· AI
The NSA Just Called AI Distillation a Security Threat. American Labs Use It On Each Other Too.
A real security concern about a technique the industry cannot put back in the bottle and will not stop using on itself.
On September 8, the NSA, CISA, and the FBI published a joint advisory naming six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, and accusing them of running industrial-scale campaigns to extract the capabilities of American frontier models. The advisory says the six have pulled "billions of tokens across millions of exchanges" from Claude, GPT, Gemini, and Grok since late 2024, using fraudulent accounts and proxy hubs, which the advisory labels transfer stations, to route requests around geographic blocks and rate limits.
My take: the security concern is worth taking seriously. The fix the advisory points toward is not going to work, and the framing quietly skips over an inconvenient fact. Distillation, the technique at the center of this, is exactly what has made frontier-adjacent AI affordable for anyone who is not one of the three or four companies that can afford to train from scratch. That includes some of the loudest American voices now treating it as a national security problem.
Steelman: this is not ordinary competition
Give the advisory its due first. Distillation, training a new model on the outputs of an existing one, is a normal and useful research technique, and the advisory says so directly. What it describes goes further than that. DeepSeek allegedly pulled from four versions of Claude, five of GPT, two of Gemini, and Grok 4 to build its R1 and R3 models, and the advisory notes that DeepSeek's widely cited $5.6 million training-cost figure understates how much of R1's ability rode in on other companies' models rather than DeepSeek's own compute, per CyberScoop's reporting. Moonshot AI is accused of distilling 18 different U.S. models, Anthropic's Fable included, to build Kimi K2 and K3.
If that holds up, it is not a researcher fine-tuning on public completions. It is six well-funded firms deliberately rotating accounts and routing through gray-market resellers specifically to keep extracting after being cut off, which is a different animal from an ordinary training-data dispute, and it does blunt years of chip export controls meant to slow China's path to frontier-grade capability. That case deserves a fair hearing, not a shrug.
Where the advisory can't have it both ways
Here is the problem: distillation is not a technique the accused firms invented, and American labs are not innocent of using it on each other. OpenAI and Microsoft were already banning suspected distillation accounts back in early 2025, mostly aimed at rivals, not at China specifically. Anthropic made its own distillation accusations against competitors earlier this year. And Elon Musk admitted under oath, in litigation reported by Engadget, that xAI trained on OpenAI's outputs too. The technique the advisory wants treated as a national security threat is standard practice among the very companies it is trying to protect. The real objection is not to distillation itself. It is to who is doing it and how fast they are closing the gap.
That is why the advisory's own remedy, closer information sharing across government, industry, and allied nations, will not hold up. The evasion tactics it documents, rotating accounts, proxy chains, third-party aggregators, gray-market API resale, exist precisely because ToS enforcement has already failed against determined, well-capitalized actors. If OpenAI, Anthropic, and Google cannot fully stop each other's labs from distilling their models, a memo asking allied governments to share threat intelligence will not stop six companies with state backing and purpose-built evasion infrastructure either. Locking down model outputs by policy is fighting the last war; the market has already made clear that model outputs, unlike source code, are nearly impossible to fence off once an API is public.
What this actually means for your AI bill
None of this changes your invoice tomorrow, but it tells you something real about where prices are headed. The downward pressure on frontier-tier pricing over the last two years has come substantially from exactly this dynamic: cheaper models catching up fast enough on capability that the expensive ones have to compete on price. An advisory does not reverse that, because it cannot stop the mechanism causing it, and Washington calling the mechanism a threat when foreign labs do it does not make it disappear when domestic labs do the same thing to each other next quarter.
The part worth keeping for your own stack is the distinction, not the technique itself. Routing routine work to a smaller, cheaper model while reserving a frontier model for what actually needs it is good engineering, done on your own licensed data or squarely within a vendor's published API terms. What the advisory describes is different in kind: unauthorized, obfuscated extraction at industrial scale from someone else's paid service. If you are trying to figure out where a smaller or open model can honestly replace a frontier one in your own workflow, that is a normal vendor decision, and it is one worth making deliberately rather than defaulting to whichever model has the biggest name attached.
Sources
References used in this article. Links also appear alongside the relevant claims.
Tell us what's on your mind.
You don't need a polished brief to reach out. A two-line email about what's bugging you is plenty; we'll tell you straight if we're the right fit, and what we'd tackle first.
We'll scope the work around your workflow, goals, and timeline before quoting anything, so you know what's included before committing.