Most of the coverage of Monday’s joint advisory from the NSA, CISA and the FBI stopped at the accusation, which Engadget summarised as industrial-scale campaigns to copy American models: six Chinese AI companies, billions of tokens extracted from variants of Claude, GPT, Gemini and Grok since late 2024. That part is newsworthy and it is also the least interesting thing in the document.
Read the advisory itself, catalogued as AA26-251A, and two things jump out that almost nobody reported. The first is what the agencies recommend American AI companies actually do about it. The second is a word that never appears.
The Remedy Is a Downgrade You Are Not Told About
The advisory does not recommend blocking suspected distillers. It recommends something considerably stranger. Providers are told to vary “changes to responses across requests to complicate response quality evaluations,” with suggested tactics including “reducing reasoning depth, presenting correct information with different reasoning, or stylistic inconsistencies.”
Then comes the line that should have led every story about this:
Avoid informing China-based AI company users suspected of distillation campaigns of a switch to a downgraded model.
The stated logic is sound on its own terms. Telling a distiller you have caught them lets them “improve their defense evasions and indicate when to roll back training.” Fine. But strip the reasoning away and look at the instruction. Three national security agencies are advising private companies to serve a deliberately worse product to a paying customer, and to say nothing.
Note the scope carefully, because it matters: the advisory frames this as applying to suspected China-based AI company users, not to customers generally. The problem is how a provider arrives at suspicion.
The Detection Profile Describes a Normal Agent Fleet
The advisory’s recommended signals are behavioural, not identity-based. Providers are told to monitor “subscription-to-usage ratios, immediate maximum usage from new accounts,” “enterprise-scale throughput patterns,” “shared accounts from multiple IPs/user agents,” and “24/7 sustained usage without human variation/idle periods.”
Now describe a legitimate American company running an automated agent fleet in production. It signs up and goes straight to maximum usage, because the workload was sized before procurement. It runs continuously with no idle periods, because that is what a scheduled pipeline does. It hits enterprise-scale throughput from what may not be a formal enterprise contract. It calls from multiple IPs and user agents, because it runs in more than one region.
Every one of those is on the list. The detection profile does not distinguish a distillation campaign from a well-built automation stack, because at the level of API telemetry the two look substantially alike. Combine a behavioural detector that produces false positives with a remedy that is silent by design, and you get a customer paying full price for degraded reasoning with no notification, no appeal, and no way to detect the switch. Independent researchers reviewing the advisory have already flagged exactly this.
Three Agencies, No Legal Theory
Here is the second thing. Across the substance of the advisory the agencies characterise the conduct as “violating U.S. AI companies’ terms of use,” as a breach of terms of use, and as bypassing geographic restrictions. What they never say is theft. Or stolen, illegal, unlawful, copyright, trade secret, lawsuit, or sanction.
That omission is deliberate and it is the most honest thing in the document. Distillation through a public API is, on current US law, a contract violation. It is not larceny and it is not obviously infringement, because the thing extracted is model behaviour rather than a copyrightable artefact. The agencies plainly know this, which is why they reached for a self-help remedy instead of an enforcement action.
Our position is that this is the wrong trade. If the conduct is serious enough to warrant three agencies, six named companies and a formal advisory, it is serious enough to warrant a legal theory. What the government produced instead is a recommendation that private firms quietly punish customers on suspicion, which places the entire cost of a false positive on a US business that will never know it was accused. That is not a national security programme. It is an outsourcing of enforcement to companies with no obligation of due process and every commercial incentive to err toward suspicion, and the affected party is the one party with no seat at the table.
The advisory does contain one genuinely useful disclosure. The agencies state that DeepSeek’s much-repeated $5.6 million training cost is misleading because it excludes data acquired through distillation. That figure moved markets in early 2025 and reset expectations for what frontier training should cost. If it was never a like-for-like number, that is a material correction, and it belongs in every model of AI capital expenditure that has been built on the premise that cheap training had arrived.
There is a pattern here worth naming. We wrote last week about OpenAI hitting its own critical cyber threshold and having the framework log the event rather than halt it. The governance instruments in this industry keep resolving to observation and quiet adjustment rather than to a decision anyone has to defend. This advisory fits that shape precisely, only now the quiet adjustment lands on customers instead of on a model.
Anyone running production inference against a US frontier model should treat AA26-251A as an operational document rather than a geopolitical one. Ask your provider, in writing, whether it has implemented the response-alteration guidance, what triggers it, and whether you would be told. The advisory’s whole design assumes the answer to the last question is no. It also came from a government that, not three months ago, wanted a 30-day look at frontier models before public release, so the direction of travel on who gets to see inside these systems is not exactly toward the customer.