Three Agencies Named Six Chinese Labs for Distillation. The Advisory Cites No Law, So Enforcement Lands on Your API Account.
The National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI published a joint cybersecurity advisory on Tuesday, September 8, 2026. It names six China-based AI companies by name: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It accuses all six of what the agencies call systematic extraction of proprietary functionalities and capabilities from US frontier models through industrial-scale knowledge distillation campaigns running since at least late 2024.
The advisory says the distillation is not a supplement to Chinese AI development. It says distillation forms the core of it.
That is a heavy sentence for a US government document to publish, and the coverage has treated it as the story. I want to point at something else. Read the advisory looking for the instrument, the thing that says what happens next to a company that does this, and there is nothing there. Three agencies, six named firms, billions of tokens documented, and the operative recommendation is that the ecosystem should improve information sharing.
This is the third rung of a ladder TensorFeed has been tracking since June, and it is the highest rung available that still has no teeth on it. Which is why the interesting question is not whether Beijing objects. It is where a control actually gets built once the escalation runs out of institutions to escalate to.
What the Advisory Actually Contains
The document is more specific than any prior US statement on this subject. It is a provenance ledger: which Chinese model, trained on outputs from which American model, over what period, for which capability.
| Named company | US models allegedly distilled | Chinese models trained | Capabilities cited |
|---|---|---|---|
| DeepSeek | 12 models: four Claude versions, two Gemini versions, five GPT versions, Grok 4 | R1, V3 | Agentic function, question and answer optimization, creative and occupational writing |
| Moonshot AI | 18 models, including Fable 5 and GPT-4o | Kimi K2, Kimi K3 | Agentic reasoning, coding and data analysis, computer vision, visual processing |
| Alibaba | Named, per-model detail not itemized publicly | Not itemized | Not itemized |
| MiniMax | Named, per-model detail not itemized publicly | Not itemized | Not itemized |
| StepFun | Named, per-model detail not itemized publicly | Not itemized | Not itemized |
| Z.AI | Named, per-model detail not itemized publicly | Not itemized | Not itemized |
One caveat on the top row, because precision matters here and the public readouts do not agree. CyberScoop reports the DeepSeek outputs as R1 and R3. Other summaries of the same advisory list R1 and V3. DeepSeek's own naming makes both plausible, and I have not seen the discrepancy resolved. Treat that cell as the softest number in the table.
The Moonshot row is the one that changes the temperature. Fable 5 is Anthropic's current commercially available flagship, not a two-generation-old model somebody scraped in 2024 and forgot about. The allegation is that the distillation target is the live frontier, on a rolling basis, as each model ships. That is a very different claim from catching up to a snapshot.
Every Listed Tactic Is an Account Problem
Here is the part of the advisory that tells you where this goes, and almost nobody quoted it. The agencies enumerate the operational tradecraft. Spreading requests across many accounts, models and platforms. Bulk premium subscriptions. Fraudulent account creation. Routing through native APIs, remote cloud providers and third-party aggregators to obfuscate user metadata. Proxies and gray tech markets to get around geographic restrictions, terms of use and model-side safeguards.
Read that list again as an engineer rather than as a policy analyst. Not one item on it is a chip. Not one is a smuggled GB300 in a Thai warehouse, which is the shape of the story the White House told about Moonshot in July. Every single one is an identity, billing or routing artifact sitting inside a US company's own API infrastructure.
Export controls cannot reach any of it. You cannot put a license requirement on an HTTPS POST. The Commerce Department's entire toolkit is built around physical goods crossing a border and the technology embodied in them, and a completion returned to a customer who paid for it does not cross a border in any sense that regime was designed to police.
The Ladder Has No Rungs Left
Put the escalation in one place and the pattern is hard to miss.
| Date | Who spoke | Named | Enforcement attached |
|---|---|---|---|
| Jun 2026 | Anthropic, to Senate Banking | Alibaba | None. Testimony. |
| Jun 2026 | White House OSTP (Kratsios) | Moonshot AI | None. Public accusation. |
| Sep 8, 2026 | NSA, CISA, FBI joint advisory | Six companies | None. Recommends information sharing. |
Ten weeks, three rungs, one vendor to six, a single agency voice to a tri-seal document. The specificity goes up every time and the consequence stays at zero every time. Above a joint NSA, CISA and FBI advisory there is not much left in the advisory register. The next move has to be an instrument or it is nothing.
There Is No Clean Statute Here
Distillation is a genuinely awkward object for US law, and it is worth being honest about why rather than assuming somebody will find a hook.
Trade secret law is the intuitive fit and the worst fit. A trade secret has to be secret. Model outputs are the product, sold to anyone with a credit card, generated on demand, at published prices. What is allegedly being extracted is not a stolen artifact, it is the behavior of a service operating exactly as designed.
Copyright is worse still, and for a reason the labs will not enjoy. Asserting that training on model outputs infringes is difficult to reconcile with the position US labs are currently defending in court against authors, artists, music publishers and news organizations. Anthropic is in the middle of its own music copyright exposure. You cannot argue that training on somebody else's output is fair when you do it and theft when they do it, at least not in the same filing season.
