Skip to content

AI Governance

The NSA, CISA, and FBI just told AI vendors to watch how you use your account. Here is what business owners should know before running AI at scale on a shared login.

On September 8, 2026, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI published a joint advisory naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, accusing them of systematically extracting billions of tokens' worth of capability from Claude, GPT, Gemini, and Grok since at least late 2024. That part of the story does not require most businesses to do anything. The part that does: the advisory tells U.S. AI vendors to start watching subscription-to-usage ratios, high throughput from new or team-shared accounts, and to quietly alter responses for any account that looks like it fits the pattern, rather than announcing a block. Several of the exact usage habits described as red flags, a paid seat shared across a team, an automation that runs an account hard from day one, are also ordinary ways small and medium businesses use AI to save money. This post is about what to check before that overlap becomes your problem.

By Fabio Rabelo · Founder, ATLACIS ·

What happened

On September 8, 2026, the NSA, CISA, and FBI released a joint Cybersecurity Advisory, AA26-251A, accusing six China-based AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running "industrial-scale knowledge distillation campaigns" against U.S. frontier AI models since at least late 2024. Distillation, training a smaller or cheaper model to imitate a larger one's outputs, is a legitimate, widely used research technique. The advisory's claim is that these companies went well beyond that: extracting reasoning patterns, coding ability, and specialized skills from named versions of Claude, GPT, Gemini, and Grok at a volume and with an evasion toolkit the agencies describe as systematic, not incidental. The advisory names specific techniques, routing requests through native APIs, cloud providers, and third-party aggregators that obfuscate user identity, using a gray market of proxies it calls "transfer stations" to get around geographic and account restrictions, and buying premium subscriptions in bulk to share across teams of developers. It states directly that DeepSeek's widely cited $5.6 million training cost for its R1 model "is misleading" because it excludes the cost of the data obtained this way. The advisory then does something less reported but more useful for a business owner: it tells U.S. AI companies what to do about it. Three recommendations. First, detect anomalous accounts by monitoring subscription-to-usage ratios, unusually high usage from brand-new accounts, and enterprise-scale request volume. Second, for accounts suspected of malicious distillation, "subtly alter responses" to reduce the value of what is extracted, rather than simply blocking the account outright. Third, share intelligence on suspicious activity across model providers, cloud platforms, and API resellers. None of the six named companies had issued a public response as of this advisory's release, and a spokesperson for China's embassy in Washington did not immediately reply to a request for comment.

Why it matters for business owners

Almost no small or medium business is running a covert distillation operation against a frontier AI lab. That is not the reason to read past the headline. The reason is that the advisory's recommended defense is built around usage patterns, not intent, because intent is not something a vendor's automated system can see. "A team shares one paid account" and "an automation runs a new account hard from the first day" are both named, almost verbatim, as detection signals in the advisory, and they are also completely ordinary ways businesses use AI tools to control cost: one $20 to $200 monthly seat split across five employees, or a new agentic workflow that starts running requests at volume as soon as it is switched on. That overlap does not make an ordinary business a target. It does mean that as vendors build out the detection systems this advisory asks for, the traffic those systems are watching for will sometimes look statistically similar to how a cost-conscious small business already operates. And the advisory's second recommendation, quietly altering output for a flagged account instead of blocking it outright, is specifically designed not to announce itself. A business that never hears "your account was flagged" has no obvious way to know whether an unexplained dip in AI output quality is a model issue, a prompt issue, or something else entirely.

What owners should not misunderstand

This advisory is not evidence that any specific business account has been flagged, throttled, or degraded. Nothing in the advisory, or in the reporting confirming it, states that ordinary customer accounts have been caught up in this. It is a warning about attribution risk and a set of new incentives for vendors, not a report of harm to small business customers. Treat it as a reason to check how your AI access is set up, not as a reason to panic about anything already in place. It is also not, by itself, a reason to stop using any Chinese AI model your business may already rely on for cost reasons, such as DeepSeek or Alibaba's Qwen. This advisory is about how those companies allegedly built their models, not new evidence about how safe or capable they are to use today. That is a separate decision, covered in an earlier post on China's own restrictions on model access, and it depends on your data handling needs and workflow fit, not on this specific advisory. Finally, do not read the "subtly alter responses" recommendation as proof that any AI vendor is currently doing this to your account, or as proof that it never happens. The advisory recommends it as a defense; whether and how any specific vendor implements it, and against whom, is not disclosed, which is itself part of the point: a business has limited visibility into how its own account looks from the vendor's side.

The operational lesson

The advisory hands every major AI vendor a government-endorsed reason to tighten account-level anomaly detection, and it names the exact patterns those systems will be watching for: usage relative to a single subscription, throughput from new accounts, and enterprise-scale request volume with unclear attribution. Whatever a business's reason for that kind of usage, cost savings, an early-stage automation project, a shared team login, it is worth knowing that the pattern itself, not the intent behind it, is what a detection system evaluates first. The practical shift is toward clear attribution. An AI account tied to a named business, billed on a company card, ideally through a proper API relationship rather than a shared consumer login, gives a vendor an obvious, low-friction explanation for high or fast-scaling usage, and gives the business a real support channel if something does go wrong. A personal ChatGPT Plus or Claude Pro account shared by five people running an automation gives a vendor neither. This was already reasonable practice for account hygiene and audit purposes. The advisory is a new, concrete reason it now also matters for output reliability.

