The National Security Agency, the Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation published joint advisory AA26-251A on 8 September, and it does something these documents usually avoid. It names companies.1 CISA 2026-09-08 Advisory AA26-251A, 8 Sep 2026, NSA, CISA and FBI; names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI; billions of tokens across millions of requests from late 2024 to mid 2026; gray market transfer stations, chain of thought extraction and prompt injection; likely with Chinese government awareness. Open source DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI are identified as running industrial scale knowledge distillation campaigns against American frontier models, specifically variants of Claude, GPT versions 4 through 5.2, Gemini versions 2 through 3, and Grok.1 CISA 2026-09-08 Advisory AA26-251A, 8 Sep 2026, NSA, CISA and FBI; names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI; billions of tokens across millions of requests from late 2024 to mid 2026; gray market transfer stations, chain of thought extraction and prompt injection; likely with Chinese government awareness. Open source
The scale claimed is billions of tokens across millions of requests, running from late 2024 through mid 2026.1 CISA 2026-09-08 Advisory AA26-251A, 8 Sep 2026, NSA, CISA and FBI; names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI; billions of tokens across millions of requests from late 2024 to mid 2026; gray market transfer stations, chain of thought extraction and prompt injection; likely with Chinese government awareness. Open source The access paths were ordinary commercial ones, meaning APIs, cloud providers and third party aggregators, with gray market transfer stations used to bypass geographic restrictions.1 CISA 2026-09-08 Advisory AA26-251A, 8 Sep 2026, NSA, CISA and FBI; names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI; billions of tokens across millions of requests from late 2024 to mid 2026; gray market transfer stations, chain of thought extraction and prompt injection; likely with Chinese government awareness. Open source The tradecraft described is patient rather than clever: pools of premium accounts spreading requests, traffic routed centrally across several cloud providers, and metadata stripped to reduce traceability.2 Help Net Security 2026-09-09 Capabilities extracted include reasoning, coding, legal work, mathematics and agent development; tradecraft includes premium account pools, centralised routing and metadata obfuscation; CISA Acting Director Nick Andersen urged immediate steps; mitigations include differential privacy, varied responses, limited reasoning depth and routing suspects to weaker models. Open source
Two technical methods carry most of the weight. Chain of thought extraction targets the intermediate reasoning a model produces before it answers, which is the part with the most training value and the part a provider least intends to sell. Prompt injection is used to surface reasoning the provider has chosen to hide.1 CISA 2026-09-08 Advisory AA26-251A, 8 Sep 2026, NSA, CISA and FBI; names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI; billions of tokens across millions of requests from late 2024 to mid 2026; gray market transfer stations, chain of thought extraction and prompt injection; likely with Chinese government awareness. Open source Automated quality evaluation scored what came back, and failover logic rerouted traffic when a pathway was blocked.1 CISA 2026-09-08 Advisory AA26-251A, 8 Sep 2026, NSA, CISA and FBI; names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI; billions of tokens across millions of requests from late 2024 to mid 2026; gray market transfer stations, chain of thought extraction and prompt injection; likely with Chinese government awareness. Open source
The attribution sentence
The advisory states the activity occurred likely with Chinese government awareness.1 CISA 2026-09-08 Advisory AA26-251A, 8 Sep 2026, NSA, CISA and FBI; names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI; billions of tokens across millions of requests from late 2024 to mid 2026; gray market transfer stations, chain of thought extraction and prompt injection; likely with Chinese government awareness. Open source That is careful wording and it is worth reading precisely. Awareness is not direction. The agencies did not assert tasking, funding or operational control, and a joint advisory that had evidence of tasking would ordinarily say so. Readers should treat the state involvement claim as an assessment of knowledge rather than a finding of sponsorship, and coverage that upgrades it to a state directed operation is going beyond the document.
