The NSA, CISA and FBI have formally confirmed that named China-based AI firms are running an industrial-scale campaign to extract capability from US frontier models. For UK regulated sectors running AI on-prem or in the cloud, the mitigation playbook now matters as much as the accusation itself.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Resource Development | 0 | 4 |
| Access | 4 | 4 |
| Execution | 8 | 4 |
| Discovery & Staging | 12 | 4 |
| Collection | 16 | 4 |
| Exfiltration & Impact | 20 | 4 |
What the US agencies confirmed
A joint advisory from the NSA, CISA and FBI states that, likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens across millions of exchanges from US frontier AI models — including variants of Claude, GPT, Gemini and Grok — since at least late 2024.
Between late 2024 and mid-2025, DeepSeek is described as having distilled training data and capabilities from Claude, Gemini, GPT-4, GPT-5 and Grok 4 to build its R1 and V3 models, covering API rule-driven tasks, agentic functions, Q&A optimisation, fine-tuning and creative and occupational writing. Moonshot reportedly carried out a comparable exercise, extracting Claude Fable 5 data to improve Kimi-K3 and GPT-4o data to improve Kimi-K2. Similar activity is documented across the other named firms.
Why this is more than a US industry dispute
The agencies frame the impact as financial harm to US developers and a strategic threat to fair technological competition and US technology leadership, rather than a direct attack on enterprise AI users. But the techniques catalogued — regional restriction evasion, subscription exploitation, centralised request routing, automated metadata sanitisation, and systematic quota and cost optimisation — are exactly the kind of abuse patterns that show up in any organisation's API logs, regardless of who is running them.
The tactics are mapped against the MITRE ATLAS framework, tracing the full chain from resource development and access through execution, discovery, staging, collection, exfiltration and impact. UK teams already implementing robust cybersecurity measures around AI should treat this mapping as a ready-made detection reference, not a US-only concern.
On-prem, cloud and hybrid: where the exposure differs
The advisory's mitigation advice is explicitly aimed at the broader ecosystem — cloud providers, API aggregators and infrastructure providers — because distillation abuse routes through shared API surfaces rather than through a single compromised endpoint. That has a direct bearing on the choice between evaluating on-premise, colocation, or cloud compute options for AI workloads: a model served purely on-prem has a narrower, more controllable request surface than one exposed via a shared cloud API tier.
Google threat-intelligence reporting from February 2026 found extraction and distillation attempts occurring via entirely legitimate API access, confirming that this is not solely an infrastructure-compromise problem. Organisations securing cloud AI deployments need behavioural monitoring on top of standard access controls, because the requests themselves can look like normal usage until volume and pattern analysis reveals otherwise.

The mitigation toolkit UK buyers should assess
The agencies' recommendations range from purely defensive controls to more assertive responses. Behavioural detection and monitoring sit alongside a differential privacy approach — adding calibrated noise to model outputs to prevent extraction of training-data membership information, decision boundaries or other signals that could help reconstruct private data. More assertive options include targeted degradation of service against high-confidence malicious requests, which the agencies say can impose real costs on distillation campaigns when attribution is backed by multi-source correlated activity.
For UK buyers, this points towards a layered approach built on zero trust principles for API access and managed detection & response tuned to AI-specific behaviours, rather than treating model access as a solved problem once authentication is in place.
- •Behavioural monitoring for abnormal token volume, request cadence and metadata patterns
- •Differential privacy noise on model outputs to limit training-data reconstruction
- •Cross-provider correlation of activity across cloud platforms and API aggregators
- •Defined response tiers, from throttling to targeted degradation of confirmed abuse
The UK regulatory backdrop
The NCSC updated its adversarial-AI guidance on 8 September 2026, explicitly listing unauthorised distillation and model stealing as a demonstrated attack technique against machine learning systems, framing model extraction as using a target model's outputs to learn confidential information about its operation or training data. That guidance now sits alongside the UK's Cyber Security and Resilience Bill, reported as targeting AI users and operators of critical digital services, managed service providers and datacentre operators rather than the AI vendors themselves.
That distinction matters: obligations are likely to fall on the banks, healthcare providers, utilities and other critical operators actually deploying AI, even where the underlying model is supplied by a third party. Separately, extortion crews have been observed stealing proprietary AI data — model scripts, prompts, source code and secrets — from technology, healthcare, pharmaceutical and media firms across North America and Europe, widening the threat surface beyond pure model extraction and reinforcing why IP-rich regulated sectors are already in scope.
View the data behind this chart
| On-Prem | Cloud | Hybrid | |
|---|---|---|---|
| Data residency | Full control | Vendor-dependent | Mixed control |
| API exposure | Low | High | Moderate |
| Distillation risk | Lower | Higher | Variable |
| Monitoring complexity | Simpler | Multi-vendor | Complex |
| UK regulatory fit | Strong | Needs controls | Needs mapping |
What this means for procurement decisions
For organisations weighing sovereign infrastructure choices, this advisory strengthens the case for considering sovereign AI strategies for the UK where data sensitivity or IP exposure is high, and for building distillation-aware monitoring into any deployment plan rather than treating it as a bolt-on. Teams understanding the nuances of AI infrastructure should factor API governance and cross-provider log correlation into procurement requirements from day one, not after an incident.
- 01SecurityWeek — US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities · 8 September 2026
- 02The Hacker News — US agencies accuse China AI firms of systematic extraction · 8 September 2026
- 03NCSC — Understanding adversarial attacks against machine learning and AI · 8 September 2026
- 04The Register — UK cyber bill targets AI users, not the vendors building it · 2 September 2026
- 05The Register — Extortion crews have their eyes on high-value AI data, Google warns · 8 September 2026
- 06BleepingComputer — Google says hackers are abusing Gemini AI for all attack stages · 1 February 2026
- 07arstechnica.com
- 08theregister.com
