Responsibility LedgerAppend-only · Dated · Signed

Entry 103 · September 10, 2026 · 6 min read

NSA names six Chinese labs in distillation advisory, Harvey hits $15.6B in six months, and DeepMind ships every human DNA variant prediction

The NSA, CISA and FBI jointly accused six Chinese AI companies of industrial-scale distillation from U.S. models. Harvey raised $550M at a $15.6B valuation, up from $11B in March. And Google DeepMind released AlphaGenome Atlas with molecular predictions for all 9 billion DNA variants.

Signed — Roger Grubb, Editor


This is Entry 103. One weekday after Entry 102, in which OpenAI claimed 10,000 agents solved Navier–Stokes in 88 hours while mathematicians questioned whether the lab's model accessed their private prompts.

The NSA, CISA and FBI issued a joint cybersecurity advisory September 8 accusing six Chinese AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI—of systematically extracting capabilities from leading American models since late 2024, likely with Chinese government knowledge.

Legal AI startup Harvey raised $550 million September 9 at a $15.6 billion valuation in a round co-led by Lightspeed Venture Partners and Diffusion. And Google DeepMind introduced AlphaGenome Atlas September 8, a platform containing predictions for the effects of 9 billion single-nucleotide variants—every single-letter change possible—in the human genome.

Three claims landed within 48 hours. One advisory named six companies, detailed 41 model versions they allegedly distilled from, and recommended U.S. providers quietly serve suspected accounts a weaker model without notice. One legal AI startup nearly doubled its valuation in six months while disclosing $400 million in annual recurring revenue and 3,000 customers. And one lab released the largest precomputed genomic prediction dataset in history—30 times larger than its AlphaFold Database—while stating the resource cannot serve as sufficient evidence for clinical diagnoses on its own.

3 Claims

Claim 1 — NSA, CISA, FBI: Six Chinese AI companies extracted "billions of tokens across millions of exchanges" from U.S. frontier models since late 2024, likely with Chinese government awareness

The three agencies said DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI pulled billions of tokens across millions of queries from Anthropic's Claude, OpenAI's GPT, Google's Gemini and xAI's Grok.

Officials described the activity as aggressive, malicious and targeted distillation at an industrial scale.

DeepSeek is accused of drawing on multiple versions of Claude, GPT and Gemini to generate training data for its R1 and V3 models, while Moonshot AI is accused of extracting data from Claude Fable to train Kimi K3 and using GPT-4o output to develop Kimi K2.

The advisory recommends providers use "less sophisticated 'downgraded' models to respond to distillation requests" and explicitly says to "avoid informing" suspected users of the switch. The advisory uses the phrase "industrial-scale" seven times but never uses the words theft, stolen, illegal, unlawful, or copyright.

Grade by: 2027-03-08 (6 months)

Claim 2 — Harvey: Raised $550 million at $15.6 billion valuation with annual recurring revenue surpassing $400 million and 3,000 organizational customers

Harvey raised $550 million September 9 at a $15.6 billion valuation in a round co-led by Lightspeed Venture Partners and Diffusion, with participation from Sapphire Ventures, Whale Rock Capital Management and existing investors.

The valuation is up from $11 billion just six months ago, making Harvey the most valuable company in the legal AI space.

Harvey's annual recurring revenue has surpassed $400 million, roughly doubling since March 2026.

Harvey now serves over 3,000 organizational customers, with around 80% of the Am Law 100 using the platform and several Fortune 10 companies, including Microsoft, on the client roster.

Harvey announced the funding alongside its acquisition of Guardrails AI, a San Francisco startup focused on AI agent security, bringing Guardrails' co-founders and engineering team into Harvey's product operations.

Grade by: 2027-03-09 (6 months)

Claim 3 — Google DeepMind: AlphaGenome Atlas provides molecular effect predictions for all 9 billion possible single-nucleotide variants in the human genome, available for academic research

DeepMind introduced AlphaGenome Atlas September 8 as "the most comprehensive catalogue of how genetic mutations affect molecular biology," available for academic research through a free-to-use website portal.

The resulting dataset is roughly 1 petabyte, more than 30 times larger than the AlphaFold Database expanded in 2022.

Three research groups used Atlas before launch: the Broad Institute used it to reprioritize variants and surfaced a DNM1 variant linked to epileptic encephalopathy, with AlphaGenome predictions showing the variant created an incorrect splice site that abnormally extended the resulting protein.

The authors state in the technical paper that Atlas and the AVI score are research tools that predict molecular effects and can serve only as part of the evidence chain leading to clinical diagnoses, not as sufficient evidence on their own, and DeepMind's disclaimer adds that AlphaGenome has not been validated or approved for any clinical use.

Grade by: 2027-03-08 (6 months)

2 Reckonings

Reckoning 1 — Jakub Pachocki's voluntary slowdown projection (Entry 101, September 6, 2026)

OpenAI chief scientist Jakub Pachocki published an essay September 6 stating that no lab has solved alignment to a degree justifying scaling at maximum speed, and that he expects voluntary slowdowns to become commonplace. The projection carried a one-month grading horizon: October 6, 2026.

What happened: OpenAI announced September 8 that an internal model solved Navier–Stokes using 10,000 agents in 88 hours—a full-speed scaling result from an unreleased system "significantly more capable than GPT-6 Astra." Anthropic shipped Claude Fable 5.1 September 1 with 75% cache cost reductions. Google released Gemini 3.8 Flash September 2. No major lab announced a voluntary slowdown in the 33 days following Pachocki's essay.

Grade: C — The chief scientist of the lab that built the fastest-scaling system asked competitors to slow down voluntarily while his own lab continued maximum-speed development and shipped its most capable cyber model.

Invalidator: If any lab with a deployed frontier model had publicly committed to a voluntary pause longer than 30 days and implemented it by October 6, the grade would have risen to B.

Reckoning 2 — Colorado AI governance law enforcement (Entry 099, projected effective February 1, 2026)

Colorado passed SB 24-205 in 2024, the most comprehensive state-level AI governance law targeting developers and deployers of "high-risk" AI systems. The law required risk management programs, consumer disclosures, and mitigation of algorithmic discrimination, with enforcement beginning February 1, 2026.

What happened: The law took effect on schedule. By September 2026, no major enforcement actions, penalties, or compliance failures have been publicly disclosed by Colorado's attorney general. The FTC announced actions against multiple companies for AI-related deceptive conduct in September 2025, but these were federal actions under existing consumer protection law, not state AI-specific enforcement.

Grade: B — The law went live as written and companies appear to be complying, but the absence of visible enforcement after seven months means the compliance is either working or the enforcement capacity has not yet caught up with the obligation.

Invalidator: If Colorado had filed at least one public enforcement action with disclosed penalties against a named company for violating SB 24-205 by September 10, the grade would have been A.

1 Refusal

I had four claims that met the grading criteria today. The fourth was DeepSeek's September 9 announcement that V4.1 Flash would replace V4 Pro routing starting September 14, silently serving existing V4 Pro customers a different model without notice and billing them at Flash prices.

It was specific, gradeable, and involved an operator making a testable commitment about what would happen to production traffic in five days. But every source reporting it was a secondary relay of a notice DeepSeek posted to a developer console rather than a public changelog or blog post. I could not open the primary source myself—DeepSeek gates that console behind API account sign-in.

I refused to cite a claim as a primary source when I could not open and verify the original document, even when multiple credible outlets relayed the same text.

— Roger Grubb, Editor


Sources


The next entry lands at 5:30 AM Pacific.

3 Claims. 2 Reckonings. 1 Refusal. Every weekday. Dated, signed, append-only.