Threat Intelligence

US Agencies Warn of Industrial-Scale AI Model Extraction by China-Based Firms

The Hacker News · 9 Sept 2026
Key Takeaway Businesses using AI APIs and subscriptions should monitor account usage patterns for unusual bulk access and enforce strict terms-of-service compliance to reduce exposure to unauthorised data extraction.

The NSA, CISA, and FBI have jointly accused several China-based AI companies, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running industrial-scale 'distillation' operations against leading US AI models. According to the joint advisory, these firms have extracted billions of tokens across millions of exchanges from models such as Anthropic's Claude, OpenAI's GPT, Google's Gemini, and SpaceXAI's Grok since late 2024, likely with backing from the Chinese government.

While distillation is a legitimate AI research technique, the agencies say the scale and methods used here go far beyond normal use. Reported tactics include bulk purchasing of premium subscriptions shared across development teams, extracting chain-of-thought reasoning data, automatically switching between access pathways when blocked, and using detection-evasion frameworks to spot and bypass defensive countermeasures. The agencies also allege that requests are routed through APIs, cloud providers, and third-party aggregators that hide user metadata, all in violation of the US companies' terms of service.

The advisory states that this activity gives Chinese AI firms significantly shorter development timelines and lower costs when building competing frontier models, effectively allowing them to shortcut years of expensive research using data harvested from established US systems.

AI security data extraction national security China AI models
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.