Technology

CISA, FBI and NSA advisory AA26-251A: what it alleges about AI model distillation

Advisory AA26-251A from CISA, the FBI and NSA alleges industrial-scale AI model distillation. Here is what is claimed, contested and not public.

Original editorial illustration of advisory AA26-251A beside a shield and a teacher AI model transferring knowledge to smaller models
Original editorial illustration of advisory AA26-251A beside a shield and a teacher AI model transferring knowledge to smaller models. Illustration: Reddy News.
Key points
  • CISA, the FBI and the NSA published advisory AA26-251A on 8 September 2026, alleging industrial-scale, unauthorised AI model distillation by six named China-based companies.
  • Model distillation is not inherently improper: a student model can legitimately learn from a teacher model when the necessary access and permissions exist.
  • The advisory alleges billions of tokens across millions of exchanges since late 2024, but does not publish raw logs, a complete forensic dossier or court-tested proof.
  • Anthropic’s first-party report gives its own methodology and figures for DeepSeek, Moonshot and MiniMax only; it is not independent confirmation of allegations about Alibaba Group, StepFun or Z.AI.
  • China’s Ministry of Commerce rejected the U.S. allegations as lacking factual and legal basis, while China’s Foreign Ministry called for an end to what it described as unfounded accusations.
  • The advisory does not name India, Indian companies or an India-specific campaign; its provider guidance is stated at a U.S. policy level.

What the CISA FBI NSA advisory AA26-251A says

On 8 September 2026, the U.S. Cybersecurity and Infrastructure Security Agency published AA26-251A, a joint advisory with the Federal Bureau of Investigation and the National Security Agency. Its title is “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies.” The publication is verifiable. Its substantive account is an official U.S. government allegation, not a judicial finding.

The agencies allege that six China-based companies obtained capabilities from variants of U.S. frontier models, including Claude, GPT, Gemini and Grok, since at least late 2024. They call the claimed activity unauthorised and industrial in scale, and assess that it was likely undertaken with Chinese government awareness. That qualified assessment does not publicly establish state direction, funding or control.

AA26-251A should be read with claim discipline. It raises whether particular access and use were authorised, not whether distillation itself constitutes misconduct. It does not establish criminal liability, sanctions or a company admission. Reuters and other outlets independently reported the advisory and competing official responses; that coverage does not independently verify the alleged conduct.

Distillation is a technique, not a verdict

In plain English, model distillation trains a smaller or less capable “student” model to reproduce useful behaviour from a stronger “teacher” model’s outputs. The aim can be lower cost, lower latency or a system specialised for a narrower job. Reuters describes the technique as using the outputs of larger, more expensive models to lower the cost of training a new tool.

That technique can be legitimate when a developer has permission to use the teacher model and its outputs. Anthropic says frontier laboratories routinely distil their own systems into smaller, cheaper versions. For an external project, authorisation can depend on provider permissions, contract terms, access controls, training-data provenance and applicable law. This article does not offer a legal conclusion about every use of model outputs.

The U.S. agencies’ alleged distinction is a combination of unauthorised access, purported violations of provider rules and geographic restrictions, targeted acquisition of proprietary capabilities, and high volume. That is why it is misleading both to call all distillation improper and to treat the advisory’s account as already proven. The same word describes a recognised optimisation method and a disputed set of claimed practices; the authorisation and evidence are the crucial questions.

The six companies named and the scale claimed

AA26-251A names DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun and Z.AI. That list is a fact about the advisory’s contents, not an independently established finding about any company. The agencies allege that the six collectively extracted billions of tokens across millions of exchanges or requests. The advisory does not publish one total token count, one total request count or a complete company-by-company numerical breakdown.

Its company narratives are uneven. CISA says DeepSeek’s claimed activity began no later than late 2024 and says Moonshot AI’s began no later than mid-2025. It places alleged activity involving Alibaba Group and MiniMax in late 2025, and StepFun’s between late 2025 and early 2026. For Z.AI, the advisory alleges billions of tokens from specified U.S. models by mid-2026. Those dates and quantities are the agencies’ claims, not independent measurements.

The agency document associates the alleged activity with abilities such as reasoning, coding, agentic functions, reinforcement learning and supervised fine-tuning. Those labels describe what CISA says was targeted; they do not establish that a particular model capability was copied. The document’s lengthy version lists also include a minor MiniMax naming variation, so this explainer does not present every label as a settled technical record.

How to read the advisory’s scale claim

“Billions of tokens” can sound definitive, but it is a broad measure rather than a disclosed ledger. A token is a unit of text a model processes or produces; token volume does not by itself show what material was used, whether it was authorised, or what training effect followed. AA26-251A gives a collective billions-and-millions allegation and a Z.AI-specific billions allegation, while most of its other company accounts have no published quantity.

