On September 8, 2026, the National Security Agency, FBI and CISA, America's cyber defense agency, accused six Chinese AI companies of harvesting American models' answers to train competing systems. Among their recommendations: quietly give suspected copiers less capable answers. For a business selling intelligence by the response, protecting the product could mean making the product worse for someone the seller has decided to distrust.
The answers become training material
The companies named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. According to the agencies, their campaigns gathered billions of tokens, the small pieces of text models process, across millions of exchanges with Claude, GPT, Gemini and Grok variants, since at least late 2024.
The method is called distillation: training a model to imitate capabilities demonstrated in another model's responses. Even the NSA explicitly recognizes legitimate uses of this technique. Its complaint concerns targeted extraction of restricted capabilities from competitors. Learning from a model and having permission to do so are separate questions.
That distinction puts the commercial interface under pressure. In the agencies' account, fraudulent accounts, resellers that conceal customer identities and intermediaries that bypass geographic restrictions spread the activity across multiple routes. A provider looking at one account sees only a fragment of the campaign it needs to identify.
Each customer can use an answer to complete a task or to help build a future competitor to its supplier. The response itself does not come back and explain which happened.
Anthropic's complaints came before the government warning
In February, Anthropic reported approximately 24,000 fraudulent accounts and more than 16 million exchanges with Claude, attributed to DeepSeek, Moonshot AI and MiniMax. Those are Anthropic's allegations about activity on its service, not an independently measured total for the industry.
The company later accused Alibaba of a campaign involving roughly 28.8 million exchanges over a 44-day window, as CNBC reported in June. Alibaba denied wrongdoing. June anchors the disclosure; the figure describes that campaign's measurement window, not a running count through September.
The supplier is selling responses for permitted uses. An alleged copier is collecting responses to improve a rival. Both can attach considerable value to the same transaction while disagreeing about what was sold.
Government awareness is still an assessment
The advisory describes copying as central to the named firms' development work. It also assesses Chinese government awareness as likely. Neither formulation should quietly become a statement that every capability was copied or that Beijing directed every request.
China rejected the accusation on September 9. The disagreement is on the record; repeating an accusation with an agency's name attached does not resolve it.
Even accepting the reported scale, volume answers only part of the economic question. To determine how much development work was displaced, a reader would need to know what the recipient learned and what it could have built without those responses. A count of exchanges cannot supply that counterfactual by itself.
The proposed defense changes what comes back
The agencies recommend altering responses or serving weaker models to suspected malicious distillers without notifying them. They frame targeted changes around high-confidence identification. This is guidance for providers, not evidence that every lab has implemented it.
Consider the incentive. Blocking an account tells the operator that a route has closed. Continuing to answer, with less useful material, could leave the collector investing in responses the provider has deliberately made less valuable. The defense would work partly through the collector's uncertainty.
That uncertainty creates a cost if the classification is wrong. A legitimate customer receiving weaker responses might blame the model's ability, their own prompts or their application. Without notice, they would lack the information needed to distinguish those possibilities from a defensive downgrade.
The advisory draws an explicit exception for AI safety researchers and outside evaluators, who should be informed of model changes. A useful evaluation depends on knowing what was evaluated. The exception preserves that principle while asking providers to withhold the same information from suspected copiers.
Why it matters
If the proposed defense is adopted, a provider's judgment about the customer could determine the quality of the answer. The boundary would run through the service itself: who gets the full capability, who gets less, and who gets told about the difference.
Protecting costly research from unauthorized imitation is a defensible goal. So is requiring a service to disclose when it deliberately changes what a customer receives. Here, achieving the first could require withholding the information that makes the second possible.
The burden would fall on the quality of the detection and the handling of mistakes. A promise to target only malicious actors still leaves someone responsible for deciding who qualifies, reviewing that decision and repairing the consequences when it is wrong.
Would you accept an AI provider secretly weakening your answers to protect its research from competitors, or should reliable disclosure take priority even when it helps the copier?
Adapted from a carousel prepared for @recul.ai.