evidentiary predicate for them. A Treasury official declined to confirm or deny whether designations were being prepared.
What the advisory does not resolve is the precise legal status of distillation itself. Companies including OpenAI and Anthropic prohibit the practice in their terms of service, but those prohibitions are civil agreements, not criminal statutes. Using a commercial AI service within its stated rate limits, even with the intent to distill its outputs, does not on its own constitute a crime under existing US law. The agencies acknowledged in the advisory that the current legal framework contains gaps and said they were working with the National Security Council on “appropriate legislative and regulatory tools.”
MIT Technology Review has noted that the line between legitimate AI improvement and illicit distillation is technically blurry: researchers routinely use one model’s outputs to benchmark or train another. What differentiates the conduct the advisory describes, US officials said, is the scale, the systematic domain coverage, and the coordinated effort to avoid detection, all of which point toward a state-directed or state-facilitated program rather than normal commercial AI development.
The named Chinese companies did not respond to requests for comment before publication. DeepSeek’s servers have been inaccessible from US-based connections since early August, when the Commerce Department placed the company on its Entity List. Moonshot AI, which operates the Kimi AI assistant, has maintained that its models were developed independently.
Five Eyes intelligence partners are expected to issue their own national security advisories in the coming days, though their precise framing may differ from Washington’s. The advisory marks the first time the US government has named specific Chinese AI companies in connection with what it characterizes as a national security threat, and the clearest signal yet that the AI competition between Washington and Beijing is being prosecuted not just through chip export controls and investment restrictions, but through the intelligence apparatus as well.

