UnDesto AI®

Six Chinese AI companies just got caught copying American models. Here is what that means for your business.

Right? You saw the headline and scrolled past it. Another AI espionage story, another set of acronyms. But this one is worth ninety seconds of your attention. So let’s break it down, because it changes how you should think about the AI tools running inside your company.

Here is what actually happened.

The federal government named names

On September 8, 2026, the NSA, the FBI, and the Cybersecurity and Infrastructure Security Agency published a joint advisory, numbered AA26-251A. It names six China-based AI companies. They are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. According to the advisory, these companies ran what the agencies call “industrial-scale knowledge distillation campaigns.” The targets were American AI models, including outputs from Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini, and xAI’s Grok families.

Knowledge distillation, in plain English, means training a cheaper, smaller model by learning from the answers a bigger model gives. It is a real technique, and companies use it on their own models all the time. So the problem here is not the method. Instead, it is the scale and the lack of consent.

The advisory describes proxy networks, nicknamed “transfer stations,” built to dodge geographic restrictions and rate limits. It also describes bulk-purchased subscriptions shared across teams of developers. Then there is automated failover, which kicked in whenever one access point got blocked. On top of that, jailbreak-style prompts were used to pull out a model’s hidden reasoning steps.

The scale is the real headline here. According to the advisory, the six companies extracted billions of tokens. They did it through millions of requests, and the earliest campaigns date back to late 2024.

Why the agencies are worried

CISA’s acting director, Nick Andersen, said it plainly: “We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies.” That is the strategic worry, in one sentence. Because if a competitor can copy years of research for a fraction of the cost, your lead shrinks fast.

China’s Ministry of Commerce rejected the accusations the very next day. It called distillation a “widely used, neutral AI development technique.” It also said the claims lack factual and legal grounds.

Still, both things can be true at once. Distillation is a normal technique. But doing it at this scale, this covertly, and against a competitor’s paid product, is still a real problem. I am not here to referee that argument. Instead, I am here to tell you what it means for your Monday morning.

The part almost nobody is covering

Here is the detail buried deep in the advisory, and it matters more to you than the six company names do. The agencies recommend that AI providers respond to suspected distillation quietly. Instead of banning the account, they suggest feeding it a worse model or adding noise to the output. They also recommend doing it unevenly, so the change is hard to detect. Finally, they recommend not telling the account holder what happened at all.

Think about what that means if your business makes a lot of AI calls. Maybe it is a busy customer service bot. Maybe it is an agent pipeline that batches thousands of requests overnight. Or maybe it is a sales team running enrichment scripts against an API all day long. Security researchers have already flagged the obvious side effect here. Because heavy, legitimate enterprise usage can trigger the same volume signals as an attack.

So your AI could get quietly worse. And you would have no way of knowing why, since the entire point of the recommended response is that you are never told.

That is not paranoia. That is the plan, written down, in a federal advisory, as the recommended defense.

Why this is now a business risk

This connects directly to the Security pillar in our Six Pillars of AI framework. Most executives think of AI security as “keep our data from leaking out.” However, this story flips that around. It is also about what happens when your vendor cannot tell the difference between a nation-state scraping operation and your own finance team running month-end reports.

So ask yourself three questions this week. First, does your AI vendor have a stated process for handling flagged accounts? Second, do you have a fallback if your primary model quietly gets worse for a stretch of days? Finally, if your company ships an AI-powered product to customers, are you protecting your own model outputs the same way?

A security analyst monitors multiple screens tracking network activity
The advisory tells providers to quietly alter output for suspected bad actors instead of banning them, without notifying the account holder.

What to actually do about it

Four moves, and you can start all of them this week.

  1. Ask your AI vendor, in writing, how they detect anomalous activity. Also ask what your recourse is if you get flagged by mistake. A real answer should exist, and if it does not, that is useful information too.
  2. Build in a fallback model or vendor for any workflow where a silent quality drop would hurt your business. Do not assume your primary provider will always perform the way it does today.
  3. If your organization builds or resells an AI-powered product, apply similar anomaly detection to your own API. After all, your outputs are your intellectual property too.
  4. File anything suspicious with the FBI’s Internet Crime Complaint Center. The advisory specifically names IC3 as the reporting channel, and most businesses have never used it.

None of this requires you to understand geopolitics. It just requires you to treat your AI vendor relationship like any other critical supplier. That means a contract, a backup plan, and a clear question about what happens when things go sideways.

The bigger picture

Two governments are now fighting over who owns the outputs of a chatbot conversation. That sounds almost funny, until you remember your business runs on those outputs every day. The organizations that handle this well will not be the ones with the strongest opinions about US-China tech policy. Instead, they will be the ones who quietly built a second option before they needed it.

Let’s talk about where your AI vendor risk actually sits. Reply to this post or drop a comment below. I read every one, and this is a conversation worth having before the next advisory drops.

Sources

Pa’lante siempre, mi gente. Cuiden su data como cuidan su cafe por la mañana, con respeto y sin prisa.

Photo credits: featured image by Kirill Sh on Unsplash; in-body image by Tasha Kostyuk on Unsplash.

 

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top