US Names Six Chinese AI Firms Accused of Stealing Claude, GPT and Gemini Capabilities
NSA, CISA, and FBI allege industrial-scale extraction of US AI capabilities by China-based companies

US agencies have accused six China-based AI companies of conducting industrial-scale operations to extract capabilities from America's leading AI models.
The National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI say the firms extracted 'billions of tokens' across millions of exchanges and requests from US frontier models including Claude, GPT, Gemini and Grok.
The joint advisory, published on 8 September 2026, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as companies involved in the campaigns. The agencies say the activity dates back to at least late 2024 and was carried out 'likely with the knowledge of the Chinese government'.
Inside the NSA-CISA-FBI Allegations
According to the advisory, the six firms did not simply study rival AI systems. The agencies allege they ran continuous, high-volume queries designed to extract proprietary capabilities, reasoning patterns and specialised functions from US frontier models.
DeepSeek is accused of conducting organised distillation campaigns involving Claude Sonnet 3.7, Claude Sonnet 4 and Claude Sonnet 4.5, as well as multiple GPT, Gemini and Grok models, to generate training data for its R1 and V3 models.
Moonshot AI is separately accused of extracting Claude Fable 5 data to train its Kimi-K3 system, while also using GPT-4o data to train Kimi-K2.
How the Extraction Campaigns Worked
US agencies describe infrastructure they say was designed to avoid detection. The companies allegedly used fraudulent accounts, bulk procurement of premium subscriptions and proxy services known as 'transfer stations' to bypass regional restrictions and provider safeguards.
These transfer stations reportedly resold access to US models at reduced prices while obfuscating identifying metadata. The advisory says the routing infrastructure allowed operators to distribute requests across multiple pathways and automatically switch between them during blocking attempts, making the campaigns harder to detect and trace.
The document also outlines a countermeasure now recommended to US AI companies. Rather than simply blocking suspected offenders, companies are advised to subtly alter responses or use less sophisticated models for users identified with high confidence as conducting malicious distillation, without informing those users of the change.
China-based AI companies are illicitly distilling U.S. frontier AI capabilities. Read NSA’s new report, co-sealed with @FBI, @CISAgov, highlighting AI knowledge distillation, TTPs used, and recommended mitigations: https://t.co/IgBFOnjXeg pic.twitter.com/JUYg5I08GP
— NSA Cyber (@NSACyber) September 8, 2026
A Longer Pattern of Accusations
This is not the first time Chinese AI firms have faced such allegations.
The White House Office of Science and Technology Policy said in an April 2026 memorandum that models developed through unauthorised distillation campaigns 'do not replicate the full performance of the original', although they can appear comparable on selected benchmarks.
That memorandum followed earlier disclosures in which Anthropic said three Chinese AI laboratories — DeepSeek, Moonshot and MiniMax — had generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.
The September advisory brings the six companies' alleged activities together in a single assessment by the NSA, CISA and FBI.
The accusations form part of an escalating US-China AI rivalry, in which the ability to develop frontier models faster and more cheaply has become a matter of national strategy as well as commercial advantage.
The agencies say industrial-scale distillation can allow Chinese AI companies to extract capabilities from US frontier models while reducing the research, computing and development resources required to build comparable systems independently.
For everyday users, the allegations also raise questions about transparency if AI companies begin quietly altering responses for accounts they suspect of misuse. The advisory recommends that suspected malicious distillers not be informed when their responses are changed or downgraded.
None of the six named companies had issued a public response to the specific allegations at the time of publication.
© Copyright IBTimes 2026. All rights reserved.

