What a serious business should do next

Do not change AI vendors, cancel a subscription, or slow down an automation project because of this advisory. Nothing here indicates ordinary business accounts are being targeted, and the story is fundamentally about six specific companies and a U.S.-China dispute, not about your account. Do take twenty minutes to audit how your business's AI accounts are actually provisioned: how many people share each login, whether high-volume or agentic use runs through a personal plan or a proper business or API account, and whether anyone could explain, if asked, what a spike in usage on any given account was for. If a workflow has grown from occasional use into something that runs constantly or at real scale, that is a reasonable trigger to move it onto a dedicated business or API account rather than leaving it on a shared consumer seat. Do keep this in mind the next time AI output quality seems to degrade for no clear reason. It is far more often a model update, a prompt issue, or normal variability than anything related to this advisory. But knowing that vendors are now being told to quietly adjust responses for accounts that look anomalous is a useful, if uncomfortable, addition to how you troubleshoot that complaint, and a reason to keep account usage clean enough that it is never the explanation.

The Atlacis view

Atlacis takes no position on whether the six companies named in this advisory did what the NSA, CISA, and FBI allege. That dispute will play out between governments and the companies involved, not in how a medium-size business sets up its AI accounts. What is useful here does not depend on how that dispute resolves. A government advisory just made account-level usage patterns, not just model choice or vendor reputation, part of how AI access risk actually works, and that is a new line item in vendor evaluation that most businesses have never had reason to think about before. Atlacis helps owners look past which model or chatbot they picked and examine how AI access is actually structured across the business: who has a login, what runs on it, whether usage matches the account type it runs on, and whether that setup would hold up to a closer look from a vendor, a security review, or simply a bad week where output quality drops and no one can say why.

The short version

  • On September 8, 2026, the NSA, CISA, and FBI named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI in a joint advisory accusing them of industrial-scale distillation of Claude, GPT, Gemini, and Grok models since at least late 2024.
  • The advisory tells U.S. AI vendors to monitor subscription-to-usage ratios, high usage from new or team-shared accounts, and to quietly alter output for suspected accounts rather than announce a block.
  • Several of the named detection signals, a paid seat shared across a team, an automation that runs an account hard from day one, are also ordinary ways small and medium businesses use AI to control cost.
  • This is not evidence that any ordinary business account has been flagged. It is a reason to check how your AI accounts are provisioned before vendor anti-abuse systems built around this advisory become widespread.
  • Move high-volume or agentic AI workloads onto a clearly attributed business or API account rather than a shared consumer login, so usage has an obvious explanation and a real support path if something goes wrong.
Tags:AI governanceAI vendor riskAI securityAI access controlAI accountsbusiness AIAI decision supportvendor dependency
FAQ

Common questions

Does this advisory mean my business's ChatGPT, Claude, or Gemini account could get flagged?
There is no evidence that ordinary business accounts have been targeted. The advisory is aimed at large-scale, cross-account operations tied to six named Chinese companies. It is still a reasonable prompt to check how your own accounts are set up, since the detection signals it describes, shared logins and fast-scaling usage, are common in small businesses for entirely legitimate reasons.
Should my business stop using DeepSeek, Qwen, Kimi, or other Chinese AI models because of this advisory?
Not based on this advisory alone. It describes how these companies allegedly built their models, not new evidence about how safe or capable they are to use today. Whether a Chinese open-weight model fits your business is a separate decision based on data handling, cost, and workflow fit.
What should my business actually check because of this?
Audit how your AI accounts are provisioned: how many people share each login, whether high-volume or automated use runs on a personal plan or a proper business or API account, and whether anyone could explain a usage spike if asked. Move heavy or agentic workloads onto a clearly attributed business account.
Keep reading

More from the blog

The White House says China's most popular new AI model was built by stealing from Anthropic. Here is what business owners should know before adopting a model under an active sanctions threat.

On July 22, 2026, a White House official accused Chinese AI startup Moonshot of covertly distilling Anthropic's Fable model to build Kimi K3, and of using export-restricted Nvidia chips to do it. Treasury Secretary Scott Bessent said sanctions remain on the table. Moonshot denied it, and independent experts told reporters the timeline does not clearly support the claim. Nobody has settled this yet. That uncertainty is itself the business risk.

Anthropic says Alibaba stole Claude's capabilities using 25,000 fake accounts. Here is what business owners should understand about the AI products they buy.

Anthropic accused Alibaba's Qwen AI lab of using roughly 25,000 fraudulent accounts to generate more than 28.8 million interactions with Claude between April and June 2026, with the goal of copying Claude's advanced capabilities into a cheaper competing model. The story surfaced publicly on June 24, 2026, through a letter Anthropic sent to the US Senate Banking Committee. The real business question is not about geopolitics. It is about how to evaluate the AI products you buy when you cannot see what is under the hood.

China is discussing limits on overseas access to its own AI models. Here is what business owners using cheap Chinese AI should know.

Reuters reported on July 7, 2026 that Chinese authorities have held meetings with Alibaba, ByteDance, and Z.ai about restricting overseas access to their most advanced AI models, the same low-cost, high-capability models many businesses have adopted to cut rising AI token costs. Nothing has been decided, and any limits may apply only to future models. Here is what business owners should understand about this new kind of vendor risk before it changes anything about how they use AI.

Make better AI decisions, starting with one call.

Book a free AI Fit Call. We will tell you what to use, what to avoid, and where to start. No jargon, no pressure.