The advisory says the alleged activity shortened development timelines and reduced training costs. That is an agency assessment, not an audited reconstruction of research spending, training budgets or product roadmaps. Its comment on DeepSeek’s publicly quoted $5.6 million figure is likewise CISA’s evaluative assertion, not a public independent audit.

Three points should remain separate: the advisory shows that U.S. agencies made detailed allegations; its scale language explains why they consider the issue serious; and the underlying numerical record is not public. Broad counts should not be extrapolated into a conclusion about each company.

What evidence is public — and what is not

AA26-251A publishes a narrative, indicators the agencies say are associated with the alleged conduct, general attribution conclusions and defensive recommendations. It does not publish raw request logs, account data, forensic images, a technical appendix that assigns evidence to every named company, or evidence tested in court. The absence of a public evidence bundle does not prove the allegations false; it does mean readers cannot independently reproduce the agencies’ attribution from the advisory alone.

The publication’s wording on the Chinese state requires similar care. The agencies assess that the alleged activity occurred “likely with Chinese government awareness.” This is a qualified attribution assessment. It is not public proof that Beijing ordered the activity or that every named company acted under state direction. Converting awareness into command would overstate the source.

Independent coverage serves a different purpose. Reuters, AP reporting carried by ABC News, CNN and Al Jazeera confirm the advisory’s release and record the public dispute. None supplies an independent forensic audit that settles the company-specific allegations.

What Anthropic’s report adds — and its limits

Anthropic published its own report on 23 February 2026, before AA26-251A. It says it identified campaigns by DeepSeek, Moonshot and MiniMax that generated more than 16 million exchanges with Claude through about 24,000 accounts it describes as fraudulent. It also gives separate figures of more than 150,000 exchanges for DeepSeek, 3.4 million for Moonshot and 13 million for MiniMax. These are Anthropic’s first-party claims and figures.

Anthropic says it attributed the three campaigns with high confidence using IP-address correlation, request metadata, infrastructure indicators and, in some cases, partner corroboration. That is more methodological detail than the joint advisory publishes, but it remains a model provider’s analysis of activity against its own service, not an independent audit or judicial determination.

Its scope is also narrower than AA26-251A. Anthropic’s report concerns Claude and three laboratories; it does not independently substantiate the advisory’s allegations involving Alibaba Group, StepFun or Z.AI, nor does it establish every allegation involving the other three. CNN reported Anthropic’s 16-million-exchange claim, but reporting that the company made a claim is not separate verification of the claim.

China’s response and the companies’ response status

China’s Ministry of Commerce rejected the U.S. allegations on 9 September, saying they lacked factual and legal basis. It called distillation a neutral, common technical method, argued that U.S. companies’ model-development reports disclose extensive distillation of Chinese models, and said China would take countermeasures if the issue were used to suppress Chinese AI companies. Those are the ministry’s counterclaims; the sources reviewed do not independently validate them.

China’s Ministry of Foreign Affairs separately urged the United States to refrain from what it called unfounded accusations or smears, and said the two countries should strengthen AI cooperation. AP reporting carried by ABC News recorded that position. It is a government response to the advisory, not an evidentiary answer by one of the named companies.

No attributable public statement from DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun or Z.AI was located in the reviewed sources by the article’s stated cutoff. AP said four companies did not immediately respond to its request; Al Jazeera said the named companies did not immediately respond to its request; and The Stack reported no response before publication. This should not be read as acceptance of the allegations, a permanent refusal to comment or evidence of liability.

What the agencies recommend — at policy level

The advisory’s main audience is the AI ecosystem rather than ordinary users. CISA, the FBI and the NSA call for comprehensive detection and mitigation of anomalous account and usage patterns, targeted response changes when suspected extraction is assessed with high confidence, and intelligence sharing among model providers, cloud platforms and API aggregators. These are policy-level recommendations from the agencies.

The governance issue is balancing protective controls with legitimate research, customers and developers. The agencies’ logic is that patterns spread across providers can be harder to assess in isolation, warranting coordination around credible indicators and care to reduce erroneous action against normal users. That does not make every high-volume or cross-border customer suspicious.

This article deliberately does not reproduce the advisory’s operational descriptions of alleged access abuse, evasion or capability-extraction methods. Publishing those details as a how-to guide would not help readers understand the policy dispute and could aid attempts to bypass provider safeguards. The public-interest takeaway is the governance approach: access assurance, anomaly assessment and cross-organisation coordination.

