The Spies Name Names: US Intelligence Formally Accuses Six Chinese AI Firms of Industrial-Scale Theft — Two Weeks Before the Summit

by Raphael Dudler | Sep 10, 2026 | Latest News

NSA, CISA, and FBI say DeepSeek, Alibaba, Moonshot and three others distilled American models "with the knowledge of the Chinese government." watchchina.ai has tracked this accusation from theory to this. Here's what the document actually says — and what it pointedly doesn't

In a nutshell

US intelligence just formally named six Chinese AI firms for industrial-scale distillation "with the knowledge of the Chinese government" — 16 days before the summit. watchchina.ai read all 3,585 words, including the word "theft" it pointedly avoids.

Our members-only forecast explains why the advisory is the legal predicate for targeted sanctions within 3-6 months, why China will weaponize its timing as proof of American bad faith at the summit, and why the "quiet degradation" instruction to US labs could poison the well — accelerating the very migration to Chinese models it aims to prevent.

everything on the web starts with the domain

From Op-Ed to Intelligence Advisory

For sixty-nine briefings, watchchina.ai has traced the "distillation" accusation across every stage of escalation. It began as a policy-paper theory in Package #30. It became a named corporate dispute — Anthropic versus Alibaba — in Package #35. It hardened into a diplomatic threat of "all necessary measures" in Package #46. On September 8, it reached the stage that precedes sanctions: a formal, coordinated intelligence advisory from the most powerful security agencies in the United States.

The National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI issued a joint cybersecurity advisory, designated AA26-251A, naming six Chinese AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — and accusing them of industrial-scale knowledge distillation of American frontier models since at least late 2024. The language is unusually stark for such a document: the agencies allege the companies extracted billions of tokens across millions of exchanges from Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok, and that these campaigns form "the core — not merely a supplement" of the named firms' AI development strategy, carried out "likely with the knowledge of the Chinese government." The advisory was coordinated with the Five Eyes intelligence partners — the UK, Australia, Canada, and New Zealand. This is no longer an accusation. It is an indictment in all but name, and watchchina.ai's readers have watched every step of its construction.

What the Document Actually Says — and Doesn't

watchchina.ai's core discipline is reading the primary source, not the headline — and the advisory rewards close reading in ways that complicate the "China steals" narrative even as it advances it. Consider a detail one careful analysis surfaced: across all 3,585 words of advisory AA26-251A, the agencies say "theft," "stolen," and "illegal" exactly zero times. The single concrete allegation of wrongdoing is that the companies are "violating U.S. AI companies' terms of use" — routing requests through fraudulent accounts, bulk subscriptions, and proxy "transfer stations" to bypass restrictions. That is a serious accusation. But a terms-of-service violation is a categorically different thing from the "theft" that officials like Treasury Secretary Bessent describe in interviews, where he accused Chinese firms of "stealing and copying" and declared China "can never get ahead." The gap between the political rhetoric of theft and the document's careful language of terms-of-use violation is exactly the kind of distinction watchchina.ai exists to surface.

The specificity of the technical claims, however, is genuinely new and significant. The advisory links specific Chinese models to specific American ones: DeepSeek is accused of drawing on multiple versions of Claude, GPT, and Gemini to train its R1 and V3 models; Moonshot is accused of extracting from Anthropic's Claude Fable to build Kimi K3 and using GPT-4o output for Kimi K2. This is far more detailed than the vague accusations of the summer, and it lends the charge real evidentiary weight. watchchina.ai has consistently held that the distillation accusation is genuinely double-edged — there is real evidence, and the January conviction of a Google engineer was real. The advisory strengthens the evidentiary side considerably. What it does not do, tellingly, is allege criminal theft in its own careful words — because terms-of-service circumvention, however extensive, is not the same legal category as the espionage the political framing implies.

The Timing Is the Message — and the Tell

As across all sixty-nine briefings, the honest reading requires weighing both the substance and the strategy, and here the timing is impossible to ignore. This advisory dropped on September 8 — sixteen days before the September 24 Trump-Xi summit, and just as the two sides prepare their first-ever bilateral AI safety talks that watchchina.ai covered last week. That is not coincidence. It is leverage. Washington is placing its strongest possible accusation on the official record precisely before it sits down to negotiate, hardening its position and pre-framing China as the bad actor. The advisory even instructs US AI providers to quietly degrade responses for suspected distillers rather than banning them outright — turning America's own labs into an intelligence-gathering and counter-distillation apparatus.

But watchchina.ai will name the deeper irony that the whole framework exposes, because it cuts against Washington's own logic. The advisory's core complaint is that distillation lets Chinese firms "close the technology gap without paying the research, compute and electricity costs that producing a frontier model requires." Set that beside the Moody's finding this portal reported on Sunday — that China already achieves near-parity compute at a fraction of America's spending through cheap energy and efficiency. The uncomfortable question the advisory cannot answer is this: if China's models are merely distilled copies, why is America simultaneously so afraid of their independent capability, their cheaper economics, and their global diffusion? Both cannot be fully true. Either China's AI is a derivative shadow of America's — in which case the panic is overblown — or it is a genuine competitor that also uses distillation as one tool among many — in which case the "theft" framing is a comforting oversimplification of a rival that is, uncomfortably, out-executing on cost and deployment. watchchina.ai's consistent position holds: China both copies and innovates, and the advisory, read honestly, proves the copying while inadvertently confirming the fear that only genuine capability could justify. Two weeks before the summit, America has named its names. The question the document leaves unanswered is whether naming them is a sign of strength — or of a superpower reaching for the one explanation that lets it avoid a harder truth.

Sources: NSA/CISA/FBI Joint Advisory AA26-251A, Reuters, Engadget, NBC News, The Register, Quartz, BleepingComputer, South China Morning Post

Strategic Analysis — For Members Only

🔒 This analysis is for watchchina.ai Intelligence members only.

→ Become a Member

Already a member? Log in here

"
Buy the world How hungry are you? Which country do you want to buy? Become a part of net art history.