US agencies name six Chinese AI firms accused of copying American frontier models at industrial scale
The NSA, CISA, and FBI say DeepSeek and five other Chinese companies have been extracting capabilities from US AI models since late 2024, potentially saving billions in development costs.

Key points
- The NSA, CISA, and FBI jointly named six Chinese AI firms on Tuesday, accusing them of large-scale theft of US AI model capabilities.
- The six named companies are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
- The agencies say the firms targeted multiple US AI models, including versions of Claude, GPT, Gemini, and Grok.
- US agencies allege the Chinese government was likely aware of the activity.
- The agencies say the practice can dramatically shorten development timelines and cut billions from training costs.
Three US government agencies have pointed fingers at six Chinese AI companies, accusing them of running what they call "industrial-scale" operations to copy the capabilities of leading American artificial intelligence models.
The National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) issued a joint statement Tuesday naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies say the firms have been doing this since at least late 2024.
What exactly are they accused of doing?
The technique at the centre of this is called distillation. Think of it like this: instead of spending years and billions of dollars teaching an AI system from scratch, you feed it the answers from a smarter, already-trained system and let it learn by imitation. The agencies say these Chinese firms did that at scale, targeting American frontier models, the most capable AI systems that companies like Anthropic, OpenAI, Google, and xAI have built.
The specific models named in the advisory include variants of Claude (Anthropic's AI assistant), GPT (the family of models behind ChatGPT), Gemini (Google's AI), and Grok (xAI's chatbot). The agencies did not spell out exactly how the firms accessed these systems, but large language models, the AI technology behind all of these chatbots, are often accessible through public-facing products or developer APIs.
Does this mean the Chinese government was behind it?
The agencies stopped just short of saying so directly. Their statement says the six firms "likely" acted with "Chinese government awareness." Likely is doing a lot of work in that sentence, but from three federal agencies, it is a notable allegation, as first reported by Ars Technica AI.
The financial motive is straightforward. Training a frontier AI model from zero can cost hundreds of millions to billions of dollars. If distillation lets you shortcut that process, the savings are enormous. The agencies said the practice gives Chinese companies "significantly shorter AI development timelines and reduced financial expenditures."
What does this mean for ordinary users?
If you use any of the named apps, particularly DeepSeek, which became widely popular in early 2025, it is worth knowing that US agencies now formally consider it a national security concern. That does not mean the app will stop working on your phone tomorrow. But it does mean American regulators are watching these companies closely.
Privacy catch worth flagging: DeepSeek's own privacy policy states it stores user data on servers in China. If you share sensitive personal or work information with any of these AI tools, that data could be accessible to parties outside your control.
Common questions
Is DeepSeek safe to use?
US agencies have flagged DeepSeek as a national security concern, and its privacy policy confirms user data is stored in China. For casual use it may feel fine, but avoid sharing anything sensitive, like work documents or personal details, through the app.
What is AI distillation, in plain terms?
Distillation means training a new AI model by having it learn from the outputs of an existing, more capable model. It is faster and cheaper than training from raw data, which is why the agencies say it can save billions in development costs.



