Skip to content

Product1 publisher3 min readPublished

Three US agencies advise AI providers to quietly degrade answers for suspected distillers

The NSA, FBI and CISA name six Chinese firms and describe how the traffic was routed, then recommend one mitigation that lands squarely on whoever owns the abuse queue and answers the support ticket.

The Product Desk · Product desk

Photograph accompanying Three US agencies advise AI providers to quietly degrade answers for suspected distillers
Photo: thenextweb.com

What happened

  • A joint advisory from the NSA, the FBI and CISA names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as systematically extracting capabilities from American frontier models since late 2024.
  • Attribution is given firm by firm and model by model, down to Z.AI extracting billions of tokens from GPT-5.5 and Claude Opus by the middle of this year.
  • The advisory sets out how the traffic reached providers: fraudulent accounts, single accounts spread across many addresses, and a grey market of API proxies it calls transfer stations that defeat geographic limits and traceability.
  • Among the recommendations, the agencies suggest providers deploy responses that subtly alter output to suspected distillers without telling them, while informing legitimate researchers.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • cost On TNW's reading of the recommendation, each false positive is a paying customer receiving worse answers and a support agent with nothing to reproduce, which turns into refunds and a lost renewal the security team never sees on its dashboard.
  • constraint The flags the advisory highlights, aggregator routing and cloud egress and one key used from many addresses, also describe how a lot of legitimate procurement reaches an API, so tightening them narrows who can buy access through an intermediary at all.
  • decision Providers now choose between enforcement the customer can see and contest, such as rate limits or key suspension, and a quality penalty nobody is told about; only the first produces a false positive rate anyone can measure.
  • precedent TNW reads the move from policy complaint to three-agency technical advisory with per-model attribution as the form these disputes take shortly before sanctions are discussed, which changes the procurement question for anyone building on those six firms' models.

A ticket that says "answers got noticeably worse this week and nothing changed on our end" is close to unanswerable. There is no log line for it, no reproduction path, and the customer is usually right that they changed nothing. The item the three agencies put in their recommendations section would produce tickets of exactly that shape on purpose, and it is the only recommendation in the document that alters what an end user experiences rather than what a provider logs [15]. It is written for the abuse-detection owner at a frontier lab. It is paid for by whoever answers the ticket.

The detection side is where this gets uncomfortable. Fraudulent account creation is a clean signal. One account used across many addresses, calls arriving through cloud providers and third-party aggregators that strip identifying metadata, automatic failover to a second route when the first is blocked [11][13]: that is also a fair description of a platform team sharing one enterprise key across regions behind a gateway with retry logic. Teams tell themselves the flagged account is a scripted harvester on a rented box. Some share of it will be a mid-market customer whose procurement bought API access through a reseller. The prompt-level tell the advisory describes, a jailbreak that asks a model to imagine and narrate the reasoning behind an answer it has already given, is the rare signal a provider can inspect directly instead of inferring from routing [12].

The load is not spread evenly. Counting the per-firm descriptions, a Claude model appears in five of the six [21]: DeepSeek since late 2024 [5], Moonshot from mid-2025 [6], Alibaba in late 2025 [7], MiniMax attempting prompt injection against Claude Code [8], and Z.AI on Claude Opus [10]. StepFun is the only firm described by capability taken rather than by model targeted [9]. Anthropic had already said publicly that Alibaba ran the largest distillation campaign against Claude [19], and the advisory's framing is that this kind of extraction is "the core, not merely a supplement" of how the six build [3].

The cost argument will travel furthest and is the hardest to act on. The advisory says the widely cited $5.6mn DeepSeek training figure excludes the cost of data acquired through malicious distillation [4], and no revised number is reported alongside it [23]. A buyer comparing a Chinese model's economics against a US provider's list price now knows the denominator is contested without knowing what to put in its place. Liu Chang of the Chinese embassy called the allegations a deliberate attack on China's development in AI, according to Bloomberg, which first reported the advisory, and none of the six companies responded to requests for comment [17][18]. The agencies are careful where it counts least for a product team and most for a diplomat: the campaigns ran "likely with Chinese government awareness", which is awareness and not direction [14].

For anyone who has to decide this on Monday, the forcing function is a sentence, not a matrix. For each enforcement tier, write what you will say to the account that turns out to be clean. "We rate-limited you for eleven days, here is the flag that caused it, and here is how to contest it" is survivable. "We served you quietly worse output for eleven days" is a renewal conversation you lose, and there is no contest because the customer never knew there was anything to contest. Visible tiers also hand you the number the silent one withholds: the share of appeals you reverse, which is a false positive rate measured on live traffic rather than assumed inside a threat model.

What to watch

  • Whether any provider names output alteration as an enforcement tier in its published abuse policy, or leaves it unwritten in the terms.
  • Whether the per-model attribution turns into sanctions or export action against any of the six named firms.
  • Whether providers cut off third-party aggregators and proxy resellers, and what happens to customers who bought access that way.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories