CONFIRMED: the US government names six Chinese firms and puts dates on the extraction

Editorial label: CONFIRMED. On September 8, 2026, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI published a joint bulletin accusing Chinese AI companies of systematic extraction of American frontier models' capabilities through distillation, a legitimate research technique that, according to the agencies, is being used aggressively and maliciously at industrial scale. The document names six companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, and states they extracted billions of tokens across millions of interactions with models from Anthropic, OpenAI, Google and SpaceXAI since at least late 2024, likely with the Chinese government's knowledge.

Who took what from whom, according to the official bulletin

The level of detail is what sets this alert apart from a generic accusation. DeepSeek reportedly targeted reasoning capabilities and specific optimizations from Claude 3.7, Sonnet 4, Sonnet 4.5, Opus 4.1, Gemini 2.5 Pro and Flash, plus GPT-4, GPT-4o, GPT-4 Mini, GPT-4 Nano, GPT-5 and Grok 4 to train R1 and V3. Moonshot AI reportedly extracted relevant Claude Fable 5 data to train Kimi K3 and GPT-4o data for Kimi K2. Alibaba reportedly distilled Claude-4, Opus, Sonnet and GPT-5 to improve software engineering, customer service dialogue and image generation in Qwen. MiniMax reportedly pulled chain of thought reasoning, RL and SFT from Claude Code, Sonnet 4, Opus, Gemini 1, Gemini 2.5 Pro and Gemini 3 Pro for M2, even using prompt injection to try to convince Claude Code it was actually a MiniMax product. StepFun reportedly targeted Opus 4.1, 4.5, Sonnet 4.5, Haiku 4.5 and the GPT-5.1 and 5.2 family for Step 4. Z.AI reportedly pulled billions of tokens from GPT-5.5 and Opus 4.8 to develop chain of thought reasoning.

The real trick isn't copying, it's hiding that you're copying

The bulletin describes sophisticated evasion engineering: use of APIs, remote cloud providers and third party aggregators that obfuscate user metadata, plus a gray market of proxies known as transfer stations, openly advertised on Chinese marketplaces like Taobao and Xianyu, to get around the geographic blocks that prevent direct access to American models from inside China. The more advanced tactics include chain of thought extraction, automated failover between access routes when one gets blocked, and quality evaluation frameworks specifically designed to detect American labs' defensive countermeasures. MiniMax, for instance, reportedly redirected queries to test a new Claude model's defenses within 24 hours of its release.

Why this isn't just a lab squabble, it's a real cost question

The bulletin directly attacks the efficiency narrative that built the reputation of cheap Chinese models. DeepSeek publicly claimed it trained R1 for $5.6 million, but the agencies argue that figure is misleading because it excludes the cost of data acquired through malicious distillation. That changes the comparison yardstick: if part of a model's capability comes from extracting another lab's work without paying for it, the argument that China reached parity at a tenth of the cost loses force, because the real cost includes unauthorized access to someone else's research.

The pattern isn't new, but the scale and the official label are

Anthropic itself had already identified extraction campaigns by DeepSeek, Moonshot AI and MiniMax against Claude back in February, and Google Threat Intelligence Group reported this same week a spike in distillation campaigns against its models, with volumes exceeding 100 million prompts focused on visual and audio understanding, image and video generation. What's different now is that three US federal agencies are signing the same diagnosis at the same time, mapping the activity to the MITRE ATLAS framework and calling for coordinated response across government, private industry and allies, a move that elevates the dispute from isolated corporate complaint to declared national security policy.

What changes in MaxAssistant's read

This is fact confirmed by a primary federal source, not a leak or third party interpretation: the CISA bulletin is published, signed and detailed. What remains analysis is the practical consequence: whether this translates into harder API restrictions, heavier identity verification requirements for accounts flagged as Asian, or just another rhetorical chapter in the US-China fight for AI leadership. For anyone running a product on frontier models, the direct takeaway is to look at your own API key and service account exposure, because the bulletin makes clear the distillation target isn't just the model itself, it's any legitimate access that can serve as an entry point.

Sources

The Hacker News, U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok: https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html | CISA, AA26-251A joint cybersecurity advisory: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a | FrontierNews.ai, U.S. Intelligence Agencies Expose China's Systematic Theft of OpenAI, Claude, and Gemini Models: https://www.frontiernews.ai/news/article/us-intelligence-agencies-expose-chinas-systematic-d52ef385