Part of the AI Regulation News hub.
Three US agencies have published a non-binding joint advisory alleging that six named China-based AI companies ran industrial-scale knowledge distillation campaigns against US frontier models, and recommending three defensive actions
Nothing in this document obliges anyone to do anything. Its practical weight is that it writes down, in a government voice and on a dated page, what a frontier model provider is now expected to be watching for.
Bottom line: Non-binding. AA26-251A is a joint cybersecurity advisory. It creates no legal duty, imposes no deadline, opens no proceeding and announces no sanction, designation or export control action, and the agencies state that its information and opinions are provided as is and without any warranties or guarantees.
Who this affects: Trust and safety, abuse detection and security engineering leads at frontier model providers, CISOs and general counsel at AI companies, cloud platform and API aggregator compliance teams, and export control and trade secret counsel advising on model access.
Issue date: Release date 8 September 2026, Alert Code AA26-251A. The advisory is undated internally beyond that header.
What changed: A named federal threat description now exists on the public record, attributing sustained extraction activity to six China-based companies and recommending a specific set of provider-side controls.
Analysis: The recommendations reach further into product design than the mitigations sections of advisories usually do, which is our reading, including a suggestion that providers alter responses to suspected distillation traffic without telling the China-based AI company user they suspect. That is a product decision with its own legal surface, and the advisory does not address it.
Primary sources: Joint Cybersecurity Advisory AA26-251A
- Instrument (EN)
- Joint Cybersecurity Advisory AA26-251A, China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
- Authority
- National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation, jointly
- Jurisdiction
- United States, federal. Addressed to industry, not to a regulated population
- Status
- Published 8 September 2026 on CISA's cybersecurity advisories index
- Bindingness
- Non-binding throughout. The advisory recommends mitigations, and its disclaimer states that the information and opinions are provided as is and without any warranties or guarantees
- Issue date / next deadline
- 8 September 2026. No deadline, comment period or response date is set
- Legal basis
- Stated purpose: developed in furtherance of the authoring agencies' cybersecurity missions, including responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations
- Document
- Alert Code AA26-251A, with MITRE ATLAS mappings and references to NIST AI 100-2e2025
- Primary source
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
Start with what the advisory is, because it is not a rule
AA26-251A is guidance. It binds nobody, and the document says as much about itself in two places. Its purpose statement describes it as developed in furtherance of the authoring agencies' cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. Its disclaimer of endorsement states that the information and opinions contained in the document are provided as is and without any warranties or guarantees.
No deadline appears anywhere in it. No proceeding is opened, no entity is designated, no licence is affected and no penalty is threatened. A company that reads it and does nothing has broken no rule that this document creates.
Everything in the following sections is therefore what the agencies say, not what has been established. We have kept that attribution on the face of every sentence, and we recommend that anyone repeating these claims does the same.
What the agencies say they observed
The executive summary states that China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of US AI companies' models through industrial-scale knowledge distillation campaigns. It separates that from the technique itself, noting that distillation is recognised as a legitimate and useful technique in AI research, and characterising the conduct it describes as aggressive, malicious and targeted distillation at industrial scale.
In the attribution section the agencies name DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, with corporate names given for five of them, and say they have conducted high-volume knowledge distillation campaigns against several US AI companies since at least late 2024. The advisory states this was done likely with the knowledge of the Chinese government. That hedge is the agencies' own word, and we preserve it rather than reporting government direction as established.
The advisory lists specific US models it says were distilled, across Claude, GPT, Gemini and Grok variants, and specific capability targets including chain-of-thought reasoning, agentic functions, software engineering and supervised fine-tuning optimisation. It says the companies route requests through native APIs, cloud providers and third-party aggregators, and use a gray market of API proxies described as transfer stations to bypass regional restrictions. It states that this conduct breaches the US providers' terms of use.
One characterisation is worth reading with care. The advisory says DeepSeek's publicly quoted training costs of 5.6 million dollars are misleading because they do not include the true cost of data acquired through what it calls extensive malicious distillation. That is the agencies' assessment of a published figure, sourced in the advisory's own footnote to the DeepSeek-V3 technical report. It is not a finding by any tribunal, and no court or agency adjudication is cited anywhere in the document.
The three recommended actions, and the one that carries product risk
The agencies recommend that US AI companies take three immediate actions. The first is comprehensive detection and mitigation: detecting anomalous and malicious prompts, accounts, networks and behaviours, and monitoring subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns. The second is targeted response changes. The third is cross-organisation intelligence sharing, correlating activity across model providers, cloud platforms and API aggregators.
The second recommendation is the one that should go past the security team. The advisory recommends subtly altering responses for suspected malicious distillation attempts, and in its implementation strategies suggests reducing reasoning depth, presenting correct information with different reasoning, or introducing stylistic inconsistencies, while varying changes across requests to complicate quality evaluation. It also advises against informing China-based AI company users suspected of distillation campaigns that they have been switched to a downgraded model, while saying that AI safety researchers and third-party evaluators should be informed of model changes.
That is a recommendation to degrade a paid service without notice to the account holder, on a suspicion, and it is being made by agencies that do not administer consumer protection, contract or advertising law. The advisory does not discuss terms of service drafting, false advertising exposure, enterprise service level commitments, or what evidentiary standard a provider should hold before acting on a suspicion. Any provider taking this recommendation should route it through counsel before it reaches a config file. That last sentence is our view, not the advisory's.
