The U.S. Just Accused DeepSeek of Stealing American AI — Here's What Service Businesses Need to Know

The NSA, CISA, and FBI named six Chinese AI companies for industrial-scale model theft. If your service business uses DeepSeek or Alibaba AI tools, read this now.

Ido Cohen · Published 2026-09-09 · AI News

The NSA, CISA, and FBI issued a joint cybersecurity advisory on September 8, 2026, formally accusing six Chinese AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — of systematically stealing capabilities from American AI models at what the agencies called "an industrial scale." If your plumbing company, dental practice, law firm, or real estate office has been using DeepSeek to write marketing copy, answer client emails, or power a chatbot, this is the story you need to understand — not because you did anything wrong, but because the regulatory ground is shifting fast underneath these tools.

What Actually Happened — and Why Three Agencies Issued This Together

This is not a think tank report or a media rumor. Advisory AA26-251A came directly from the National Security Agency, the Cybersecurity and Infrastructure Security Agency (CISA, the nation's cyber defense organization), and the Federal Bureau of Investigation — all three agencies signing one document. That combination is rare and signals that the U.S. government considers this a serious, verified threat, not a speculative concern.

The advisory accuses the six named Chinese companies of using a technique called knowledge distillation — a valid AI training method where a smaller model learns by studying the outputs of a more powerful one — in a way the agencies describe as malicious. Specifically, the advisory says these companies ran automated, high-volume query campaigns against American frontier AI models to harvest training data, then used that data to build their own competing models at a fraction of the legitimate cost.

According to the CISA advisory itself and reporting from Engadget, the NSA, CISA, and FBI found that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted "billions of tokens across millions of exchanges/requests" from American models — including Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok — since at least late 2024, likely with Chinese government awareness.

The advisory also included a detail that made headlines everywhere: DeepSeek's famous $5.6 million training cost figure, which the company used to shock the AI world in early 2025, is misleading because it does not include the cost of data obtained through this distillation activity, according to reporting from The Next Web and technology.org.

Which Companies Are Named and What Are They Accused Of

The advisory is unusually specific. Here is the breakdown, company by company, based on reporting from The Next Web, technology.org, and the CISA advisory itself:

As Nextgov reported, the companies routed these requests through "native APIs, remote cloud providers, and third-party aggregators" that automatically stripped user metadata to avoid detection. According to the advisory, they also used fraudulent accounts, bulk premium subscriptions, and proxy routing services — sometimes called "transfer stations" — to bypass regional restrictions.

What "Distillation" Means in Plain English — and Why It's a Problem

Knowledge distillation, defined simply: you ask a powerful AI a million questions, record all its answers, then use those question-and-answer pairs to train a cheaper model to behave similarly. Done legitimately, between models you own, it is standard practice. Done against a competitor's API without permission, at scale, using fake accounts — it violates those companies' terms of service and, according to the agencies, potentially constitutes IP theft.

The key claim in advisory AA26-251A, per reporting from Quartz and The Register, is that the agencies found distillation "functions as the critical core — not merely a supplement — of these companies' development programs." In other words, the accusation is not that DeepSeek occasionally used some ChatGPT outputs to help train a model. The claim is that these campaigns were the engine of their development strategy.

That distinction matters for you as a service business owner for a practical reason: if these findings hold up and sanctions follow, these tools could face access restrictions in the U.S. market. Treasury Secretary Scott Bessent, according to technology.org's reporting, threatened "sanctions and Entity List designations" against firms found to have distilled American models — language that would effectively make doing business with those companies a compliance issue for American companies.

What's the Sanctions Risk for Service Businesses Using These Tools Right Now

Here is the honest answer: right now, as of September 9, 2026, no sanctions have been imposed on DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, or Z.AI. The advisory is an accusation and a warning, not a legal order.

But the risk trajectory is moving in one direction. According to Quartz and Just Security's reporting, Congress advanced the Deterring American AI Model Theft Act of 2026 (DAAMTA) earlier this year, which would mandate assessments of model extraction attacks and authorize sanctions. Treasury Secretary Bessent reiterated the threat publicly after the advisory dropped. The summit between President Trump and Chinese President Xi Jinping — scheduled for later this month — has AI on the agenda, which means the next few weeks could bring either diplomatic de-escalation or an acceleration of enforcement.

For a plumber, a dentist, or an HVAC company using DeepSeek's free tier to write service descriptions or draft follow-up emails, the practical risk today is not legal liability. The practical risk is tool disruption: if DeepSeek faces U.S. market restrictions, your workflow breaks without warning.

