US agencies accuse six Chinese firms of copying American AI capabilities in a joint cybersecurity advisory released on 8 September 2026. The NSA, CISA and FBI document names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, alleging large-scale extraction of outputs from US models to develop competing systems. These are government allegations, not a court finding establishing liability.
The dispute concerns more than copying an individual answer. The agencies describe efforts to use repeated interactions with advanced models as training material for other models. For the companies involved, the argument centres on development costs, access restrictions and control over capabilities that can be reproduced without obtaining the original system’s internal parameters.
US agencies accuse six Chinese firms in a wider advisory
The advisory alleges that the named companies extracted billions of tokens through millions of exchanges, targeting variants of Claude, GPT, Gemini and Grok. It describes proxy infrastructure and other routes intended to conceal or distribute access. The agencies recommend detecting suspicious activity, changing responses to suspected extraction attempts and sharing intelligence. The document expressly acknowledges that distillation itself can be legitimate.
That qualification is central. Training one model from another model’s outputs is a technical method. Whether a particular use is authorised, deceptive or otherwise improper depends on the circumstances. Calling every instance of distillation theft would erase a distinction that the accusing agencies themselves preserve.
The latest development is the breadth and official status of the joint warning. LiveAIWire previously covered the dispute surrounding Moonshot and Anthropic. This advisory brings several companies and alleged campaigns into one government account, accompanied by recommendations for defensive action.
How learning from answers differs from stealing a model
A useful analogy is learning from a large collection of worked examples rather than obtaining the teacher’s private notes. The learner does not need a copy of the original machinery to imitate some of its behaviour. The quality, variety and selection of examples can matter to what is learned.
That analogy has limits, but it clarifies what should not be assumed. The allegation is not necessarily that attackers downloaded the original model’s weights or entered a laboratory’s internal network. A campaign involving model outputs can raise a serious access dispute even when the service delivering those outputs is functioning as designed.
The practical boundary is therefore partly about use. A service may permit a customer to obtain help with a task while restricting use of its responses to build a competing model. Assessing the allegation requires attention to the conduct, the applicable terms and the evidence connecting the activity to the accused organisation.
Anthropic had already made related allegations
In February, Anthropic reported campaigns involving DeepSeek, Moonshot and MiniMax. It alleged more than 16 million exchanges through roughly 24,000 fraudulent accounts. The company said it used indicators including request metadata, infrastructure and IP-address correlations for attribution. That is the affected vendor’s account, rather than an independent adjudication of the claims.
The vendor and government accounts should not be mechanically combined into a larger total. Their time periods, covered companies and definitions may differ, and the same underlying activity could appear in both. Treating the figures as separate descriptions avoids presenting overlapping allegations as additional independent incidents.
Equally, an official advisory does not make every inference beyond dispute. Readers need to distinguish the evidence described publicly from conclusions attributed to the agencies. The article cannot independently inspect confidential material that may sit behind the assessment, and should not imply that it has done so.
What changes for businesses using AI
For an ordinary customer, the publication does not itself establish a change to a subscription or access to a particular tool. Its immediate significance is a warning to providers and a sharper dispute about how competing systems are developed. Any subsequent product restriction, contractual change or government measure would need to be assessed on its own terms.
For a business building on model services, the episode makes access arrangements worth understanding. A supplier’s permitted uses, geographic restrictions and rules for using generated material may affect a proposed workflow. Paying for access does not, by itself, answer every question about what the resulting outputs may be used to build.
The advisory’s recommendations also raise a design trade-off. Providers trying to identify coordinated extraction need to avoid treating every intensive legitimate user as suspicious. A good enforcement process would distinguish evidence of prohibited conduct from ordinary high-volume work and provide a route for resolving mistaken restrictions.
The argument about training runs in both directions
The controversy sits alongside a broader dispute over the material used to build AI. LiveAIWire’s coverage of the music publishers’ case against Anthropic concerns a different set of allegations about training inputs. It provides context for why demands to protect model outputs attract scrutiny from people whose own work has become part of AI disputes.
Those controversies should not be treated as legally interchangeable. Using copyrighted works, breaching service terms and extracting model capabilities involve different facts and possible claims. An allegation against one party does not settle a separate allegation that party makes against somebody else.
The common policy question is how to define acceptable learning from existing material while preserving meaningful incentives to create it. That question cannot be answered simply by calling every use innovation or every imitation theft. Clear permissions, evidence and proportionate enforcement matter to both sides of the debate.
What to watch next
The most informative developments would be detailed responses from the named firms, further evidence that can be examined publicly and specific measures taken by providers. Claims about security consequences should likewise be separated from demonstrated incidents. A warning that capabilities could be misused is different from evidence that a particular misuse occurred.
For now, the defensible news is the joint accusation and the requested response. US agencies have identified model-output extraction as a coordinated threat to American AI companies. Whether the dispute produces narrower technical controls, wider access barriers or further legal action remains to be established.
About the Author
Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity and the social impact of emerging technology. LiveAIWire is an independent, human-led technology publication using AI-assisted research, editorial production and original AI-assisted editorial illustrations under his direction.