Where the practical weight actually lies
A non-binding document can still change what a reasonable provider is expected to know, and that is our reading of this one rather than anything the advisory claims for itself. Three agencies have now published, on a dated page, a list of detection indicators: shared accounts from multiple IPs or user agents, sustained round-the-clock usage without human variation or idle periods, anomalous subscription-to-API usage ratios, and new subscriptions immediately at maximum usage instead of gradual adoption.
The advisory also maps the described conduct to MITRE ATLAS technique identifiers, including AI model inference API access, prompt injection and jailbreak, and exfiltration via AI inference API, and points to mitigation identifiers and to NIST AI 100-2e2025 on adversarial machine learning. That gives a provider a vocabulary and a reference frame that did not previously carry a federal signature.
What follows from that is not a legal duty. It is a documentation problem. If a provider is later asked, in litigation, in a procurement questionnaire or by an insurer, whether it monitored the indicators a joint federal advisory published, the answer will be easier to give if someone wrote it down in September 2026.
What the advisory does not say
It does not find that any law was broken. Breach of terms of use is a contractual characterisation stated by the agencies, not a judicial finding, and the advisory names no statute violated, no enforcement referral and no pending action.
It gives no denominator. The advisory says billions of tokens across millions of exchanges or requests, and query volumes in the thousands to millions per domain, but it does not state total legitimate traffic over the same period, so no share of traffic can be derived from it. We give none.
It does not describe the evidence. The advisory does not say how the described activity was observed, what portion came from provider disclosures as against government collection, or what confidence level attaches to any individual attribution. It lists published industry and press references, including material from Anthropic, Google, OpenAI and a technology news outlet, alongside two White House memoranda. Those are references, not shown workings.
It creates no obligation for cloud providers or API aggregators, although it repeatedly addresses them. The mitigations section speaks of what collaboration across the ecosystem can enable, in the conditional, and stops there.
What we did not verify
What we opened: the advisory page at cisa.gov for alert code AA26-251A, retrieved and read in full as extracted text, roughly 108 kilobytes of HTML, including the executive summary, the attribution section and its two tables, the tactics techniques and procedures section with its MITRE ATLAS mappings, the four novel TTP descriptions, the mitigations section, the references list, and the disclaimer, purpose and contact blocks. The page header carries Release Date September 08, 2026 and Alert Code AA26-251A.
What we did not open: the PDF version of the advisory, the separate CISA press release on the same subject, NIST AI 100-2e2025, the MITRE ATLAS entries for the identifiers cited, the DeepSeek-V3 technical report the cost footnote relies on, the vendor publications listed in the references, and White House memoranda NSPM-11 and NSTM-4. We describe all of those only as the advisory describes them.
What we refuse to claim: we do not state as fact that any named company extracted anything, because the advisory is an allegation by agencies and not an adjudication; every such statement in this piece is attributed. We do not say any company broke any law, because the advisory identifies none. We do not say the Chinese government directed the activity, because the advisory says likely with the knowledge of the government and we keep that hedge. We do not convert the recommendations into obligations, and we do not say any provider is non-compliant with anything. We do not calculate any share of traffic, because the advisory supplies no denominator.
Quotations are reproduced with ASCII punctuation in place of the typographic quotation marks and apostrophes used on the page, which is a house typesetting convention and not a change to any word.
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
Treat this as a published expectations list, not as a rule, because a rule is what it is not. The detection indicators in the advisory are specific enough to audit against in an afternoon: subscription-to-usage ratios, new accounts running at ceiling from day one, shared credentials across IPs and user agents, sustained usage with no idle pattern. Write down what you already monitor and what you do not. Then send the response alteration recommendation to your general counsel before anyone implements it.
Source File
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
Open the advisory and read three parts against each other: the executive summary for the claim and its framing, the four novel TTP blocks for the detection indicators you can actually test, and the disclaimer of endorsement and purpose statements at the foot of the page, which is where the document describes its own status.
The sheer scale of these campaigns and their sophistication indicate that distillation is not a supplement to these companies' AI model development, but the critical core of it. ยท Joint Cybersecurity Advisory AA26-251A, Attribution section, 8 September 2026
FAQ
Does this advisory require AI companies to do anything?
No. AA26-251A is a joint cybersecurity advisory and creates no legal duty, no deadline and no reporting obligation. It recommends three actions and lists mitigations, and its own disclaimer states that the information and opinions are provided as is and without any warranties or guarantees. Nothing in it opens a proceeding or announces a sanction.
Have the named companies been found to have broken the law?
Not by this document. The advisory is an attribution by three agencies, not an adjudication. It states that the described conduct violates US AI companies' terms of use, which is a contractual characterisation by the agencies, and it identifies no statute violated, no enforcement referral and no pending action.
What does the advisory recommend that carries legal risk for a provider?
The second of its three immediate actions. The agencies recommend subtly altering responses to suspected malicious distillation attempts, including reducing reasoning depth or introducing stylistic inconsistencies, and advise against telling China-based AI company users suspected of distillation campaigns that they have been switched to a downgraded model. The advisory does not address the contract, consumer protection or advertising questions that raises.
Can the advisory's numbers be used to size the problem?
No share of traffic can be derived from it. The advisory refers to billions of tokens across millions of exchanges and to query volumes in the thousands to millions per domain, but it gives no figure for total legitimate traffic over the same period, so there is no denominator.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.