All episodes

    Episode 244 · September 10, 2026 · 7:02

    NSA, FBI warn China scraped U.S. AI models—where’s the line?

    The NSA, CISA, and FBI issued a joint advisory on September 8th, naming six China-based AI firms for allegedly extracting billions of tokens from U.S. frontier models like Claude, GPT, Gemini, and Grok via API requests. This signals AI model APIs are now considered strategic infrastructure, potentially leading to increased security controls, higher costs, and altered access for all users.

    Listen to this episode

    Episode breakdown

    What happened

    On September 8th, the NSA, CISA, and FBI released a joint advisory, directly naming six China-based AI companies: DeepSeek, Moonshot AI, Alibaba, Minimax, StepFun, and Zai. These firms are accused of conducting "industrial scale campaigns" to extract billions of tokens across millions of API requests from various U.S. frontier models. These models include variants of Claude, GPT, Gemini, and Grok.

    The advisory highlights that this extraction occurred "through the front door" using APIs and interfaces intended for use, rather than through a traditional breach. The core of the issue is defining the line between heavy usage, scraping, and intrusion when proprietary capabilities are extracted to train rival systems. This process is described as "industrial scale distillation" of proprietary capabilities.

    In response, the agencies recommended practical defenses. These include monitoring anomalous usage and enterprise-scale query throughput, adjusting outputs when distillation attempts are suspected, and establishing cross-organization intelligence sharing. Providers and resellers were also encouraged to check logs for scripted bulk traffic patterns and share indicators back with the agencies.

    Why it matters

    This joint advisory represents a significant shift in how AI model APIs are perceived. They are no longer just helpful tools but are now treated as strategic infrastructure, akin to a power grid. This reclassification inherently brings increased security controls and, consequently, more friction into their use, challenging the previous convenience of access.

    The incident redefines AI security beyond preventing malware. It now explicitly includes preventing competitors from extracting valuable intellectual property from models through heavy, legitimate-appearing usage. This sets a precedent for how model providers may need to defend their core assets and raises questions about intellectual property in the age of API-driven AI.

    For businesses and individual users, this shift implies a potential future of tighter access, more verification steps, and possibly higher prices for AI services. The costs of operating AI models, which power many everyday tools, could rise as providers implement more robust security measures. This directly impacts everything from free writing tools to enterprise-level AI applications, potentially altering reliability and accessibility.

    What to watch next

    • How AI model providers will implement enhanced security measures, such as rate limits or anomaly detection, and the impact on user experience.
    • Whether the definition of "scraping" or "distillation" via APIs will be legally clarified or standardized across jurisdictions.
    • The extent to which costs for AI API access will increase, and how this will affect the development and pricing of AI-powered applications.
    • Changes in data privacy practices, particularly how companies handle AI usage logs and user prompt data, given their newfound sensitivity as "intelligent signals."
    • The emergence of new AI security roles and expertise within organizations as "AI Literate" becomes a necessary skill, paralleling "Internet Literate."

    What this means for you

    Business leaders and operators need to recognize that AI access is likely to become more restricted and potentially more expensive. If your operations rely heavily on external AI APIs for proposals, advertising, translation, or code assistance, stable access can no longer be assumed. Develop backup plans for critical AI-driven workflows to mitigate potential disruptions from stricter access policies or service changes.

    Enhance your organization's data privacy discipline, especially regarding what information is entered into AI systems. Given that AI logs are now considered sensitive "intelligent signals," the use of proprietary, medical, legal, or financial data in external AI tools carries increased risk. Implement policies that guide employees to use placeholders for sensitive information and avoid pasting secrets into systems not fully controlled by your organization.

    Key takeaways

    • U.S. security agencies view AI model APIs as strategic infrastructure.
    • China-based AI firms are accused of industrial-scale token extraction from U.S. frontier models via APIs.
    • This redefines AI security to include protecting intellectual property from competitors via heavy usage.
    • Expect tighter access, potential price increases, and more friction for AI services.
    • Businesses must prioritize data privacy and develop backup plans for AI-dependent workflows.

    FAQ

    What did the NSA, CISA, and FBI warn about regarding AI models?

    The NSA, CISA, and FBI issued a joint advisory on September 8th, cautioning about industrial-scale campaigns by six China-based AI companies. These firms, including DeepSeek, Alibaba, and Minimax, are accused of extracting billions of tokens from U.S. frontier models like Claude, GPT, Gemini, and Grok. This extraction reportedly occurred through legitimate API requests, raising questions about what constitutes acceptable usage versus harmful scraping of proprietary capabilities.

    Which China-based AI companies were named in the advisory?

    The joint advisory from the NSA, CISA, and FBI specifically named six China-based AI companies. These companies are DeepSeek, Moonshot AI, Alibaba, Minimax, StepFun, and Zai. The advisory alleges these firms engaged in extensive campaigns to extract proprietary capabilities from U.S. frontier AI models through millions of API requests.

    How might this advisory impact the cost of using AI services?

    If AI providers begin to treat high-volume usage as a security risk, they may tighten access, which could lead to increased costs. This could manifest as more stringent verification steps for accounts, new usage limits, or direct price increases for API access and token consumption. These higher costs could then trickle down to affect the pricing of AI-powered tools and services that rely on these models, including those used by businesses and individual consumers.

    What are practical defenses recommended against industrial-scale AI model extraction?

    The agencies recommended several practical defenses against the industrial-scale extraction of AI model capabilities. These include monitoring for anomalous usage patterns and enterprise-scale query throughput. Adjusting model outputs in response to suspected distillation attempts is another suggested measure. Furthermore, establishing cross-organization intelligence sharing and encouraging providers to check logs for scripted bulk traffic patterns and share indicators back with the agencies are crucial steps.

    How should businesses adjust their AI usage given these new security concerns?

    Businesses should adopt a more disciplined approach to their AI usage. This includes implementing a strict "AI data diet" where sensitive information is never pasted directly into external AI tools. Instead, use placeholders for proprietary, medical, legal, or financial data. Creating a "safe prompt" template that explicitly states "Do not request private data. Assume placeholders. Ask clarifying questions" can help prevent accidental oversharing and maintain control over sensitive information when interacting with AI systems.

    AI SecurityChina AIGeopolitics

    Share with a friend