CISA names six Chinese AI labs in distillation advisory
NSA, CISA and FBI named DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.AI in advisory AA26-251A. If your router sends tokens there, read the list.
Three US agencies just put names on a page. On September 8, 2026, the NSA, CISA and the FBI published joint advisory AA26-251A, which accuses six China-based AI companies of running industrial-scale distillation campaigns against US frontier models. The six are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. If you route any production traffic to a cheap model, there is a decent chance you are routing it to one of them.
What actually happened
Per CISA advisory AA26-251A, the agencies say these companies extracted "billions of tokens across millions of exchanges/requests" from US frontier models, running since at least late 2024 through mid-2026. The advisory's sharpest line is about intent: the campaigns "form the core — not merely a supplement" of how those companies build models.
The tradecraft described is procurement, not hacking. Gray-market API proxies the advisory calls "transfer stations" to get around geographic limits. Prompts written to pull out hidden chain-of-thought reasoning. Automated sanitizing of request metadata at the infrastructure layer. Spending spread across many accounts and suppliers so no single one looks abnormal. The NSA's release frames it as a systematic effort, not opportunistic scraping.
Every mitigation in the advisory points at frontier labs, not at you: watch subscription-to-usage ratios, flag new accounts that hit maximum throughput immediately, alter responses for suspected distillation, share signals across providers. You are not the defender here. You are downstream of the outcome.
Why a distillation advisory matters for your business
Nothing became illegal on September 8. An advisory is not a sanction and not an export control. But it is the paper trail those things get built on, and we wrote in July that the Treasury threat was the early signal. This is the next one, and it arrives with a list.
Look at that list against what you actually run. DeepSeek and Alibaba's Qwen sit behind a large share of the "good enough, 80% cheaper" routing that small teams adopted this year. Moonshot ships Kimi. Z.AI ships GLM, which we covered in August as the cheapest credible multimodal option under MIT. These are not obscure vendors. They are the default answer to "our OpenAI bill is too high."
The practical exposure is not that your inference stops tomorrow. It is a procurement question you will be asked and cannot currently answer: which models touch customer data, under whose terms, hosted where. If a client, an insurer or an acquirer asks that in Q4, "we use a router" is not a response.
Two things fix this and both are cheap now. First, write down the actual routing table — model, provider, endpoint, what data class each one sees. Not the diagram; the config. Second, make sure every model in it has a tested substitute behind the same interface, so a policy change is a config edit and not a sprint. Open weights help here, because a model you host is a model nobody can revoke — but hosting a model whose lab is named in a federal advisory is a different conversation than hosting one that isn't.
Key takeaways
- AA26-251A was published September 8, 2026 by NSA, CISA and the FBI, naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI
- The agencies allege billions of tokens extracted across millions of requests since at least late 2024
- Described tactics are commercial: gray-market proxies, metadata sanitizing, spending spread across accounts and suppliers
- All recommended mitigations target frontier labs — nothing in the advisory asks anything of you
- The real exposure is a procurement answer you owe: which model, which provider, which data class
You should be able to swap a model in an afternoon. We build the routing layer, the fallback, and the written inventory of what runs where — so a policy shift is a config change, not a rebuild. Tell us what you're routing today, or see how we work.
Sources: CISA advisory AA26-251A, NSA press release.
- #ai-policy
- #vendor-risk
- #model-portability
- #cisa
- #open-weights
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Accenture is putting 1,000 engineers inside Gemini clients
Accenture and Google Cloud formed a Gemini Enterprise business group with a 1,000-person forward deployed engineer bench. The tell: agents stall at integration, not the model.
Read itQualcomm–AWS AI chip deal: read the $60B warrant terms
Qualcomm and AWS signed a multi-generation custom silicon deal for AI inference, backed by a warrant that vests against up to $60B in purchases. Here is what it means for your token bill.
Read it