What happened
On September 8, 2026, CISA, the NSA, and the FBI released a joint cybersecurity advisory (AA26-251A) formally accusing China-based AI companies — named as DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — of conducting systematic, industrial-scale knowledge-distillation campaigns to extract proprietary functionality and capabilities from US frontier AI models, alleging this is core (not incidental) to China's AI development strategy and likely conducted with government awareness. The advisory recommends mitigations for US AI companies including detection of malicious distillation query patterns and covert model-access downgrades for suspected malicious accounts, while continuing to inform legitimate safety researchers of any changes.
Why it matters
This is the first joint US intelligence/cybersecurity-agency attribution of AI model theft via distillation as a national AI-industrial-policy practice, elevating what was previously a contractual/IP dispute into a national-security matter. It creates pressure for US AI labs to implement stricter access controls, telemetry, and query-pattern monitoring, and provides an evidentiary and policy basis for further export-control or entity-list action against the named Chinese firms ahead of the planned US-China leaders' summit.
Action needed
US frontier AI labs should review and harden API access controls, rate-limiting, and anomaly detection for suspected distillation query patterns per the advisory's recommended mitigations; compliance/legal teams at labs with China-facing API access should reassess exposure given the advisory's implicit warning of forthcoming enforcement.