Which leaves terms of service, and computer fraud statutes reached through terms of service, a theory that has been narrowed repeatedly by the courts and that in any case requires a defendant a US court can actually reach. Six Chinese corporates are not that.
So the mechanism most likely to be used is the one the government does not need a new law for: sanctions and entity listing. That is where the Senate Banking testimony in June was already pointing, and a tri-seal advisory documenting a pattern is exactly the sort of record that gets cited in a designation package later. Advisories are not enforcement. They are frequently the paperwork that precedes it.
What This Costs the Rest of Us
Sanctions take months and hit six companies. The account layer takes a sprint and hits everybody, and it is the only surface where the described tradecraft is actually visible. If you are OpenAI or Anthropic or Google reading an advisory that says adversaries are getting to your model through fraudulent accounts, bulk subscriptions and third-party aggregators, you now have a documented federal finding that your signup flow is a national security surface.
The plausible responses are all things developers will feel:
Identity verification moving up-funnel, from a fraud check at high spend to a condition of frontier-tier access. Organization verification already exists at several labs for the top model tiers. The advisory is an argument for making it the default rather than the exception.
Aggregator scrutiny. The document explicitly names third-party aggregators as an obfuscation channel. Routers are how a very large share of independent developers reach frontier models, and they are also, structurally, a metadata laundering layer. Expect pressure on pass-through identity, and expect it to be uncomfortable for the router business model.
Behavioral rate limiting that looks for the shape of a distillation harvest rather than for abuse: high-volume, high-diversity, low-repetition prompting with no downstream product attached. That is also a fair description of a synthetic data pipeline, an eval suite and a research benchmark run, which is the problem.
None of that stops a well-resourced state-adjacent lab. All of it is friction on a solo developer in Lagos or Warsaw or Jakarta with a prepaid card. The asymmetry of that outcome is the actual cost of an advisory with no instrument attached: the control lands where it is cheap to apply, not where the problem is.
Beijing, and the Calendar
China's Foreign Ministry answered on Wednesday. Spokesperson Mao Ning urged the US to refrain from making unfounded accusations or smears, said China's AI development is the result of high-level technological self-reliance, and added that both countries are major AI powers who should strengthen cooperation.
That last clause is doing more work than the denial. AI governance is expected on the agenda when Trump and Xi meet later this month. Publishing a tri-seal advisory naming six national champions ten days out is not a coincidence, and the absence of an enforcement instrument is not an oversight. An advisory is a position you can hold or trade. A designation is one you have to defend. The US built the record and left the response unspecified, which is the correct move if the point is leverage in a room rather than a consequence for a company.
One detail that makes the timing read as almost editorial: DeepSeek opened a public test endpoint for V4.1 Flash on September 8, the same day the advisory landed, with the beta identifier set to expire on September 10 and a full release targeted for around then. The company named in the top row of a US intelligence document shipped a model that afternoon. Whatever the advisory is for, it is not slowing the release cadence.
The Line Nobody Has Drawn
The agencies concede, correctly, that distillation is ordinary practice. Labs distill their own models to make small variants. Researchers distill published models. Open-weight communities do it constantly and it is a large part of why the open frontier moves as fast as it does. The advisory's distinction is that the Chinese activity is aggressive, malicious and targeted, at industrial scale.
Those are adjectives, not a threshold. No token count, no query volume, no intent test, nothing a compliance team could apply to its own usage on Monday. When the operative distinction in a national security document is a matter of degree and the degree is unpublished, the practical effect is that platform operators get to draw the line privately, per account, with no appeal. That is not a hypothetical concern. It is what happens next month.
Our Take
The number that matters in this advisory is zero: the count of legal instruments cited in a document that took three agencies to sign. Everything else in it is evidence, and evidence is only interesting once you know what it is evidence for.
My read is that the government knows perfectly well that distillation cannot be prosecuted and can barely be defined, and published anyway, because the audience is not DeepSeek. The audience is the American labs, and the message is that their API surface is now treated as national infrastructure whether they wanted that designation or not. The advisory is a request for private policing dressed as a threat assessment, and the labs will comply, because the alternative is having compliance specified for them.
Practical implication if you build on frontier APIs. Nothing changes this week. Over the next two quarters, plan for identity verification to become a gate rather than a formality on top-tier model access, and check whether your provider chain runs through an aggregator, because the metadata story of that hop is now a documented federal concern. If you are running high-volume synthetic data generation against a frontier model for legitimate reasons, and many teams are, your traffic shape is indistinguishable from the thing this advisory describes. Talk to your account team before somebody's new heuristic talks to you.
Three signposts for the next 90 days. First, whether any of the six named companies appears on an OFAC or Commerce list, which is the direct test of whether the advisory was a predicate document or a bargaining chip. Second, whether any US lab publishes a verification requirement that cites the advisory, which is the direct test of whether the private policing theory is right and the fastest signal available, since a pricing or access page changes faster than a rulemaking. Third, whether anyone in government publishes a quantitative threshold separating research distillation from industrial distillation, because until somebody does, the line will keep being drawn by platform trust and safety teams with no obligation to explain it.
We track provider access changes and model availability on the models page. The next thing that moves this story is a signup flow, not a statute.
