What is AI distillation? Why the NSA, CISA and FBI now treat it as a security threat.

Illustration of a large glowing neural network streaming data into a smaller one in a data center

AI-generated illustration

Key points

  • Distillation means training one model on another model's outputs
  • The technique dates to a 2015 Google paper
  • Three US agencies named six Chinese companies on September 8
  • Anthropic measured about 190 million Claude exchanges

Distillation is a way to teach one AI model by showing it another model's work. A powerful, expensive model answers millions of questions. A smaller or newer model trains on those answers and learns to behave in similar ways, without repeating the original model's full training run.

That's a normal, published technique. The concern is unauthorized distillation at industrial scale: companies using another lab's closed model as a teacher, often through large numbers of accounts and in ways that violate the provider's terms. On September 8, the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation named six China-based companies they say have been doing that since late 2024. Anthropic published a report two days later with its own measurements.

How distillation works

The basic idea comes from a 2015 paper by Geoffrey Hinton, Oriol Vinyals and Jeff Dean at Google, Distilling the Knowledge in a Neural Network. The larger model is the teacher. The smaller model is the student. The student learns by trying to reproduce the teacher's responses.

In the original version, the teacher gave the student more than the correct answer. If the question was an image of a dog, the teacher might rank dog highest, wolf second and fox third. That full ranking, called a soft label, tells the student which wrong answers are close and which are not.

Most modern closed models do not reveal those underlying rankings. But their visible outputs can still teach a student a great deal: written answers, code, and, where a model shows it, its reasoning trace. A model trained on the answer learns the conclusion. A model trained on the visible reasoning can also learn the route used to reach it.

The line between normal practice and industrial scale

Distillation is not inherently illicit, and nobody serious argues that it is. Labs distill their own models constantly, which is where most small, fast, cheap model variants come from. The industry letter Jensen Huang shared in his first post on X, "Open Weights and American AI Leadership," dated July 24, 2026 and now carrying well over 100 signatories, calls it "a widely used technique for model improvement, evaluation, and validation." That letter draws the line itself, separating the technique from "unlawful efforts to extract value from closed models," and argues the second should be met with targeted legal action rather than a ban on the first.

Anthropic chief executive Dario Amodei has been precise about which version he wants stopped, calling for policy action against "industrial-scale distillation operations" while rejecting a blanket ban on open-weight models. His argument for why it matters is that distillation "can bring the Chinese frontier to within a few months of the US frontier."

Not everyone agrees it needs a remedy. Garry Tan, chief executive of Y Combinator, told CNBC he would "do nothing" about distillation, and suggested that "there should be an American distillation regime" instead, with regulators focused on the balance between open-weight and frontier models.

What the government and Anthropic actually found

The joint advisory, catalogued as AA26-251A, names DeepSeek, Moonshot AI, Alibaba (BABA), MiniMax, StepFun and Z.AI. It describes billions of tokens pulled across millions of requests since late 2024, targeting Claude, OpenAI's GPT models, Google's Gemini and xAI's Grok, and says the campaigns were run "likely with Chinese government awareness." Its three recommendations are detection, intelligence sharing between providers, and one stranger instruction: "Subtly alter responses for suspected malicious distillation attempts."

Anthropic's report, published on September 10, is the measured version. It attributes about 190 million Claude exchanges to seven China-based labs. The largest campaign it describes is Alibaba's, which it calls the largest distillation attack it has ever measured: more than 151 million exchanges between May and July 2026, peaking near 3 million a day, spread across more than 3,500 accounts flagged as fraudulent, to produce training material for the Qwen model family.

The Zhipu campaign is the one that shows what reasoning traces are worth. Anthropic logged more than 3.4 million exchanges over 17 days in June and July, and describes the lab rotating 273 accounts to push hundreds of thousands of exchanges through an automated tool that cleaned Claude's reasoning traces for training. Z.AI (2513.HK), the Beijing lab still widely known as Zhipu, announced a $5 billion raise days after the report named it.

For investors the practical read is narrow. Distillation is one reason capability gaps can close faster than capital spending gaps, and why a Chinese lab can field a competitive model without matching the teacher's training budget or compute base. It does not require the student to be as good as the teacher. It only requires the student to be good enough, and cheap.

Frequently asked questions

What is distillation in AI?

Distillation is training one AI model on another model's outputs. A large model, called the teacher, produces answers, and a smaller or newer model, the student, trains on those answers rather than on raw data. The technique comes from a 2015 paper by Geoffrey Hinton, Oriol Vinyals and Jeff Dean at Google titled Distilling the Knowledge in a Neural Network. It lets a much smaller model reproduce a lot of a larger one's behavior at a fraction of the training cost.

Is AI distillation legal?

The technique itself is standard and widely published, and labs routinely distill their own models to produce smaller, cheaper variants. The dispute is about doing it to another company's model at scale and against its terms of service. The July 24, 2026 industry letter Open Weights and American AI Leadership calls distillation a widely used technique for model improvement, evaluation and validation, while separating it from what it calls unlawful efforts to extract value from closed models.

Which Chinese companies were named in the US distillation advisory?

The joint advisory from the NSA, CISA and FBI, catalogued as AA26-251A and released on September 8, 2026, names DeepSeek, Moonshot AI, Alibaba (BABA), MiniMax, StepFun and Z.AI. It says they pulled billions of tokens across millions of requests since late 2024 from Claude, GPT, Gemini and Grok, likely with Chinese government awareness.

How much data did Anthropic say was taken?

Anthropic's threat report, published September 10, 2026, attributes about 190 million Claude exchanges to seven China-based labs. It describes Alibaba's campaign as the largest distillation attack it has ever measured: more than 151 million exchanges between May and July 2026, peaking near 3 million a day across more than 3,500 accounts flagged as fraudulent, to produce training material for the Qwen models. This is general information, not investment advice.

More on BABA

Dennis Singleton
Dennis Singleton

Dennis Singleton has spent years following the markets, but what keeps his attention is how AI is built. He writes about the companies behind the technology, from semiconductor designers and advanced packaging to photonics, memory, networking, and the hardware powering modern AI. His approach starts with filings, earnings, and industry research, then translates the important details into clear, straightforward analysis without unnecessary hype.