US Agencies Warn Chinese AI Firms of Large‑Scale Model Extraction from U.S. Frontier AI Systems
What Happened — The NSA, CISA, and FBI jointly issued an advisory that six China‑based AI companies (DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI) have been running industrial‑scale knowledge‑distillation campaigns against U.S. frontier models such as Claude, GPT, Gemini, and Grok. The campaigns allegedly sent millions of queries and extracted billions of tokens, including specialized reasoning and coding capabilities, since late 2024.
Why It Matters for Trust & Control Assurance
- This activity tests the third‑party risk management control that requires continuous monitoring of external AI service providers and evidence that model‑access policies are enforced.
- Demonstrating that you have documented oversight, usage‑logging, and contractual safeguards provides defensible audit evidence across frameworks (e.g., NIST AI RMF, ISO 42001).
Who Is Affected – AI platform providers, enterprises that integrate external LLM APIs, and any organization that relies on proprietary model capabilities for critical functions (finance, health, government).
Recommended Actions
- Inventory all external LLM endpoints your organization consumes and map them to a vendor‑risk register.
- Enforce strict API‑usage policies, rate‑limit requests, and capture detailed request/response logs for continuous monitoring.
- Conduct a contractual review to ensure providers include clauses on model‑extraction prohibitions and audit rights.
Technical Notes – The advisory describes “industrial‑scale distillation” that leverages massive query volumes to reconstruct model behavior (chain‑of‑thought reasoning, legal expertise). No specific CVE is cited; the risk stems from misuse of publicly exposed model APIs. Source: Security Affairs