CISA/NSA/FBI: SIX CHINA AI LABS. BEIJING: GROUNDLESS.
AA26-251A names DeepSeek, Moonshot, Alibaba, MiniMax, StepFun, Z.AI. China commerce and MFA deny. Not tips.
Desk file · 10 SEP 2026 · 02:25 GMT

NTH MERIDIAN EXTRA
CYBER DESK — The United States put six China-based artificial-intelligence companies on a joint cybersecurity advisory and named the method: industrial-scale knowledge distillation against U.S. frontier models. Cybersecurity Advisory AA26-251A, released Tuesday, 8 September 2026 by the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI), alleges that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted proprietary functionalities and capabilities from variants of Claude, GPT, Gemini, and Grok. Beijing rejected the frame within a day. China’s Ministry of Commerce called the accusations groundless; the foreign ministry urged Washington to stop what it called unfounded smears. This Extra shelves the advisory’s attribution block and the Chinese denial. It is not a product tip. It does not teach distillation, bypass, or extraction technique.
The authoring agencies’ executive summary is blunt. Distillation, they note, is a recognized research technique. The charge is scale and intent: aggressive, malicious, targeted campaigns that, they say, form the core of the named companies’ development strategy rather than a side experiment. The advisory states that, likely with Chinese government awareness, the six firms extracted billions of tokens across millions of exchanges and requests from U.S. frontier models since at least late 2024. DeepSeek is tied in the text to work supporting R1 and V3; Alibaba to the Qwen family; Moonshot, MiniMax, StepFun, and Z.AI to parallel campaigns. Extra prints those attributions as the agencies wrote them. It does not independently verify the volume figures or reproduce operational detail.
China-based AI companies are engaging in aggressive, malicious and targeted distillation activities at an industrial scale.
Named U.S. model families in the advisory include Anthropic’s Claude line, OpenAI’s GPT line, Google’s Gemini line, and xAI’s Grok. Table material in AA26-251A maps companies to cited model versions and capability domains — reasoning, software engineering, agentic functions, supervised fine-tuning, and related headings. Reuters’ same-day Washington wrap summarized the political clock: the charge lands ahead of a planned leaders’ meeting later in September and an AI-safety dialogue mid-month. Extra does not invent a summit outcome. It files the timing as wires carried it.
China’s reply is the other half of the file. On Wednesday, 9 September, the Ministry of Commerce said the U.S. allegations lacked factual basis and legal grounding, accused Washington of double standards and of interfering in normal commercial activity, and said distillation is a widely used, neutral technical method. Commerce warned that if the United States used a crackdown on distillation as a pretext to contain Chinese AI companies, China would take resolute measures. Straits Times and Reuters both carried that commerce line. At a regular briefing, foreign ministry spokeswoman Mao Ning said the United States should refrain from unfounded accusations and smearing China, credited Chinese AI progress to high-level self-reliance, and said the two major AI powers should strengthen cooperation. Moonshot AI declined to comment when AFP asked, per Straits Times; other named firms were contacted with limited immediate reply. Extra does not speak for the companies.
What this desk will not do is turn the advisory’s tactics section into a field manual. AA26-251A discusses pathways, proxies, account patterns, and detection recommendations addressed to U.S. AI companies — including monitoring anomalous usage, altering responses when distillation is suspected, and sharing indicators across providers. Those pages exist on cisa.gov for defenders. This Extra does not restate operational steps, payload language, or evasion recipes. Readers who need the mitigation list go to the primary advisory. Hobby and product language stay out: no model ranking, no allocation tip, no “how to distill” sidebar.
CLAIM vs CONFIRMED. CONFIRMED as published government and wire text: AA26-251A exists; authoring agencies are CISA, NSA, and FBI; release date 8 September 2026; six named China-based companies; U.S. model families Claude, GPT, Gemini, Grok cited; “industrial-scale” and “malicious” framing is the agencies’; “likely with Chinese government awareness” is the agencies’ phrase; Commerce called accusations groundless and alleged double standards; Mao Ning urged cooperation and rejected smears; Reuters and Straits Times carried the exchange. NOT here: a judicial finding of theft; independent lab-by-lab forensic proof beyond the advisory; any how-to; any stock or product tip. FALSE framing — do not use: “Nth Meridian proves the theft” or buy/sell language on named firms.
VIDEO=no. Nailed down, 10 September 2026, 02:25 GMT. PATH /wire/cisa-nsa-fbi-china-ai-distillation-six-labs. DESK_ID cisa-nsa-fbi-china-ai-distillation-six-labs. Beat WIRE / CYBER EXTRA. Verification: CISA AA26-251A; Reuters Rozen/Vicens 8–9 Sep 2026; Straits Times / AFP 9–10 Sep 2026 — verification only, do not republish. No investment advice. NTH MERIDIAN does not invent advisories, denials, or tips.
DESK_ID cisa-nsa-fbi-china-ai-distillation-six-labs. Verification: CISA/NSA/FBI Cybersecurity Advisory AA26-251A, 8 Sep 2026; Reuters Courtney Rozen & A.J. Vicens; Straits Times / AFP China denial wrap — verification only, do not republish. No investment advice. NTH MERIDIAN does not invent advisories, quotes, or tips.


