What happened
- The U.S. National Security Agency (NSA), the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) published a joint alert on September 8 about distillation: training your own model on another model’s answers.
- The alert names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It says they extracted billions of tokens from versions of Claude, GPT, Gemini and Grok since at least late 2024, probably with the Chinese government’s knowledge.
- It describes the access routes: direct application programming interfaces (APIs), clouds, aggregators that hide metadata and a gray market of intermediaries reselling access at a fraction of the official price.
- It recommends three actions to U.S. companies: detect anomalous patterns, alter responses to those who distill and share intelligence among providers, clouds and aggregators.
Why it matters
- The most concrete recommendation is not to warn. The document suggests responding to confirmed cases with downgraded models, shorter reasoning or stylistic inconsistencies, without informing the user of the change.
- The red flags it lists include continuous 24-hour use with no human breaks, accounts shared across several IPs, new subscriptions that immediately hit the maximum and cache-optimized queries. A team in Chile running agents all night through an aggregator ticks several of those boxes. The alert doesn’t explain how to appeal or how to know whether an account was degraded.
- If a model starts answering worse without saying so, the error shows up in the product of whoever built on top of it, under their brand.
The number
$5.6 million. That’s the training cost DeepSeek published for its V3 model. The alert calls it misleading because it doesn’t include the value of the data obtained through distillation.
Context
The alert itself acknowledges that distillation is a legitimate and common technique in research. What it objects to is access through routes that violate terms of use and evade geographic restrictions. The U.S. labs now receiving protection face their own lawsuits for training on other people’s content: the Seattle Times and Newsday sued OpenAI and Sony and Warner sued Anthropic.
What’s next
- The alert calls for coordination among model providers, clouds and aggregators, without setting deadlines.
- No timelines announced for sanctions or regulatory measures stemming from the document.
Bottom line
DeepSeek, the first company on the alert’s list, launched V4.1 Flash two days later, with lower prices than its previous model.
Sources
- NSA and Others Warn China-Based AI Companies are Distilling U.S. Frontier AI Models — NSA, September 8, 2026
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — NSA, CISA and FBI, joint alert, September 2026
Edited by Rodrigo Cornejo. How we select and verify the facts, in who writes.




