- What: US agencies warn about AI model distillation by Chinese companies
- Impact: Threats to US AI leadership
Artificial Intelligence US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities Distillation is an âattackâ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. By Kevin Townsend | September 9, 2026 (8:32 AM ET) Flipboard Reddit Whatsapp Whatsapp Email The NSA, CISA and FBI say that China-based AI companies are using the distillation process against US frontier models. âLikely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba , MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024,â they say . The result doesnât simply improve Chinaâs AI models, it also threatens the existing US technology leadership. Between late 2024 and mid 2025, DeepSeek distilled training data and capabilities from Claude, Gemini, GPT-4 and GPT-5, and Grok 4 to train its R1 and V3 models. The knowledge distilled included, but was not limited to, API rule-driven tasks, agentic functions, Q&A optimization, supervised fine-tuning optimization, and creative and occupational writing optimization. Moonshot undertook a similar large scale distillation, including the extraction of significant Claude Fable 5 data to improve its Kimi-K3 model; and GPT-4o data to improve its Kimi-K2 model. Such distillation was repeated across all the named Chinese AI systems and is chronicled in detail within the agenciesâ report. The tactics, techniques, and procedures (TTPs) used by the Chinese organizations in their distillation are mapped to the MITRE ATLAS framework providing the TTP Title, its ID, and a description. This mapping provides a detailed explanation of the distillation process from resource development through access, execution, discovery, AI attack staging, collection, exfiltration and impact. The impact (on US frontier model developers), for example, is described as financial harm, undermining competitive advantages, and representing âa strategic economic threat to fair technological competition and U.S. technological leadershipâ. Advertisement. Scroll to continue reading. However, the authoring agencies also note the Chinese companies leverage additional techniques not present in MITRE ATLAS, thus distinguishing the process from an opportunistic exploitation. This is a planned and well-resourced national level action. The novel TTPs are described as regional restriction evasion and subscription exploitation; centralized request routing infrastructure, automated request metadata sanitization; and systematic quota and cost optimization. Mitigations proffered by the agencies should be coordinated across the broader US AI ecosystem, including cloud providers, API aggregators, and infrastructure providers. Recommendations include purely defensive actions (such as behavioral detection and monitoring, including examples of the behavior that could be detected), to more aggressive strike back responses. For the latter, the agencies suggest that âEmploying targeted changes in response to high-confidence malicious distillation requests can impose meaningful costs on knowledge distillation campaigns.â Sharing information about distillation campaigns is of course recommended. âMulti-source correlated activity enables more confident attribution of malicious knowledge distillation campaigns, justifying response degradation with lower-to-no legitimate user risk.â The principle of differential privacy is also recommended. It could be implemented by âadding calibrated noise to model outputs and preventing malicious actors from extracting training data membership information and other sensitive model information, such as decision boundaries or signals that could help reconstruct private data.â The purpose of the report is to alert all AI stakeholders that Chinese AI companies are systematically and, on an industrial scale, effectively stealing US technological leadership. The threat is not directly to the enterprise use of AI (although adversarial knowledge of how an AI defense might respond could potentially allow a more sophisticated and evasive attack). The threat is more directly to US technology leadership and consequently to the US economy and could potentially lead to a national security issue. Related : Trump Administration Vows Crackdown on Chinese Companies âExploitingâ AI Models Made in US Related : Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini Related : Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models Related : Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines â from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend OpenAI Agents Hijack Another Victim Website OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders Catch Raises $5 Million for AI Executive Assistant With Guardrails Capsule Security Launches âAI Circuit Breakerâ to Stop Rogue Agents AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million OpenLeash Adds a Human Check to Risky AI Agent Actions UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense Latest News ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws Ivanti Patches Critical Flaws Across Enterprise Security Products New Phishing Attack Creates Malicious Pages Inside the Victimâs Browser This Key Will Self-Destruct: An Open Standard for Revocable API Keys Chrome 153 Patches Seventh Zero-Day of 2026 Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day The Hidden Instructions That Can Hijack AI Agents Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the Move Frank Verdecanna has been appointed Chief Financial Officer at Armadin. Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America. Skyhigh Security has named Anthony Palladino as Chief Operating Officer. More People On The Move Expert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Donât Stop Attackers â They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email