How we read the signal

Analysis frame

Evidence level

Primary-source evidence

Analytical lens

The central governance problem is separating legitimate model learning from coordinated access evasion while the government making the attribution withholds much of the underlying intelligence.

Affected groups
  • Frontier model providers, cloud platforms, and API aggregators targeted by distributed extraction
  • Chinese AI firms and researchers whose legitimate activity could be swept into broad countermeasures
  • Security agencies and allied governments responding to technology-transfer and military concerns
  • Ordinary developers exposed to stricter identity, rate, and regional access controls
What remains unknown
  • The underlying evidence and confidence level supporting each named company attribution
  • How much extracted output materially improved the recipient models compared with independent research and training
  • Whether proposed response degradation can avoid harming legitimate high-volume users or contaminating research
  • What review or appeal process will exist when cross-provider detection flags an organization incorrectly
Second-order effects to watch
  • Model providers may form a shared threat-intelligence layer that becomes a powerful private access-control institution
  • Stronger identity and location checks could fragment global access to frontier research tools
  • Targeted response manipulation could trigger an arms race between distillation quality assurance and defensive degradation
  • Security framing may accelerate export controls and encourage domestic substitutes in restricted markets

The advisory names companies, methods, and scale

The NSA, FBI, and CISA say the campaigns extracted billions of tokens across millions of requests from variants of Claude, GPT, Gemini, and Grok. They name DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, and describe distillation as central rather than incidental to the alleged development strategy.

The assessment says operators used native APIs, clouds, aggregators, shared subscriptions, fraudulent accounts, and gray-market transfer stations. It also describes chain-of-thought extraction attempts and automated quality checks that could detect defensive degradation.

The defense must see across company boundaries

The advisory recommends monitoring subscription-to-usage ratios, immediate maximum activity from new accounts, nonstop usage, shared identities, similar prompts, and correlated behavior across pathways. It also recommends changing responses to reduce the value of suspected extraction and sharing intelligence across organizations.

That coordination can expose a campaign that looks ordinary inside any one provider. It can also create a private access-control layer with the power to flag organizations across the market, which makes accuracy, retention limits, independent review, and appeals essential.

Distillation is not automatically malicious

The agencies explicitly recognize distillation as a legitimate research technique. The disputed conduct is coordinated extraction combined with access evasion, terms violations, and the targeting of restricted capabilities.

The report provides operational detail but not the underlying intelligence for every attribution. Policymakers should respond to documented behavior and confidence levels, not convert a security advisory into a blanket presumption against foreign researchers or open model development.

  • Correlate indicators across providers without creating an unreviewable blacklist.
  • Preserve evidence before manipulating responses to suspected users.
  • Separate high-volume legitimate research from coordinated access evasion.
  • Publish confidence and correction procedures wherever security permits.
Primary trail

Go to the source

Read the evidence behind this analysis. External links open in a new tab.

NSA — Joint advisory on industrial-scale model distillation