← All Briefings
Briefings


CISA Names Six Chinese AI Firms In Model-Distillation Advisory

CISA advisory AA26-251A, published alongside the Justice Department and intelligence-community statement this week, names six China-based AI firms running what the agencies call industrial-scale distillation against American frontier models since late 2024. The mechanism is not a hack. It is billions of tokens pulled through paid API access, then used to train competing models on the outputs. Dark Reading's framing, "covertly draining," describes a business relationship the vendors themselves billed for. The advisory names OpenAI, Anthropic, Google Gemini and SpaceX's Grok as the source models. No CVE attaches to this. The extraction ran through terms-of-service violations and output logging, not an exploit.

For a Hong Kong or Singapore bank, this lands on model-supply-chain due diligence rather than the AI governance frameworks written for internal agent use. HKMA has no circular addressing frontier-model provenance; SFC's September circulars this week cover virtual asset intermediaries and private-market fund exposure, not AI vendor risk. If a bank's AI red-teaming or vendor-risk process depends on assumptions about a foundation model's training lineage, this advisory is the first government-sourced document stating that lineage is contested at the model layer, not just the data layer.

No vendor an APAC bank runs is implicated here; Anthropic, OpenAI and Google are named as victims, not as parties requiring a patch. The control that matters is API rate-limiting and output-watermarking on the bank's own model access, the same technique used against it now available as a case study for any vendor evaluating outbound token exposure. The advisory changes what "training data provenance" means in a vendor questionnaire. It does not change anything in a SOC.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.