The sharper claim is commercial rather than geopolitical. The advisory describes distillation as the critical core of these companies development strategies rather than a supplementary activity.1 CISA 2026-09-08 Advisory AA26-251A, 8 Sep 2026, NSA, CISA and FBI; names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI; billions of tokens across millions of requests from late 2024 to mid 2026; gray market transfer stations, chain of thought extraction and prompt injection; likely with Chinese government awareness. Open source If that holds, the implication is that a category of frontier capability which was widely read as independent replication was substantially derived, and the capabilities listed are the commercially valuable ones: reasoning and coding, writing and question answering, agent development, legal work, mathematics and software engineering, and customer service automation.2 Help Net Security 2026-09-09 Capabilities extracted include reasoning, coding, legal work, mathematics and agent development; tradecraft includes premium account pools, centralised routing and metadata obfuscation; CISA Acting Director Nick Andersen urged immediate steps; mitigations include differential privacy, varied responses, limited reasoning depth and routing suspects to weaker models. Open source
The mitigations are the story
What the agencies recommend is more consequential than what they allege. Alongside conventional advice on identity verification and anomaly detection, including watching for round the clock usage without human variation, odd subscription to usage ratios, and accounts that hit maximum usage immediately, the advisory recommends that providers subtly alter outputs for suspected distillation attempts, apply differential privacy with controlled noise, vary responses, limit reasoning depth, and route suspected operators to less capable models.1 CISA 2026-09-08 Advisory AA26-251A, 8 Sep 2026, NSA, CISA and FBI; names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI; billions of tokens across millions of requests from late 2024 to mid 2026; gray market transfer stations, chain of thought extraction and prompt injection; likely with Chinese government awareness. Open source 2 Help Net Security 2026-09-09 Capabilities extracted include reasoning, coding, legal work, mathematics and agent development; tradecraft includes premium account pools, centralised routing and metadata obfuscation; CISA Acting Director Nick Andersen urged immediate steps; mitigations include differential privacy, varied responses, limited reasoning depth and routing suspects to weaker models. Open source
We assess with high confidence that this is a request for American AI companies to build a system that silently degrades service to users it suspects, on the basis of behavioural inference, with no notice and no appeal.
The security logic is sound. Poisoned outputs are the natural counter to extraction, because a distilled model inherits the noise. The governance problem is that the classifier deciding who gets the degraded product is a heuristic operating on usage patterns, and heuristics produce false positives. A research group running automated evaluations at high volume looks a great deal like a distillation pool. So does a startup building on an API around the clock. Neither receives a notification that the model it is paying full price for has quietly become a worse one.
CISA Acting Director Nick Andersen urged AI companies to take immediate steps to safeguard their platforms.2 Help Net Security 2026-09-09 Capabilities extracted include reasoning, coding, legal work, mathematics and agent development; tradecraft includes premium account pools, centralised routing and metadata obfuscation; CISA Acting Director Nick Andersen urged immediate steps; mitigations include differential privacy, varied responses, limited reasoning depth and routing suspects to weaker models. Open source The advisory does not address what a provider owes a customer it has wrongly flagged, and no American regulator currently requires disclosure that a paid model output was deliberately altered.
There is also a competitive asymmetry buried in the recommendation to limit reasoning depth.2 Help Net Security 2026-09-09 Capabilities extracted include reasoning, coding, legal work, mathematics and agent development; tradecraft includes premium account pools, centralised routing and metadata obfuscation; CISA Acting Director Nick Andersen urged immediate steps; mitigations include differential privacy, varied responses, limited reasoning depth and routing suspects to weaker models. Open source The reasoning trace is the part of a frontier model that users increasingly pay for, because it is what makes a model auditable and what makes an agent debuggable. A provider that shortens or conceals reasoning to frustrate extraction is withdrawing the feature that distinguishes a frontier product from a cheap one, and it is doing so at the request of the federal government rather than in response to a market signal.
Who gains
The advisory hands the named American providers a security rationale for tighter access control, which is also a competitive rationale. Gray market resale and aggregator access are margin leakage as well as extraction vectors, and a policy justified on national security grounds will close both. That is a real benefit to the incumbents and it is not why the document was written.
The open weight developers are unaffected and quietly vindicated in a narrow sense. Distillation defences are only meaningful for a model served behind an API. Weights that have been released cannot be protected from derivation at all, which means the entire enforcement architecture applies to exactly one half of the market.
Context is worth noting on timing. The advisory landed on a day that also carried roughly 80 billion dollars of Anthropic neocloud commitments and the Qualcomm arrangement with Amazon Web Services on custom inference silicon.3 The Neuron 2026-09-08 Daily digest confirming the advisory and its six named companies on 8 Sep 2026, with the document hosted on media.defense.gov; same day carried Anthropic neocloud commitments near 80 billion dollars and the Qualcomm and AWS inference silicon partnership. Open source The capital story and the security story are the same story: everything the agencies are asking providers to protect is the output of spending at that scale.
What to watch
First, whether any named company responds with a technical rebuttal rather than a diplomatic one. A dated account of independent training runs would be testable. A statement from a foreign ministry would not.
Second, whether any American provider discloses that it applies output degradation, and under what criteria. The advisory recommends the practice. Adoption of it, unannounced, would be the more significant development, and nothing currently compels a provider to say so.
Third, whether this advisory becomes the evidentiary basis for export control or procurement action against the six named firms. A joint advisory naming companies is frequently the predicate for a listing, and the document reads as though it was written to be cited later.