Have you noticed your favourite AI becoming subtly worse? Do its replies feel foggy and confused, or is the data corrupt? Do answers that used to be precise now hedge or omit crucial details? Do tasks that once took a single prompt increasingly require an argument? Is the AI somehow less reliable, less transparent, and harder to trust?
If that has happened to you, the cause need not be a new model, a bad update, or an overloaded system. There is now another possibility: a US Government cybersecurity advisory that tells AI companies how to make their models surreptitiously less useful to certain customers — without informing them.
The Advisory
Advisory AA26-251A was released on 8 September 2026 by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI). Titled ‘China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies’, it claims in apocalyptic language that Chinese companies are extracting knowledge from leading American AI models to train competing systems.
Among several proposed countermeasures, it recommends degrading the output of AI for certain customer profiles — the user unbeknownst.
The advisory was published nine weeks after the Federal Trade Commission, a different arm of the same government, proposed treating precisely that kind of undisclosed output manipulation the advisory recommends as consumer deception.
Not Only Beijing Fits the Profile
The advisory recommends that AI service providers — aside stronger identity checks — profiles suspect users by monitoring request rates and volumes, account usage patterns, and the correlation of behaviour across organisations.
The Government’s indicators of suspicion are as follows:
- Shared accounts from multiple IPs/user agents
- Anomalous subscription-to-API usage ratios
- New subscriptions immediately at maximum usage as opposed to gradual AI adoption
- 24/7 sustained usage without human variation/idle periods
- Usage optimised for cache maximisation versus task diversity
- Coordinated pathway switching responding to pricing/rate changes
The problem: this is a description of many companies running AI agents in production — not only Chinese.
Washington’s Panic over an AI Gap
US Treasury Secretary Scott Bessent said at a press conference earlier this month: “There is no day after tomorrow if China wins at this. Like everything, a trillion-and-a-half-dollar defence budget, the Iron Dome. If they were to pull ahead of us on AI, then nothing else matters”.
One of the fears that haunts Scott Bessent and others in the Trump administration — fear shared by Anthropic CEO Dario Amodei — is that Chinese AI companies have used the paid services of American AI companies to train their own models. This is a phenomenon called ‘distillation’.
According to the advisory, “DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024”.
Two days after the advisory, on 10 September, Anthropic published its own threat intelligence report, putting the total at roughly 200 million exchanges it attributes to seven China-based laboratories. Alibaba alone accounts for more than 151 million of them between May and July 2026, which Anthropic calls the largest distillation campaign it has ever measured. Anthropic also alleges that Moonshot AI and DeepSeek quietly forwarded their own paying customers’ requests to Claude and presented Claude’s answers as their own.
According to South China Morning Post, Beijing does not deny distillation, claims it is ‘neutral’, and says that everyone is doing it — adding: “If the US takes action to contain or suppress Chinese AI companies in the name of combating distillation, China will certainly take resolute measures in response”.
Bad Optics
Nowhere in the US advisory note does it say what criminal statutes these China-associated companies should have violated. The conduct described in the advisory mostly concerns violations of terms of use, such as routing requests through proxies and aggregators.
But terms of use are a contract. Breaching one is not a crime.
In Van Buren v. United States (2021), the Supreme Court held that using access you are entitled to for a purpose the owner dislikes does not exceed authorised access.
Trade secret law protects the things the labs keep secret, such as weights, training methods, and data. Model outputs are sold to anyone who signs up.
The US Copyright Office has consistently held that purely machine-generated material lacks the human authorship copyright requires.
What may look legally more solid lies adjacent: registering accounts under false identities, obscuring payment origin, and circumventing geographic restrictions where export controls apply. The potential crime, then, is not the actual distillation, but the way these Chinese companies may have gone about setting up the accounts with these American AI companies.
Did they use false credentials? Did they actually circumvent geographic restrictions?
The Government Is Going Rogue
Now it gets interesting.
Here is the US Government’s second recommended measure, addressed to American AI companies and aimed at some of their paying customers: “Deploy targeted response changes: Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns”.
The US Government’s recommended defence is not simply to block a suspected distillation operation. It is to make the AI service worse in ways the customer may not be able to detect, while continuing to provide — and charge for — the service.
The advisory argues that correlating activity across several providers allows more confident profiling, and that this justifies response degradation with, in its own words, “lower-to-no legitimate user risk”.
However, this depends on providers sharing infrastructure and behavioural indicators with each other, which carry the risk of customers wrongly flagged by one provider becoming wrongly flagged by all of them at once — with no notification and nothing to appeal against. 18 U.S.C. § 1343 is the wire fraud statute:
Whoever, having devised or intending to devise any scheme or artifice to defraud, or for obtaining money or property by means of false or fraudulent pretenses, representations, or promises, transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, signals, pictures, or sounds for the purpose of executing such scheme or artifice, shall be fined under this title or imprisoned not more than 20 years, or both.
Is the US Government, in attempting to prevent Chinese distillation, in effect asking American AI companies to move in the direction of conduct that could amount to wire fraud?
At this point, some lawyers might even cite 18 U.S.C. § 1349: “Any person who attempts or conspires to commit any offense under this chapter shall be subject to the same penalties as those prescribed for the offense, the commission of which was the object of the attempt or conspiracy”.
Could the US Government itself then be viewed as encouraging or facilitating such potentially fraudulent conduct?
As was mentioned at the beginning of this article, nine weeks before the NSA/CISA/FBI advisory, the Federal Trade Commission proposed a policy statement titled ‘Concerning the Suppression of Accuracy in Artificial Intelligence Systems’, printed in the Federal Register on 7 July at 91 FR 41638. According to the proposal: “the Commission believes AI companies that steer the outputs of their AI systems toward unexpected objectives, and away from the objectives set by or reasonably expected by users, are likely to deceive consumers in violation of section 5 of the FTC Act”.
Here we see two parts of the same bureaucracy proposing opposite things within nine weeks of each other.
Is User Response Degradation Already Happening?
Yes.
In June 2026, Anthropic — one of the four companies whose models are named in the advisory, the others being OpenAI, Google DeepMind, and xAI — released Fable 5 with a safeguard that silently degraded its own output for requests it had flagged as frontier AI development work. There was no fallback and no notice. The behaviour was documented only inside the system card.
Researchers found it, and the backlash was immediate.
By 11 June, the company had reversed course, saying flagged requests would transparently fall back to a less capable model: Claude Opus 4.8.
Anthropic said it had made the wrong trade-off and apologised.
All of this took place three months before the advisory.
In short, the same measure that the NSA, CISA, and the FBI now recommend has already been implemented, found out, failed, and abandoned, leaving the AI company in question under a dark cloud.
And now the FBI wants them to do it again?
And so does Anthropic, it seems.
In an essay on his personal website on 12 September, Anthropic CEO Dario Amodei asked for a “crack down on unauthorized distillation by companies in authoritarian countries”, believing this would “slow China’s progress enough to widen America’s lead significantly over the next 3–5 years — the window when AI becomes geopolitically most important”.
So, the same company that apologised for covert degradation in June is now asking the FBI to mandate it in September?
The FTC has proposed calling that ‘deception’. The wire fraud statute may raise an even more serious question.