On September 8, 2026, the US NSA, CISA and FBI issued advisory AA26-251A accusing six China-based AI firms, including DeepSeek, Moonshot AI and Alibaba, of running industrial-scale knowledge distillation campaigns against US frontier models. Follow-up coverage on September 10 and 11, 2026, detailed that the firms allegedly extracted billions of tokens from models such as Claude, GPT, Gemini and Grok, and that US agencies are urging providers to quietly downgrade suspected accounts instead of banning them.
This article aggregates reporting from 6 news sources. The TL;DR is AI-generated from original reporting. Race to AGI's analysis provides editorial context on implications for AGI development.
AA26-251A is the first time three major US security agencies have jointly named specific AI labs as industrial-scale distillers of US frontier models. It effectively declares that knowledge distillation against commercial APIs is now a national security issue, not just a contractual or research concern. That reframes how model providers, cloud platforms and even open-weight advocates will think about who gets access to what capabilities and under what monitoring.
For the race to AGI, this crystallizes an already visible trend: capability diffusion is being fought at the data and interaction layer, not just at the chip export layer. If DeepSeek, Moonshot, MiniMax, StepFun and Z.AI lose reliable access to Claude, GPT, Gemini and Grok, they will have to lean harder on domestic data, synthetic data and open-weight ecosystems to keep up. At the same time, the advisory’s recommendation that US labs silently downgrade models for suspected distillers risks collateral damage to legitimate heavy users and could drive some enterprises toward self-hosted or open-weight stacks they fully control.
Longer term, this is another nudge toward a bifurcated AI ecosystem: a US-led bloc where model API usage is heavily surveilled and tiered, and a China-led bloc that doubles down on homegrown compute and training data. That does not slow technical progress so much as change who can cheaply climb on top of US models, and it accelerates work on provenance, watermarking and model-authenticity layers.