There is also a subtler risk the advisory surfaced for the first time at this scale. The CISA advisory's recommended mitigation for American AI providers is to quietly degrade responses served to suspected distillation accounts — without telling those accounts. As The Daily Brief's technical analysis noted, the indicators the advisory uses are behavioral, not account-specific, meaning a legitimate small business using an AI aggregator or API proxy for cost reasons could theoretically be caught in the same behavioral profile as a bad actor. You have no way to know if the AI responses you're getting are full-quality or quietly degraded. That is not a reason to panic, but it is a reason to use directly-verified American AI providers if reliability matters to you.

Why American AI Providers Are Not Neutral Parties in This Story

It is worth saying plainly: the U.S. government issued this advisory in coordination with intelligence partners in the United Kingdom, Australia, Canada, and New Zealand, per Eastern Herald's reporting. That is a Five Eyes intelligence alliance product — not a domestic press release. The stakes are being taken seriously at the geopolitical level.

At the same time, the companies named as victims — OpenAI, Anthropic, Google, xAI — have competitive interests in having their Chinese rivals designated as bad actors. The advisory's findings should be taken seriously because of who issued it, but the policy response will involve lobbying from companies that benefit financially from restricting access to cheaper Chinese alternatives.

For service businesses, this cuts both ways:

What to Do This Week

You do not need to do anything drastic. You do need to know what tools you're using and have a clear-headed view of the risk. Here is a practical checklist for service business owners:

1. Audit your current AI stack. List every AI tool your business or marketing agency uses. Ask specifically whether any of them are built on or routing to DeepSeek, Qwen (Alibaba), Kimi (Moonshot AI), or MiniMax. Some third-party "white label" AI tools route to these providers without advertising it. Check the product's documentation or ask the vendor directly.

2. Prioritize American-hosted AI for client-facing or sensitive workflows. If you run a law firm, medical practice, or financial advisory, your client confidentiality obligations make this especially urgent. Use ChatGPT, Claude, or Gemini for anything touching client data — not because DeepSeek is definitively proven unsafe, but because the compliance posture is cleaner.

3. Do not use free DeepSeek accounts for business workflows. The advisory's behavioral flagging criteria — high-volume usage, accounts immediately at maximum usage — also describes perfectly normal small business automation patterns. If you're running automated workflows through DeepSeek's API, review those. The degraded-response risk is real even if it's not well-publicized.

4. Watch the Trump-Xi summit coverage for AI sanctions news. According to Reuters, AI is on the agenda. Any announcement of Entity List additions or sanctions affecting the named companies will likely come fast. Set a Google Alert for "DeepSeek sanctions" and "AI Entity List."

5. Brief your marketing agency or AI vendor. Many small business owners outsource their AI-powered marketing to agencies. Those agencies may be using the named tools without disclosing it. Send this post to your agency contact and ask them to confirm which AI models power their tools.

The underlying story here is not that service businesses did something wrong by exploring lower-cost AI options — DeepSeek's interface and pricing have been genuinely compelling. The story is that the U.S. government has now formally and publicly named these tools as national security concerns, and that changes the risk calculation. Getting ahead of it costs you almost nothing.

---

Frequently Asked Questions

Is it illegal for my business to use DeepSeek or Alibaba AI right now?

No. As of September 9, 2026, no sanctions or legal restrictions have been imposed on DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, or Z.AI for American businesses. The advisory is an accusation and a warning from three federal agencies, not a legal order. However, Treasury Secretary Bessent has explicitly threatened sanctions and Entity List designations, so the landscape could change quickly. The practical risk today is tool disruption, not legal liability.

What is "knowledge distillation" and does it affect the AI tools I use as a service business?

Distillation is a legitimate AI training technique where a smaller model learns by studying the outputs of a more powerful one. The accusation in advisory AA26-251A is that six named Chinese companies ran it against American AI providers' APIs at massive scale, using fake accounts and proxy routing, to build their own models without the legitimate research and compute investment. If you are a user of ChatGPT, Claude, or Gemini, distillation does not directly affect your experience — but it may mean the Chinese AI tools you're using were built partly on capabilities extracted from those American models.

Should I stop using DeepSeek for writing my service business marketing copy?

Not necessarily this week, but you should have a migration plan. If your business has client confidentiality obligations — law, medical, finance — move to a clearly American-hosted provider now. For general content creation, the risk today is mainly workflow disruption if restrictions come. The time to migrate is before a sanctions announcement forces an emergency switch, not after.

Could my AI marketing agency be using these flagged tools without telling me?

Yes, this is a real possibility. Many marketing tools and agencies use third-party AI models as the backend without disclosing which model powers the output. Ask your agency directly which AI models and APIs they route content through. Any agency worth working with should be able to answer that question in 24 hours.

What American AI tools should I use instead?

The three most widely deployed and well-documented American AI platforms for service business marketing are OpenAI's ChatGPT (including GPT-4o and the o-series), Anthropic's Claude, and Google's Gemini. All three have explicit terms of service, clear data handling policies, and are subject to U.S. law — which matters both for compliance and for practical reliability if geopolitical restrictions escalate.

---

Sources: