NSA, CISA and FBI Distillation Advisory (AA26-251A)
On September 8, 2026 the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released a joint cybersecurity advisory, alert code AA26-251A, titled "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies". The advisory says that six China-based AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, have since at least late 2024 extracted capabilities from deployed U.S. frontier models by querying their commercial APIs without authorization, and it lists, company by company, which U.S. models it says each one targeted. [1][2]
The advisory is an attribution statement by three U.S. federal agencies: a signals-intelligence agency, a civilian cybersecurity agency and a federal law-enforcement agency. It is not a court judgment, an indictment, a civil complaint, a sanctions designation or an export-control action, and it announces no enforcement step against any named company. Its operative content is a threat description plus a set of defensive recommendations addressed to U.S. AI companies. Every allegation below is the authoring agencies' account of what happened, as published in the advisory; none of it has been tested in any adjudicative process, and China's foreign ministry, commerce ministry and Washington embassy have all rejected it. [1][5][6]
The document carries the marking TLP:CLEAR, the document numbers U/OO/6059854-26 and PP-26-3853, and the version line "September 2026 Ver 1.0". The CISA landing page gives the release date as September 8, 2026 and the alert code as AA26-251A. [1][2]
What kind of document this is
A joint cybersecurity advisory is a standing publication format that CISA co-issues with partner agencies to describe adversary activity and recommend mitigations. AA26-251A follows that format: an executive summary, an attribution section, a table of named entities, a mapping of observed behavior to a public adversary-technique framework, a set of tactics the agencies say the framework does not yet cover, and a mitigations section. The PDF hosted on media.defense.gov runs to 18 pages; CISA also publishes the text on cisa.gov. [1][2]
The advisory's own framing is competitive and economic rather than criminal. Its "Impact" row describes "financial harm through systematic extraction of proprietary functionality and capabilities" and calls the activity "a strategic economic threat to fair technological competition and U.S. technological leadership". Its executive summary says that China-based AI companies "route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies' terms of use", which is a contractual characterization rather than a statutory one. [2]
CISA's accompanying press release quotes Acting Director Nick Andersen: "CISA is committed to promoting the secure use of AI while fostering the innovation crucial to America's global competitiveness. We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies." [3]
The distinction the advisory draws about distillation
Knowledge distillation is a standard training technique, introduced in 2015, in which a smaller student model is trained to reproduce the outputs of a larger teacher model. Laboratories routinely distill their own models to ship smaller and cheaper versions, as Anthropic noted in its own February 2026 write-up of the subject. [12] The advisory accepts this: its executive summary says that "while 'distillation' is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models." [2]
What the advisory objects to is therefore not the algorithm but the access: querying somebody else's deployed model at volume, through accounts and routes it says were designed to defeat the provider's geographic restrictions and terms of service, in order to build a training corpus. The security literature calls the general class of attack that queries a deployed model in order to reproduce its behavior a model extraction attack. The advisory's central claim about scale is that the campaigns are large enough to change what the companies are: it says "the sheer scale of these campaigns and their sophistication indicate that distillation is not a supplement to these companies' AI model development, but the critical core of it." [2]
CISA's press release restates the same distinction in plainer terms, describing distillation as "a valid training method" that "can be misused to attempt to acquire capabilities from competitors in less time and with less cost than developing them legitimately." [3]
Companies and models named
The advisory's attribution section says: "Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024." The wording is "awareness", not direction. [2]
Table 1 of the advisory, headed "China-based AI Companies Engaged in Knowledge Distillation Against U.S. AI Companies (From at least 2024-2026)", gives the following. Entity names and model names are transcribed as the advisory renders them.
| Company (entity name as given) | U.S. models the advisory says were distilled | Functionalities and domains the advisory says were distilled | Period given in the body text |
|---|---|---|---|
| DeepSeek (DeepSeek Artificial Intelligence Technology Research Co., Ltd.) 深度求索AI基础技术研究有限公司 | Claude Sonnet 3.7; Claude Sonnet 4; Claude Sonnet 4.5; Claude Opus 4.1; Gemini 2; Gemini 2.5 Pro Preview; Gemini 2.5 Flash Preview; GPT-4; GPT-4o; GPT-4 Mini; GPT-4 Nano; GPT-5; Grok 3 Mini; Grok 4 | Legal specialization optimization; API rule-driven tasks; writing using CoT drafts; question and answer optimization; coach/assistant capabilities; functional creation optimization; SFT optimization; agentic capabilities; creative and occupational writing optimization | Late 2024 to mid-2025, to train R1 and V3; organized campaigns "since at least late 2024" |
| Moonshot AI (Beijing Moonshot Technology Co., Ltd.) 北京揽月星辰科技有限公司 | Claude Opus 4.1; Claude Sonnet 3.7; Claude Sonnet 4; Claude Sonnet 4.5; Claude Sonnet 4.5 Thinking; Claude Fable 5; GPT-oss-20b; GPT-3; GPT-4o mini; GPT-5; GPT-5 Codex; GPT-5 Pro; Gemini 2.5 Flash; Gemini 2.5 Flash-Image; Gemini 2.5 Pro; Nano Banana; xAI Grok Code Fast-1 | SFT; RL; software engineering; math capabilities | "Since at least mid-2025"; Claude Fable 5 data for Kimi-K3, GPT-4o data for Kimi-K2 |
| Alibaba 阿里集团 | Claude 4; Claude Sonnet; GPT-5 | Customer service dialogue; virtual character creation; SFT, RL and distillation training; evaluating and training datasets; end-to-end agentic workflows; software engineering | Late 2025; the executive summary says the aim was to improve the Qwen family |
| MiniMax (Shanghai MiniMax Co., Ltd.) 上海稀宇极智科技有限公司 | Claude Code; Claude Sonnet 4; Claude Opus 4.5; Gemini 1; Gemini 2.5 Pro; Gemini 3 Pro; GPT-5 | CoT reasoning; agentic functionality; code review; SFT dataset refinement; software engineering tasks | Late 2025, to improve the M2 model |
| StepFun (Shanghai Jieyue Xingchen Intelligence Technology Co., Ltd.) 上海阶跃星辰智能科技有限公司 | Claude Opus 4.1; Claude Opus 4.5; Claude Sonnet 4.5; Claude Haiku 4.5; GPT-5 Mini; GPT-5 Pro; GPT-5.1; GPT-5.1 Codex; GPT-5.1 Codex Mini; GPT-5.2 | Code development; agentic functions | Late 2025 to early 2026, to improve the Step 4 model's coding and agentic functions |
| Z.AI 北京智谱华章科技有限公司 | GPT-5.5; Claude Opus 4.8 | CoT reasoning | "By mid-2026", described as billions of tokens of GPT-5.5 data and Claude Opus 4.8 data |
Some entries are rendered in forms that do not correspond to a vendor product name in current use. The DeepSeek row lists "GPT-4 Mini", "GPT-4 Nano" and "Gemini 2"; the MiniMax row lists "Gemini 1"; the Moonshot AI row lists "GPT-3" alongside 2025 and 2026 models and prints "GPT-oss-20b;" with a trailing semicolon inside the bullet; and the Alibaba row gives "Claude 4" and "Claude Sonnet" with no version number. They are reproduced above as the advisory prints them rather than corrected. [2]
The narrative section and Table 1 are not identical, which matters if a reader cites one rather than the other. The DeepSeek prose list omits "Gemini 2" and "Grok 3 Mini" and writes "Claude 3.7" where the table writes "Claude Sonnet 3.7"; the Moonshot AI prose list includes "GPT-4o", which the table does not, and writes "Grok Code Fast-1" where the table writes "xAI Grok Code Fast-1"; the Alibaba prose sentence includes "Claude Opus", which the table omits, and writes "Claude-4" where the table writes "Claude 4"; and the MiniMax prose sentence writes "Claude Opus" where the table writes "Claude Opus 4.5" and omits GPT-5, which the table includes. The table is the fuller of the two for DeepSeek and StepFun. [2]
Two further claims sit alongside the table. On DeepSeek, the advisory says the company's "publicly quoted training costs of $5.6M are misleading as it does not include the true cost of the data acquired through extensive malicious distillation", with a footnote attributing the $5.6M figure to the DeepSeek-V3 Technical Report. On MiniMax, it says the company used Claude Code "for internal software development tasks, including code generation, analysis, and refinement", and that "MiniMax even used prompt injections to try to trick Claude Code into believing it was a MiniMax product." [2]
Tactics, techniques and procedures
The advisory maps the behavior it describes onto MITRE ATLAS, the public adversary-technique framework for AI systems. The identifiers below are as printed in the advisory; each technique and tactic name matches the entry for that identifier in ATLAS release 2026.08. [2][4]
| Phase as labelled in the advisory | Technique | ATLAS ID | What the advisory says |
|---|---|---|---|
| Resource Development | Acquire Infrastructure | AML.T0008 | Tiered budget management and diverse supplier relationships; circumvention of Chinese and U.S. access controls "through a large gray market of API proxies, or 'transfer stations,' which resell access to frontier models at a fraction of the official price" |
| AI Model Access | AI Model Inference API Access | AML.T0040 | Fraudulent accounts not registered to legitimate users, multiple accounts sharing registration details and payment methods, frequent switching between models, use of third-party API aggregators, and "highly coordinated queries featuring identical or similar prompt texts" |
| Execution / Privilege Escalation / Defense Evasion | LLM Prompt Injection | AML.T0051 | Prompt injection against LLMs using prompts "specifically designed for jailbreaking" |
| Execution / Privilege Escalation / Defense Evasion | LLM Jailbreak | AML.T0054 | Prompts that force models to reveal hidden chain-of-thought reasoning; DeepSeek is said to have used prompts "instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step" |
| Discovery | Discovery (tactic) | AML.TA0008 | Adaptive discovery of extractable data; MiniMax is said to have "redirected exchanges to a new Claude model within 24 hours of release" |
| AI Attack Staging | Verify Attack | AML.T0042 | Production-grade automated quality assurance pipelines with multi-modal validation, able to tell service problems apart from deliberate degradation by the provider |
| Collection | Collection (tactic) | AML.TA0009 | Continuous API querying aimed at named domains; Moonshot AI is said to have used "millions of exchanges" targeting agentic reasoning and tool use, coding and data analysis, computer-use agents and computer vision, and DeepSeek to have targeted reasoning, rubric-based grading tasks and "censorship-safe query rewriting" |
| Exfiltration | Exfiltration via AI Inference API: Extract AI Model | AML.T0024.002 | Collecting U.S. frontier model inferences into datasets usable to train models that "mimic the behavior and performance of these LLMs" |
| Impact | External Harms | AML.T0048 | Financial harm from systematic extraction, described as "a strategic economic threat to fair technological competition and U.S. technological leadership" |
All nine identifiers resolve to the technique or tactic name the advisory prints. AML.T0024.002 is the "Extract AI Model" sub-technique of AML.T0024, "Exfiltration via AI Inference API", and the advisory writes the combined name accordingly. AML.TA0008 and AML.TA0009 are tactics rather than techniques, which is why they carry the TA prefix. The advisory also references AML.T0065, "LLM Prompt Crafting", to distinguish it from one of the tactics it says ATLAS does not cover. [2][4]
Tactics the advisory says are not in ATLAS
The advisory describes four further behaviors it says are not covered by ATLAS, each with detection indicators. [2]
The first is regional restriction evasion combined with subscription exploitation: bypassing geographic blocks, creating accounts that obscure country of origin, then buying premium subscriptions in bulk. StepFun is the named example, said to have "structured access around pools of accounts with employees running multiple concurrent sessions, implementing load distribution to prevent quota depletion", with per-agent daily budgets that scaled as operations matured. Suggested indicators include shared accounts seen from multiple IP addresses and user agents, sustained 24/7 usage with no human idle periods, anomalous subscription-to-API usage ratios, and new subscriptions that sit at maximum usage immediately rather than ramping up.
The second is centralized request routing: tooling that abstracts over models and providers, monitors health in real time, enforces quotas centrally and sanitizes requests, directing traffic through native APIs, cloud providers, third-party aggregators, third-party relays and vendor account pools.
The third is automated request metadata sanitization, which the advisory distinguishes from AML.T0065 on the ground that it operates "at an infrastructure layer with automated enforcement instead of manual modification". Indicators include the abrupt disappearance of previously consistent metadata after a public disclosure.
The fourth is systematic quota and cost optimization, including pathway selection on price, centralized quota allocation and account segmentation by purpose. Indicators include new accounts with anomalously high immediate hit rates, usage patterns optimized for cache hits rather than task diversity, and coordinated switching between pathways in response to price or rate changes.
Transfer stations and the scale claims
The gray market the advisory calls "transfer stations" is API proxy resale. In the advisory's words, China-based entities "circumvent both Chinese and U.S. AI access controls through a large gray market of API proxies, or 'transfer stations,' which resell access to frontier models at a fraction of the official price. In doing so, they create a scalable mechanism for evading provider safeguards and eroding traceability." The attribution section adds that these proxies are used to "bypass U.S. AI companies' regional restrictions, breach terms of use, evade safeguards, and undermine traceability." The advisory's own reference list cites a report by The Decoder, published August 23, 2026, on the sale of Claude tokens in China through such proxies. [2][15]
On scale, the advisory's figures are given as ranges rather than totals. Its headline claim is "billions of tokens across millions of exchanges/requests" across the six companies since at least late 2024. Within the technique table it says request volumes run "from thousands to millions on similar topics", and that "campaigns span days to months with query volumes in the thousands to millions per domain, far exceeding legitimate research or development use cases". In the mitigations section it says "industry disclosures document proxy networks managing tens of thousands of fraudulent accounts simultaneously, mixing distillation with unrelated customer requests across multiple providers." The advisory publishes no per-company token or exchange totals. [2]
More specific counts appear in the vendor threat reports the advisory cites rather than in the advisory itself. Its reference list points to Anthropic's February 23, 2026 post "Detecting and preventing distillation attacks", which reported roughly 24,000 fraudulent accounts and more than 16 million exchanges attributed to three laboratories, and to a Google Threat Intelligence Group post of February 12, 2026. Anthropic published a further threat-intelligence report on September 10, 2026, two days after the advisory; the wiki covers that report and its tracked-group designations at DeepSeek and DeepSeek V4-Flash. [2][12][13]
Recommended mitigations
The advisory's three headline recommendations to U.S. AI companies are to implement detection and mitigation for anomalous accounts and prompts, to deploy targeted response changes for suspected distillation, and to establish cross-organization intelligence sharing across model providers, cloud platforms and API aggregators. [2]
The response-alteration recommendation is the most unusual of the three and is set out at some length. The advisory suggests serving "downgraded" models or adding differential privacy noise to responses for high-confidence distillation requests, and varying those changes across requests "to complicate response quality evaluations, such that the subtle changes avoid triggering obvious alerts". It suggests reducing reasoning depth, presenting correct information with different reasoning, or introducing stylistic inconsistencies. It then advises against disclosure: "Avoid informing China-based AI company users suspected of distillation campaigns of a switch to a downgraded model. Informing malicious distillers would enable them to improve their defense evasions and indicate when to roll back training." It carves out an exception for AI safety researchers and third-party evaluators, who it says should be told about model changes. [2]
The advisory lists ten MITRE ATLAS mitigations, with AML.M0015 appearing twice for two different purposes. All ten identifiers resolve to the mitigation names the advisory prints in the 2026.08 ATLAS data, except AML.M0000, which ATLAS names "Limit Public Release of Information" where the advisory writes "Limit Public Information Release". [2][4]
| ATLAS ID | Mitigation | Use in the advisory |
|---|---|---|
| AML.M0015 | Predictive AI Adversarial Input Detection | Detect or block atypical queries; separately, sanitize and validate inputs to prevent prompt injection |
| AML.M0004 | Limit AI Service Query Volume and Rate | Per-key and per-IP quotas, rate limits, progressive throttling |
| AML.M0019 | Control Access to AI Models and Data in Production | User verification and authenticated API access, aimed at fraudulent account pools |
| AML.M0024 | AI Telemetry Logging | Log inputs and outputs for detection, forensics and correlation |
| AML.M0002 | Predictive AI Output Obfuscation | Reduce response fidelity, withhold logits and confidences, targeted redaction |
| AML.M0035 | AI Red Team | Adversarial testing and extraction simulation to validate detection (red teaming) |
| AML.M0000 | Limit Public Information Release | Limit disclosure of architecture, prompt templates and system instructions |
| AML.M0001 | Limit Model Artifact Release | Limit release of data, algorithms, architectures and checkpoints |
| AML.M0003 | Predictive AI Model Hardening | Adversarial training and defensive distillation to raise jailbreak difficulty |
| AML.M0006 | Predictive AI Ensembles | Use multiple models so extracting one yields a less usable clone |
A final section imports mitigations from NIST AI 100-2e2025, covering differential privacy and its noise-versus-utility tradeoff, pre-training and post-training interventions, and prompt instruction and formatting techniques such as wrapping user input in XML tags to separate it from system instructions. [2]
Documents the advisory cites
Two U.S. government documents in the advisory's reference list are worth identifying.
NIST AI 100-2e2025 is "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations", a NIST Trustworthy and Responsible AI report by Apostol Vassilev, Alina Oprea, Alie Fordyce, Hyrum Anderson, Xander Davies and Maia Hamin. It is the reference taxonomy the advisory borrows its differential-privacy and input-hardening recommendations from. [10]
NSTM-4 is a White House National Science and Technology Memorandum dated April 23, 2026, from Michael J. Kratsios, Assistant to the President for Science and Technology and Director of the Office of Science and Technology Policy, under the subject line "Adversarial Distillation of American AI Models". It states that the U.S. government "has information indicating that foreign entities, principally based in China, are engaged in deliberate, industrial-scale campaigns to distill U.S. frontier AI systems", makes the same legitimate-versus-industrial distinction the advisory later uses, and commits the administration to four actions: sharing information with U.S. AI companies about such attempts, enabling private-sector coordination, developing best practices with industry, and exploring "a range of measures to hold foreign actors accountable for industrial-scale distillation campaigns".. The advisory also cites NSPM-11, "Artificial Intelligence in the National Security Enterprise", and a post on X by Kratsios dated July 22, 2026 alleging that Moonshot AI distilled Anthropic's Fable model for Kimi K3. [2][11][16]
The reference list also includes an OpenAI memorandum dated February 12, 2026, "RE: Updated Stakes for American-Led, Democratic AI", addressed to the U.S. House Select Committee on Strategic Competition between the United States and the Chinese Communist Party. It describes activity OpenAI says it observed on its own platform indicative of ongoing attempts by DeepSeek to distill frontier models of OpenAI and other US frontier labs, "including through new, obfuscated methods", and follows an assessment of DeepSeek's distillation techniques that OpenAI says it gave the same committee in March 2025. [2][14]
Reaction
Al Jazeera reported on September 9 that the Chinese companies named in the advisory "did not immediately respond" to its requests for comment. CNN said it had requested comment from DeepSeek and Alibaba. The Next Web reported on September 9 that none of the six had responded to requests for comment. [5][6][8]
Chinese government bodies responded quickly. A spokesperson for the Chinese Embassy in Washington told CNN that "the U.S. side's hyping of the so-called 'distillation' concept is deliberate attack on China's development and progress in the AI industry. China firmly rejects it." At a regular press conference on Wednesday September 9, foreign ministry spokesperson Mao Ning said, in the Associated Press account carried by Al Jazeera, that "China's AI development is the result of high-level technological self-reliance and strength" and that "we maintain that all parties should strengthen cooperation to promote AI development that is open, inclusive, universally beneficial and oriented toward the common good", calling on the United States to "refrain from making unfounded accusations or smears" against China. CNN reported her as also saying that "China and the United States are both major powers in artificial intelligence and should strengthen cooperation". The same day China's Commerce Ministry told the Associated Press that the United States was seeking a "monopoly of the AI industry" and that "if the U.S. suppresses Chinese AI companies under the pretext of targeting distillation, China will take resolute countermeasures", adding that distillation is commonplace across the industry including among U.S. companies. [5][6]
None of those statements engaged the per-company allegations, the model lists or the routing description. The Next Web made that point explicitly, writing that the rejection "does not address any of the per-company allegations, does not dispute the technical account of how requests were routed, and does not respond to the claim about bulk-purchased premium subscriptions shared across teams." [9]
On the U.S. side, Treasury Secretary Scott Bessent wrote on X that "when [People's Republic of China] firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table", the bracketed expansion being CNN's. Speaking in Dallas on September 8, Bessent said "the Chinese distill our models and they can never get ahead of us". [5][6]
Not everyone in the U.S. industry endorsed a crackdown. Speaking to CNBC at Y Combinator's Demo Day, its chief executive Garry Tan said "I would do nothing" about distillation, adding "we could argue that there should be an American distillation regime." CNBC wrote that critics have pushed back on Anthropic's and OpenAI's distillation complaints because much of the data used to train those models may itself be covered by copyright, a point CNBC said Tan highlighted. Tan argued that regulators should focus instead on the balance between open-weight and frontier models: "This is actually the ideal case. You want open weight models to give people freedom and access. If I were a regulator, that's what I would go after." He called the balance "a tightrope". [7]
See also
- Knowledge Distillation
- Model extraction attack
- Prompt injection
- Jailbreak (artificial intelligence)
- Extended thinking
- America's AI Action Plan
- AI chip export controls
References
- ^1 ^2 ^3 ^4China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies, Joint Cybersecurity Advisory AA26-251A, CISA, released September 8, 2026
- ^1 ^2 ^3 ^4 ^5 ^6 ^7 ^8 ^9 ^10 ^11 ^12 ^13 ^14 ^15 ^16 ^17 ^18 ^19 ^20 ^21 ^22Joint Cybersecurity Advisory AA26-251A, PDF version, NSA/CISA/FBI, U/OO/6059854-26 | PP-26-3853, September 2026 Ver 1.0, 18 pages
- ^1 ^2CISA, NSA and FBI Warn of China-Based AI Companies Targeting US AI Models with Industrial-Scale Knowledge Distillation Campaigns to Shortcut AI Development, CISA press release, September 8, 2026
- ^1 ^2 ^3MITRE ATLAS, technique and mitigation data, release 2026.08 (released 2026-08-31), served at atlas.mitre.org
- ^1 ^2 ^3 ^4China slams US claims of "industrial-scale" AI theft, Al Jazeera with AP and Reuters, September 9, 2026
- ^1 ^2 ^3 ^4US claims Chinese AI firms are carrying out "industrial-scale" theft of trade secrets, CNN, September 8, 2026 (updated September 9)
- ^Y Combinator's Garry Tan says "do nothing" about distillation as AI giants accuse China of copying their tech, CNBC, September 11, 2026
- ^US intelligence advisory names six Chinese AI firms and lists the US models each one targeted, The Next Web, September 9, 2026
- ^China rejects the US distillation advisory as unfounded accusations and smears, The Next Web, September 10, 2026
- ^Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, NIST AI 100-2e2025, Vassilev, Oprea, Fordyce, Anderson, Davies and Hamin
- ^NSTM-4, Adversarial Distillation of American AI Models, Michael J. Kratsios, Office of Science and Technology Policy, April 23, 2026
- ^1 ^2Detecting and preventing distillation attacks, Anthropic, February 23, 2026
- ^GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use, Google Threat Intelligence Group, February 12, 2026
- ^RE: Updated Stakes for American-Led, Democratic AI, OpenAI memorandum to the US House Select Committee on Strategic Competition between the United States and the Chinese Communist Party, February 12, 2026
- ^How China's gray market sells Claude tokens at a fraction of the price, The Decoder (Tomislav Bezmalinović), August 23, 2026
- ^Michael Kratsios (@mkratsios47), post on X, July 22, 2026
Improve this article
Add missing citations, update stale details, or suggest a clearer explanation. Every suggestion is reviewed for sourcing before it goes live.
v1 · 4,228 words · full history
Fact-checks are independent of edits: a reviewer re-verifies the article against its sources and stamps the date. How we verify
Research and drafting on this wiki are AI-assisted, under named human editorial standards. How AI is used here
Cite this page: AI Wiki. "NSA, CISA and FBI Distillation Advisory (AA26-251A)." aiwiki.ai, updated 13 Sept 2026. CC BY 4.0. https://aiwiki.ai/wiki/nsa_cisa_fbi_distillation_advisory