The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as the offending firms, stating they targeted models from Anthropic, OpenAI, Google and xAI. DeepSeek and Moonshot AI are identified as the top offenders, distilling multiple Claude, GPT, Gemini and Grok models. Alibaba and StepFun allegedly focused on Claude and GPT models, while Z.AI is accused of targeting GPT-5.5 and Claude Opus 4.8.
AI model distillation is a legitimate technique where a smaller “student” model learns from the outputs of a well-trained model, reducing training costs. However, the advisory describes the Chinese firms’ operations as “industrial-scale distillation” that abused API access to extract knowledge and logic at a fraction of the development cost.
The agencies assess that the scale and sophistication of the operations indicate Chinese government awareness, calling the approach a likely core development strategy for the offending firms. According to the advisory, Chinese companies distributed API requests across fraudulent or shared accounts, cloud services, aggregators and proxy “transfer stations” to bypass geographic restrictions, usage limits and detection. Some prompts attempted to expose restricted chain-of-thought reasoning, and automated systems switched providers when blocked.
The advisory recommends that AI companies improve behavioral and infrastructure-level detection, modify responses when distillation is suspected, and share intelligence about these campaigns. Potential indicators include new accounts immediately reaching maximum usage, continuous activity without normal idle periods, shared accounts accessed from numerous IP addresses, identical prompts across providers, and coordinated switching between access routes.
BleepingComputer has contacted all six Chinese AI firms for comment but has not yet received statements.