Three federal agencies just named names
CISA, the NSA, and the FBI jointly published advisory AA26-251a this week, formally attributing industrial-scale distillation campaigns against U.S. frontier AI models to six named Chinese companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The advisory states these firms have been extracting capabilities from Claude, multiple versions of GPT including GPT-4, GPT-4o, GPT-5, and GPT-5.5, Gemini 2.5, and Grok 4 since at least late 2024, with DeepSeek starting first, Moonshot AI joining in mid-2025, and Z.AI reportedly pulling billions of tokens by mid-2026. Naming six companies directly in a joint federal advisory, instead of describing a generic threat pattern, marks a deliberate escalation, and it comes from three agencies that do not typically coordinate a single statement unless the underlying evidence has already cleared a high internal bar. Each of the six companies has a real commercial footprint outside China, which is precisely why the specificity here matters more than a typical threat-actor bulletin.
It puts these firms on record as subjects of a coordinated U.S. government finding, which changes how any enterprise or government contractor with ties to these companies, or to products built on their models, should be assessing that relationship going forward. For CISOs at organizations with defense, government, or export-control exposure, a named federal advisory carries more weight in a compliance review than a vendor's own denial ever will, and it gives procurement teams a citable, dated reference point the next time a vendor security questionnaire asks about AI supply-chain risk.
The mechanics: this is not casual API scraping
The advisory describes a layered evasion architecture built specifically to look like normal usage. Requests route through gray-market "transfer stations," essentially API proxies that bypass regional access restrictions, distributed across pools of premium accounts so no single account trips a usage-limit alert. Traffic gets centralized and routed across multiple APIs and cloud providers simultaneously, and identifying metadata is stripped before requests reach the target model, all specifically engineered to defeat the kind of anomaly detection a security team would normally rely on. The advisory puts the scale at billions of tokens and millions of requests, volumes that no individual researcher or small team generates through normal API use.
The targeted capabilities are not general chat output. The advisory specifies chain-of-thought reasoning, specialized coding and legal-work functions, agentic task execution, and mathematics, the exact capabilities that took the named American labs the most capital and research time to build. Quality-control pipelines on the attacking side even detect when a targeted provider has altered its responses to poison extraction attempts, meaning this is an adversarial, iterating operation rather than a one-time scrape.
Why this is a decision for more than the AI labs
Reading this purely as a dispute between AI vendors misses the point for enterprise security teams. Any organization running a business on API access, whether that is an LLM provider, a SaaS platform, or an internal data service, faces the exact same evasion toolkit: account pooling, proxy layering, metadata scrubbing, and traffic distribution designed to make bulk unauthorized extraction look like normal customer usage. The techniques CISA just documented against AI labs describe what bulk data theft against any API-fronted enterprise service looks like once an attacker has real resources and patience behind the operation, which is worth internalizing well beyond the six companies named here.
There is also a direct exposure for enterprises with defense, government, or regulated-industry relationships. If your organization's AI vendor is a subject of a federal advisory naming nation-state-linked IP extraction, that vendor relationship now carries geopolitical and contractual risk that did not exist last week, particularly for anyone under export-control or CFIUS-adjacent scrutiny who needs to demonstrate their AI supply chain is clean. Procurement and legal teams that have not yet flagged AA26-251a in a vendor-risk register should do so this week, before an auditor or a regulator raises it first.
What CISA is telling AI providers to actually do
The mitigations are concrete and detection-oriented rather than aspirational. Providers should flag continuous 24/7 usage without the variation a human user naturally produces, watch for subscription accounts whose API usage ratio is wildly disproportionate to a normal customer, and treat new subscriptions that rapidly hit maximum usage limits as a signal worth investigating rather than a growth win. Stronger identity verification at account creation is explicitly recommended as a first line of defense.
Beyond detection, the advisory recommends active countermeasures: introducing response variation and limiting exposed reasoning depth for suspected extraction sessions, routing suspected operators toward less capable model tiers rather than cutting them off outright, and layering differential privacy with controlled noise into outputs to degrade the fidelity of anything being harvested. Rate limiting, continuous monitoring, and adversarial training round out the list, and the advisory closes with a direct line: "We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies."
The question every enterprise AI buyer should now be asking
If you are procuring or renewing frontier model access this quarter, ask your vendor directly what abuse-detection controls they run against exactly the pattern CISA just described, and whether they have evidence their own model outputs have not already been harvested at scale by one of the six named firms. A vendor with a credible answer has actually built the monitoring the advisory recommends; a vendor without one is telling you their platform, and by extension whatever proprietary prompts, data, or workflows your organization sends through it, has the same exposure the advisory just made public.
This advisory also belongs in your own AI governance conversation, not just your vendor-risk file. The same evasion techniques, proxy layering, account pooling, metadata stripping, apply just as well to an insider or a compromised partner trying to exfiltrate your own proprietary models or data through legitimate-looking API traffic. CISA just handed every security team a detection checklist for a threat pattern that will not stay confined to frontier AI labs for long.



