The National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation have jointly issued an advisory accusing six Chinese artificial intelligence companies of running industrial-scale campaigns to extract the core capabilities of U.S. frontier AI models, as reported by Security Affairs.
The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as the companies allegedly behind sustained efforts to siphon billions of tokens from American AI systems. The agencies say the operation's objective is to accelerate China's domestic AI development by replicating the advanced capabilities that U.S. firms have spent billions to develop.
A Shift from Vague Warnings to Direct Confrontation
The joint advisory represents a sharp departure from years of generalized alerts Washington has issued about foreign adversaries targeting American AI assets. By attaching specific company names with high-confidence attribution across three agencies—spanning signals intelligence, infrastructure defense, and federal law enforcement—the U.S. government is drawing a clear line: AI intellectual property is now treated as a frontline national security concern.
The escalation arrives at a moment of intensifying U.S.-China competition across the technology sector, from semiconductor export controls to chipmaking equipment restrictions. This advisory extends the conflict into the domain of AI model security, signaling that the next phase of the rivalry may hinge on who controls the capabilities embedded in frontier models.
API Abuse Replaces Traditional Hacking
What makes the alleged campaign notable is its method. Rather than resorting to conventional cyber intrusions or source code theft, the accused firms are said to have systematically exploited legitimate API access, using large volumes of carefully crafted queries to reverse-engineer and reconstruct the underlying capabilities of U.S. models.
This approach creates a dilemma for the AI industry. It occupies a legally ambiguous zone—part competitive intelligence, part intellectual property exfiltration—that existing frameworks were not designed to address. If adversaries can rebuild meaningful model functions simply through output analysis via an API, protections like licensing agreements, rate limiting, and access controls may prove inadequate for safeguarding the next generation of AI systems.
Policy Pressure and Market Risks
The advisory is expected to intensify calls in Washington for tighter restrictions on API access to advanced AI models, potentially extending the logic of chip export controls to software and services. However, any such measures carry substantial trade-offs. Restricting access to U.S. AI platforms risks fragmenting the global market, pushing international customers toward non-U.S. alternatives, and ultimately weakening the commercial position that American AI companies currently hold.
For businesses operating across Asia-Pacific markets, the advisory raises immediate questions about compliance expectations, vendor due diligence, and the shifting regulatory environment surrounding AI services. What was previously considered legitimate competitive development is now, in Washington's framing, a potential national security threat—a distinction companies on both sides of the divide will find increasingly difficult to reconcile.
The Legal and Operational Gap
Several critical questions remain unanswered. There is no established legal precedent that clearly defines where permissible use of a commercial AI API ends and unauthorized capability extraction begins. Operationally, it remains unclear what specific technical or regulatory countermeasures the U.S. intends to deploy, and how those measures will balance security imperatives against the preservation of an open AI ecosystem.
As frontier models emerge as strategic assets on par with critical infrastructure and advanced weaponry, the governance frameworks to protect them are still taking shape. This joint advisory from three of America's most powerful security agencies marks one of the first formal attempts to establish those boundaries—and signals that AI model security will be a defining arena of great-power competition in the years ahead.
美國國家安全局、網絡安全和基礎設施安全局及聯邦調查局聯合發布警告,指控六家中國人工智能公司進行工業級別的行動,以提取美國前沿AI模型的核心能力。
警告點名DeepSeek、月之暗面(Moonshot AI)、阿里巴巴、MiniMax、階躍星辰(StepFun)及智譜AI(Z.AI)為涉嫌持續努力從美國AI系統中抽取數十億令牌的公司。相關機構表示,該行動的目標是透過複製美國公司耗資數十億開發的先進能力,以加速中國國內AI發展。
從模糊警告到直接對抗的轉變
這份聯合警告標誌著與華盛頓多年來對外國對手瞄準美國AI資產所發出的籠統警報的顯著背離。透過在三個機構——涵蓋信號情報、基礎設施防禦及聯邦執法——之間以高可信度歸因附加具體公司名稱,美國政府劃下了一條明確界線:AI知識產權現已被視為前線國家安全議題。
此升級發生在美中技術領域競爭加劇之際,範圍從半導體出口管制延伸至芯片製造設備限制。這項警告將衝突延伸至AI模型安全領域,預示著競爭的下一階段可能取決於誰控制了嵌入前沿模型中的能力。
API濫用取代傳統黑客攻擊
此次被指控行動的特點在於其方法。據稱,相關公司並非訴諸傳統的網絡入侵或源代碼竊取,而是系統性地利用合法的API訪問權限,透過大量精心設計的查詢來逆向工程並重構美國模型的底層能力。
這種做法對AI產業構成兩難。它處於法律上的模糊地帶——部分屬於競爭情報,部分屬於知識產權外洩——而現有框架並非旨在處理此類情況。如果對手僅透過API的輸出分析就能重建有意義的模型功能,那麼授權協議、速率限制和訪問控制等保護措施可能不足以保障下一代AI系統。
政策壓力與市場風險
預計這項警告將會加強華盛頓要求對高級AI模型API訪問實施更嚴格限制的呼聲,可能將芯片出口管制的邏輯延伸至軟件和服務領域。然而,任何此類措施都伴隨著巨大的權衡。限制訪問美國AI平台存在著分化全球市場、推動國際客戶轉向非美國替代方案的風險,並最終削弱美國AI公司目前所持有的商業地位。
對於在亞太市場運作的企業而言,這項警告立即引發了關於合規預期、供應商盡職調查,以及圍繞AI服務不斷變化的監管環境的問題。先前被視為合法的競爭性發展,現在在華盛頓的論述中,成為了潛在的國家安全威脅——這一分界線將使兩邊的企業越來越難以調和。
法律與操作上的缺口
幾個關鍵問題仍未得到解答。目前尚無確立的法律先例明確界定商業AI API的允許使用何時結束,以及何時構成未經授權的能力提取。在操作層面,美國打算具體部署哪些技術或監管對抗措施,以及這些措施將如何平衡安全必要性與維護開放的AI生態系統,仍不清楚。
隨著前沿模型作為與關鍵基礎設施及先進武器同等重要的戰略資產浮現,保護它們的治理框架仍在成形中。這份來自美國三大安全機構的聯合警告,標誌著確立這些界線的首批正式嘗試之一——並預示著AI模型安全將在未來數年成為大國競爭的決定性領域。
