The intelligence community just ripped off the mask. A joint advisory from the NSA, CISA, and FBI says several China‑based AI firms ran industrial‑scale campaigns to siphon capabilities from U.S. frontier models. That changes the story from “look at this bargain” to “wait — someone stole the shopping list.”
What the NSA‑CISA‑FBI advisory actually alleges
The agencies say six companies — including DeepSeek and Alibaba — ran automated, large‑volume “distillation” campaigns that pulled billions of tokens and millions of queries from American models like GPT variants, Gemini, Claude, and Grok. The advisory calls these efforts “aggressive, malicious, and targeted” and describes tactics like fake accounts, proxy “transfer stations,” subscription sharing, and clever routing to dodge geo‑blocks and detection. In plain terms: this wasn’t normal research. It was industrial theft of model behavior and reasoning tricks that saved money and shortcut real R&D.
Why the famous $5.6 million “miracle” is now suspect
DeepSeek’s headline number — the oft‑quoted $5.6 million training cost — made headlines because it suggested a cheap route to frontier AI. The advisory pulls that rug out: agencies say those cost claims left out the value of outputs allegedly harvested from U.S. models. So the miracle wasn’t frugality so much as free samples from someone else’s gourmet kitchen. That distinction matters if you care about honest markets and protecting American tech leadership.
National security and diplomatic fallout
This is not just a nerd fight over math. Frontier AI powers military systems, cyber operations, and critical infrastructure tools. The advisory warns that these advances could boost Chinese military and cyber capabilities — even if the firms involved are nominally commercial. And the timing is awkward: the advisory lands ahead of high‑level talks with Beijing, meaning diplomatic handshakes may now smell faintly of finger‑pointing and demands for accountability.
Fixes the U.S. should push — fast and hard
The advisory lists sensible mitigations: better detection of anomalous prompts and accounts, subtle response changes to reduce the value of stolen outputs, and real information sharing among model makers, cloud providers, and API platforms. Those are fine first steps. But they won’t be enough. Congress and the administration should be ready to impose stronger export controls, blacklist bad actors, and force cloud and API firms to tighten identity and routing checks. If we let industrial‑scale copying slide, we’ll keep losing the race for frontier AI.
Industry responsibilities and a closing note
Model providers and cloud operators must stop treating this like a policy paper and start treating it like a crime prevention problem. Detect, throttle, share intel, and if necessary, cut off the abusers. The federal advisory is the wake‑up call — now it’s time for action. We should celebrate innovation, but not when it’s built on the systematic theft of American advances. Call it protectionism if you like; I call it common sense.

