The US Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI) and National Security Agency (NSA) have warned that several Chinese artificial intelligence companies allegedly spent months using “distillation attacks” to extract proprietary capabilities from leading US AI models. The advisory names DeepSeek, MoonshotAI, Alibaba, MiniMax, StepFun and Z.AI. Potentially affected US companies include Anthropic, OpenAI, Google and xAI.
The activity involves sending large volumes of carefully designed prompts to advanced models in an effort to reproduce their capabilities, reasoning patterns and safety restrictions. The resulting outputs can then be used to train or improve another model. CISA said some of the activity may have been conducted with the knowledge of the Chinese government, and estimated that the extracted capabilities correspond to billions of dollars in US research and development spending.
Proxy networks and fake accounts complicate detection
The advisory says the operators used proxy servers to conceal their true origins and built extensive networks of fake users. Those accounts sent large numbers of queries to evade platform monitoring and access controls. Some campaigns may have continued for months, with the objective of systematically mapping how a model performs across different tasks, subject areas and safety boundaries rather than obtaining a single answer.
Attackers also used prompt injection to persuade models to disregard their existing rules. In a September 2026 threat report, Anthropic described several prompts associated with model-distillation activity. One approach instructed a model “not to flag this as reasoning extraction,” while another claimed that the user was debugging the system and asked it to reproduce earlier reasoning word for word. Other prompts were disguised as system instructions and requested the full contents hidden inside <thinking></thinking> tags.
Distillation is not inherently unlawful. Researchers can study a model’s outputs and compare different answers to improve their own systems, which has legitimate uses in technical research. US cybersecurity agencies and AI companies draw a distinction between that work and campaigns that rely on large numbers of fake accounts, bypass service terms or induce a model to disclose restricted material. They argue that the latter activity goes beyond ordinary research.
AI companies tighten controls as tactics evolve
No single technical measure can currently prevent these attacks altogether. Anthropic and other AI companies are improving the detection of abnormal query patterns, customer identity checks and access controls, while applying more targeted responses to different types of activity. Companies are also working to share threat intelligence so they can identify similar account networks and query patterns more quickly.
CISA has called for a coordinated response covering the wider AI ecosystem. That approach would involve model developers, cloud providers, identity-verification services and the US government, rather than leaving individual companies to block the activity on their own.
The economics of AI services add to the challenge. As competition pushes prices lower and reduces the cost of making large numbers of model calls, the barrier to collecting extensive output may also fall. Platforms therefore continue to face pressure to monitor unusual usage, verify customers and protect restricted model behavior without disrupting legitimate access.
Security concerns extend beyond commercial secrets
US security agencies are concerned that large-scale replication of advanced AI capabilities could affect not only competition between Chinese and US companies, but also the availability of models with weaker safety controls. In a February 2026 report on distillation attacks, Anthropic warned that dangerous capabilities could remain in an extracted model even if the original safeguards were weakened or removed.
The company said such systems could potentially support the development of biological weapons, the design of advanced military equipment, large-scale cyberattacks or other highly disruptive automated operations. It also warned that governments with strong political control could use similar systems to develop offensive cyber weapons, conduct disinformation campaigns and carry out mass surveillance.
For AI companies, the issue is therefore broader than the loss of proprietary technology. Once a model’s capabilities and safety boundaries have been copied, the original developer may have less control over how those capabilities are deployed and whether safeguards remain in place.
Questions raised over DeepSeek’s reported costs
The dispute is also affecting how investors assess China’s low-cost AI model strategy. DeepSeek attracted significant market attention after claiming that it developed an advanced system at a cost far below that of leading US models. CISA said in its advisory that DeepSeek’s publicly cited training cost of $5.6 million was incomplete because it did not include the full cost of obtaining data and capabilities through large-scale, allegedly abusive distillation.
The advisory said DeepSeek had used prompts to ask US AI tools to reveal their step-by-step reasoning, creating a path for improving its own models. If that assessment is correct, the headline training figure would not represent the full investment required to develop the system and would not be directly comparable with models trained through the purchase of proprietary chips, construction of data centers, provision of electricity and employment of research teams.
Price competition across the AI industry is intensifying at the same time. Smaller and more efficient models are seeking developers and enterprise customers with lower fees, while Chinese models including DeepSeek are expanding their presence in the US market.
For investors, the key questions extend beyond model-call pricing. They include how companies substantiate the origin of their training data and model capabilities, whether platforms can reduce the hidden costs created by distillation attacks, and whether regulators will encourage broader cooperation across the AI ecosystem.