Editorial still-life photograph of stacked classified intelligence briefings and manila envelopes beside an orange folder on a warm ivory desk surface

The FBI Says DeepSeek's $5.6M Training Bill Was a Lie

September 10, 2026

Remember when DeepSeek announced it trained a frontier-competitive model for $5.6 million? The number lit up every AI corner of the internet. A Chinese lab, running lean, embarrassing billion-dollar American incumbents on a shoestring budget.

The FBI just called that number a lie.

On September 8, the NSA, CISA, and FBI released a joint advisory naming six Chinese AI companies for running what they called "industrial-scale knowledge distillation campaigns" against American frontier models. DeepSeek topped the list, alongside Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.

The accusation is specific. According to advisory AA26-251A, these companies extracted billions of tokens from Claude, GPT, Gemini, and Grok through millions of automated queries going back to late 2024. They used chain-of-thought reasoning extraction, jailbreak prompts, proxy routing through "transfer stations," fraudulent account creation, and bulk subscription sharing. All to copy the reasoning capabilities that took American labs years and billions of dollars to build.

About that $5.6 million figure: the advisory says it excluded the distillation costs entirely. DeepSeek's R1 and V3 models, the agencies claim, were largely trained on data siphoned from American systems.

This is already happening at scale. Moonshot AI ran a campaign since mid-2025 targeting Claude and GPT to train its Kimi models. Alibaba, MiniMax, StepFun, and Z.AI ran their own operations from late 2025 through early 2026, focused on coding, reasoning, and specialized capabilities.

The agencies recommend that AI providers detect anomalous prompt patterns and quietly degrade responses to suspected distillation accounts rather than blocking them outright. The logic: blocking tells the attacker to switch tactics. Degradation wastes their compute without tipping them off.

What this means if you run a business

If you're picking an AI vendor, this advisory just added a variable you probably weren't thinking about: supply chain integrity.

When you pay for access to Claude or GPT, you're paying for models built on massive R&D investment, safety testing, and alignment work. The distillation described in this advisory copies the outputs but skips the safety engineering. You get a model that can mimic reasoning patterns without the guardrails designed to keep it predictable.

For agencies building AI products for clients, the question gets sharper. If a client asks why you chose a specific model provider, "we know where the training data came from" is now a real answer.

Three things worth thinking about:

1. Audit your model providers. Not just pricing and performance. Ask where the model's capabilities come from. If the answer is vague, that tells you something.

2. Watch for downstream effects. If American AI providers start degrading outputs to suspected distillation accounts, that could create inconsistency in third-party tools built on top of those APIs. If your workflow depends on a tool that routes through multiple model providers, you might see unpredictable quality shifts.

3. Expect pricing pressure to ease. One reason AI API pricing dropped so fast in 2025 was that distilled models undercut the originals. If enforcement actions disrupt those operations, the companies doing the actual R&D may have less reason to race to the bottom on price.

The advisory doesn't name specific enforcement actions yet. It reads more like a public warning than a legal filing. But the specificity of the accusations (naming companies, describing methods, challenging public cost claims) suggests more is coming.

For business owners, the bottom line is simple. The AI model you use has a supply chain, just like anything else you buy. And just like physical supply chains, the cheap option sometimes comes with costs that aren't on the invoice.

— Mark Garza, Laimen AI

Mark Garza

Mark Garza

Mark is an automation and AI growth strategist and the founder of Laimen AI.

LinkedIn logo icon
Back to Blog