Three US agencies named six Chinese AI labs for copying American models at industrial scale
Four of the top five models in this site's open weights index come from companies that three US agencies named on 8 September. The agencies allege those companies built their models partly out of American ones.
Joint advisory AA26-251A from the NSA, CISA and FBI names six labs: DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI. It alleges aggressive, malicious and targeted distillation since at least late 2024, extracting billions of tokens across millions of exchanges from variants of Claude, GPT, Gemini and Grok. Distillation means training one model on another's outputs, and the advisory says plainly that the technique is legitimate. Its objection is to scale, evasion of provider restrictions, and the targeting of capabilities providers had restricted.
Why this one is different
Labs have accused each other of this before, in blog posts and interviews. This is the United States government naming companies, in a formal security advisory, and telling American providers what to do about it. The instruction is the unusual part: detect suspect accounts, share what you find across the industry, and feed them degraded answers rather than simply blocking them, so that the copying continues and produces a worse copy.
Not a block. A quietly worse answer.
How we got here
- Late 2024The start of the campaigns the advisory describes.
- 14 Aug 2026Alibaba releases Qwen3.8-27B under Apache 2.0.
- 4 Sep 2026DeepSeek orders at least 160,000 Huawei accelerators for a gigawatt site.
- 6 Sep 2026Qwen, DeepSeek twice and Moonshot's Kimi hold four of the top five places in this index's open weights ranking.
- 8 Sep 2026The NSA, CISA and FBI name all three of those companies, and three more, in advisory AA26-251A.
What it does and does not mean
An advisory is an allegation, not a finding. No court has examined it, the named companies' responses are not part of it, and it does not attempt to say how much of any particular model's capability came from distillation rather than from its own training. Distilling from another model's outputs is also ordinary research practice, which the advisory itself concedes. What it does establish is the US government's position, in writing, with names attached. Open weights rankings now carry a question they did not carry last week, and the recommended response, serving worse answers to suspected copiers, is a policy that providers will be applying to accounts they cannot always identify correctly.