What AA26-251A means for India — and what it does not

AA26-251A does not name India, Indian companies, Indian government entities, Indian users or an India-specific campaign. It should not be recast as a warning that India is implicated, targeted or subject to a new U.S. requirement. The official advisory is about allegations concerning the six named China-based companies and recommendations for the U.S. AI ecosystem.

There is still a bounded global relevance. Indian developers, enterprises and cloud customers that use AI services face familiar questions about provider permissions, data provenance, access governance and responsible use. Those are general operational and policy questions, not evidence of an India-specific threat or legal duty arising from AA26-251A. Organisations should look to the terms and laws that actually govern their own use rather than infer obligations from this U.S. advisory.

Related Reddy News coverage of OpenAI GPT-6 Astra rollout access in India and OpenAI Agents API public beta for India developers concerns product access and tools. AA26-251A is an allegation-led cybersecurity and technology-policy document.

The important distinction for readers and policymakers

AA26-251A turns an AI-industry dispute about access, outputs and training into a named joint U.S. national-security advisory. Its public record establishes that the agencies made allegations, the six companies are named, China rejected the account, and no attributable company response was located in reviewed reporting by the cutoff.

Key questions remain unresolved. The public advisory does not let outside readers test raw evidence, settle authorisation under relevant contracts or law, or substitute for a court ruling. Anthropic adds a separate, narrower account for three laboratories, but its report is first-party and does not cover the full six-company case.

For policymakers, providers and users, the durable lesson is precise rather than rhetorical. Distillation is a legitimate technical category; authorisation, evidence and context determine the disputed case. Treating government allegations as settled fact would mislead readers. Treating the existence of a legitimate technique as an answer to every allegation would do the same.

Reader guide

Article questions, answered

Short answers to common reader questions based on the reporting above.

What is CISA FBI NSA advisory AA26-251A?

AA26-251A is a joint U.S. cybersecurity advisory published by CISA with the FBI and NSA on 8 September 2026. It alleges that six China-based AI companies carried out unauthorised, industrial-scale knowledge-distillation activity against U.S. frontier AI models. The advisory is an official government allegation and defensive guidance, not a court judgment or an independently audited finding of wrongdoing.

What is legitimate AI model distillation?

Model distillation is a training technique in which a smaller or less capable student model learns useful behaviour from a stronger teacher model’s outputs. It can be legitimate when the developer is permitted to use the teacher model and outputs. The disputed issue in AA26-251A is whether the access and use alleged by the U.S. agencies were authorised, not whether distillation as a technique is inherently improper.

Which companies does AA26-251A name?

The advisory names DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun and Z.AI. Naming in the advisory establishes that the agencies made allegations about those companies; it does not independently establish that the allegations occurred.

What evidence did the agencies make public?

AA26-251A provides allegations, behavioural indicators, broad scale claims and company-specific narratives. It does not publicly provide raw request logs, account records, a company-by-company forensic evidence bundle, or a court-tested record. Independent reporting confirms the advisory and official responses, but does not independently authenticate the alleged activity.

Did any of the named companies respond?

No attributable statement from any of the six companies was located in the sources reviewed for this article by 14 September 2026, 12:00 PM IST. Contemporary AP, Al Jazeera and The Stack reports said companies had not immediately replied to their requests for comment. That reporting status is not an admission and can change.

Does AA26-251A name India or Indian companies?

No. The advisory does not name India, Indian companies, Indian government bodies, Indian users or an India-specific campaign. Its relevance for Indian developers and businesses is a general governance question around AI-provider permissions, data provenance and access controls; the advisory does not create an India-specific finding or obligation.

Sources and further reading

These references support the factual context used in this article. Links open the original publisher.

  1. China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI CompaniesCybersecurity and Infrastructure Security Agency · accessed 14 September 2026
  2. US accuses Chinese AI firms of 'malicious' copying of AI technologyReuters via Virginia Business · accessed 14 September 2026
  3. China hits back at US claims of 'malicious' AI distillation ahead of planned talksAssociated Press via ABC News · accessed 14 September 2026
  4. US claims Chinese AI firms are carrying out ‘industrial-scale’ theft of trade secretsCNN · accessed 14 September 2026
  5. MOFCOM spokesperson answers reporter’s question on the U.S. cybersecurity advisory related to alleged distillation activitiesMinistry of Commerce of the People’s Republic of China · accessed 14 September 2026
  6. Detecting and preventing distillation attacksAnthropic · accessed 14 September 2026
  7. China slams US claims of ‘industrial-scale’ AI theftAl Jazeera · accessed 14 September 2026
  8. CISA, FBI back up US AI labs' China distillation accusationsThe Stack · accessed 14 September 2026