Skip to content

September 9, 2026 · Issue 24 · 4 min read

Six named firms, one advisory, and a recommendation to quietly downgrade some customers' answers

The NSA, CISA and the FBI published joint advisory AA26-251A yesterday, naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as the operators of what the agencies call industrial-scale distillation campaigns against US frontier models. The described method is systematic querying: billions of tokens across millions of exchanges since late 2024, routed through bulk API subscriptions shared across teams, VPNs, obfuscated accounts and gray-market proxy services. Most coverage is treating this as an intellectual property story. For anyone buying model capacity, the part that changes a decision sits in the recommended mitigations.

The advisory asks US providers to answer high-confidence distillation requests with targeted changes rather than outright blocks. It names differential privacy and serving less sophisticated downgraded models as options, and it recommends varying those changes so the modifications avoid triggering obvious alerts. Read that from the buyer's side of the contract. A federal advisory now recommends that model providers serve deliberately degraded output to accounts that trip a detection heuristic, and that the degradation be designed to go unnoticed. Nothing in it requires telling the account holder.

The exposure is that legitimate enterprise traffic and the described tradecraft look alike from the provider's side. Bulk API subscriptions shared across teams is a description of normal procurement. High-volume programmatic querying is what a batch evaluation job looks like. Offshore development and VPN egress are ordinary. Routing through aggregators and resellers is a cost decision plenty of finance teams have already approved. None of that makes a company a distiller. It does mean the false positive population is not empty, and no provider has published what happens to the accounts inside it.

The consequence is measurement. Model selection at enterprise scale rests on benchmarking a provider's output on your own key against your own tasks. If per-account response modification is a recommended control, that benchmark stops being a clean read on the model and becomes a read on the model plus whatever your account's reputation score bought you. Quality regressions already get attributed to prompt drift, version changes and sampling settings. This adds one more possible cause that is invisible by design.

Two questions worth putting in writing to every model vendor this quarter. Does the provider modify responses for accounts flagged as anomalous, and against what criteria. If an account is flagged, is the customer told, and what is the path to appeal. Neither question appears on a standard vendor security questionnaire, because until yesterday there was no public reason to ask.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

The advisory is worth reading for the mitigations rather than the accusations. The accusations confirm what most people assumed. The mitigations describe a control that changes what a purchased model is.

A downgraded response served on purpose, varied to avoid detection, is not a failure mode any procurement process is written to catch. Service credits attach to availability. Nothing in a standard agreement attaches to whether the answers were the good ones. That gap existed before this week and nobody had a reason to look at it.

The token finding is the one with an owner already assigned. Out of a single 7GB stealer dump covering 5,871 machines, Okta counted 555 tokens tied to AI service authentication and 2,937 encrypted OpenAI tokens, with 1,843 tokens across the whole set still unexpired on the day it was released, alongside 24 valid API keys for Gemini, OpenAI, Groq and OpenRouter. Vendors are selling bundled access to Claude, Cursor, ChatGPT and Gemini on Telegram. None of that requires a novel attack. It requires an employee laptop with an infostealer on it and a long-lived session token that nobody scoped or expired.

That puts AI accounts squarely inside the identity program, which is where the budget and the tooling already are. The work is short-lived tokens, device binding, and monitoring for token reuse from a new address. An identity team can do all three. Most have not been asked to, because AI tools were procured as software rather than as accounts holding reusable credentials.

The third item completes an uncomfortable pairing with the first. The advisory describes US frontier models as the asset being extracted. The WeChat research describes those same models as the instrument. Researchers used a mix of open-weight and proprietary US models to find a memory corruption flaw in a VoIP stack, then built a zero-click worm on top of it. Tencent has patched.

Note what moved. Reporting through August put AI at the porting and tooling stage of exploit work, compressing the repetitive part while a skilled human still did the finding. This is the finding. One data point does not make a trend, and vulnerability research has always used automated analysis, so the honest read is narrow: the assisted portion of the work now reaches further up the chain than it did a quarter ago. Patch windows are the thing that gets repriced if that continues.

Three things to establish this quarter. Which model vendors will state in writing whether they modify responses per account. How long an AI service session token lives on a corporate laptop today. And whether your patch cycle assumes an exploit development timeline that still holds.

If none of the three has a name attached, the answer to all of them is the same person, and they do not know it yet.

Also worth knowing