Should your business use DeepSeek to cut AI costs? Three US agencies just changed the maths

"Should we use DeepSeek to cut our AI costs?" is a fair question — the price gap against the US frontier models is real, and it has been the single loudest argument in AI procurement for two years. On 8 September the NSA, CISA and the FBI published a joint advisory arguing that part of that gap was manufactured — by copying the models it undercuts. It's worth understanding what the agencies actually claim, because the useful decision for a Melbourne business turns out to rest on something else entirely.

What three US agencies actually alleged

The advisory names six China-based AI companies — DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI — and accuses them of industrial-scale distillation: pushing enormous volumes of queries through US frontier models, then using the answers as training data for their own. Since late 2024, the agencies say, that access ran through APIs, cloud providers, third-party aggregators and a grey market of proxies the advisory calls "transfer stations", with account identities obscured to get around terms of use and geographic restrictions. The agencies assess this happened "likely with Chinese government awareness."

Read it as what it is: an intelligence assessment published by three agencies, not a finding tested in any court. The attribution language is theirs, and none of the six companies has been through a legal process on it.

The line that matters commercially is about money. The advisory says DeepSeek's much-quoted US$5.6 million training cost is "misleading as it does not include the true cost of the data acquired through extensive malicious distillation."

Be precise about that number, though, because it has been misused in both directions. DeepSeek's own V3 technical report put the final training run at 2.788 million H800 GPU-hours, which at an assumed US$2 per GPU-hour comes to US$5.576 million — and the report states in the same breath that this covers the final run only, excluding prior research, architecture experiments and ablations. DeepSeek never claimed that figure was the all-in cost of building a frontier model. The internet rounded it off and built two years of "AI is about to get a hundred times cheaper" commentary on top of it.

Should your business use DeepSeek to cut AI costs?

For most Melbourne SMEs, no — but not for the reason the headlines suggest. The advisory is an allegation about how a competitor was built; it is not a finding that the model is unsafe to run. What should decide it for you is where your prompts go. DeepSeek's consumer app and hosted API send your text to servers in China, under a legal regime that is not Australian. If you would be pasting in client records, pricing, contracts or anything covered by the Privacy Act, that single fact settles the question before cost enters it.

The nuance worth knowing: DeepSeek publishes open weights, so the model can also be run on infrastructure you choose, in a jurisdiction you choose. That is a genuinely different product with the same name — and it is not free, because you are now paying for the GPUs and the person who keeps them running.

Does the Australian government's DeepSeek ban apply to your business?

No. In February 2025 the Secretary of the Department of Home Affairs issued PSPF Direction 001-2025, requiring Australian Government entities to prevent the use or installation of DeepSeek products, applications and web services, and to remove any already installed. It binds government entities — not private companies, not individuals. The reasoning is still worth borrowing: the direction rests on the extent of data collection and the risk of that data being exposed to foreign directions that conflict with Australian law. And if you do work for a government client, check your contract before you switch models, because their obligations often flow to you through it.

What to ask before you switch models

  • What does it cost in context, not per token? On most SME projects we see, API pricing is nowhere near the biggest line — integration, data cleanup and human review time are. A model at a tenth of the price that needs twice the checking is not cheaper.
  • Where do the prompts land, and under whose law? Hosted API versus self-hosted open weights is the real fork in the road. Answer it first.
  • What breaks if the vendor disappears? Bans, sanctions and procurement policy have all moved fast in this market. Keep your prompts and orchestration portable so switching is a config change, not a rebuild.
  • Have you tested it on your work, not a benchmark? Benchmark parity and usefulness on your invoices, your quotes and your customer emails are different measurements, and only the second one pays.

None of this makes every non-US model radioactive, and we would say the same about pointing a US vendor's agent at your finance system without scoping it. The takeaway is narrower: choose a model on where your data goes and what the whole workflow costs, not on a training-cost headline its own authors never claimed. That is the first conversation on every data and AI automation project we run — talk it through with us before you migrate anything.

Source: NSA, CISA and FBI — China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies (AA26-251A)

Sounds like your situation?

Talk to us — or ask the AI assistant, bottom right. It knows all three divisions and hands you to a human the moment you want one.

Data & AI VEU Energy Upgrades Intelligent Home