Anthropic's head of threat intelligence, Jacob Klein, has accused foreign adversaries, specifically Chinese AI labs, of illegally accessing and distilling its Claude models. Distillation involves using the output of one AI model to train another, which can significantly reduce development costs for the new model. Klein states that this is not legal competition but rather theft, with an "illicit ecosystem" working to evade Anthropic's controls and create accounts at scale.
This issue is emerging at a critical time for Anthropic, a company valued at nearly $1 trillion and expected to go public soon. The alleged illegal distillation allows competitors to offer similar AI capabilities at a much lower price, potentially impacting Anthropic's market position. The practice has become a controversial topic in the AI landscape, with some advocating for regulation against intellectual property theft and others arguing for an open market.
Anthropic has specifically named Chinese AI labs Moonshot AI, DeepSeek, MiniMax, and Alibaba as engaging in these distillation practices. Moonshot AI's Kimi K3 model, which gained attention for its lower price and adaptability, is alleged by Klein to have been illegally trained using the newest version of Claude. Anthropic has also accused Alibaba of a "massive distillation attack" to capture capabilities from its frontier AI models.
The U.S. government has also expressed concerns regarding this issue. An April memo from the Trump administration stated that distillation undermining American research and proprietary information is "unacceptable" and indicated that measures would be explored to hold foreign actors accountable. This highlights a broader industry concern about intellectual property protection in the rapidly evolving AI sector.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Nvidia CEO Jensen Huang characterized AI model distillation as "competition," contrasting with the White House's view of it as "theft." This statement comes amidst rising US-China tensions regarding AI supremacy and accusations against Chinese companies for using distillation.
The U.S. government and companies accuse Chinese AI labs of using "distillation" to advance their models, which involves training AI with output from more advanced models. Aidan Gomez, CEO of Cohere, disputes this, stating that while distillation occurred, recent Chinese models demonstrate independent, world-class capabilities that sometimes surpass U.S. models.
US AI developers and the government are concerned about distillation attacks on Western Frontier AI models, which may help China and Russia develop similar AI capabilities at lower costs. China has denied these claims but stated it will enact "countermeasures" if the US uses these allegations to constrain Chinese AI development. Distillation allows smaller models to emulate advanced models by analyzing their outputs, raising concerns when applied to competitors' models.
Y Combinator CEO Garry Tan stated that U.S. AI labs should use distillation techniques on frontier models to create more open-weight options, rather than regulators restricting the practice. This stance contrasts with calls from some AI companies, like Anthropic, for stricter controls on distillation, particularly regarding illicit activities.
Anthropic identified and disrupted illicit distillation attacks against its Claude AI model by seven China-based AI labs, including Alibaba, Moonshot, DeepSeek, Z.ai, and MiniMax. These labs used sophisticated methods to extract Claude's capabilities for training their own models, raising concerns about intellectual property theft and data privacy in the AI industry.
Y Combinator CEO Garry Tan stated that regulators should "do nothing" about AI model distillation, a process where smaller models are trained using outputs from larger models. This stance contrasts with concerns raised by companies like OpenAI and Anthropic, who accuse Chinese firms of illicit distillation, and a recent cybersecurity advisory from U.S. agencies. Tan suggests focusing on balancing open-weight and frontier models to ensure business model feasibility.
Anthropic detected and disrupted unauthorized large-scale efforts by Chinese AI labs, including Alibaba, Moonshot, and DeepSeek, to train their models using outputs from Claude. This "illicit distillation" involved using Claude's responses to replicate its capabilities, with Alibaba's campaign alone involving over 151 million exchanges.
Anthropic released a report detailing persistent and escalating distillation attacks by China-based AI companies, including Alibaba, Moonshot AI, and DeepSeek. These campaigns aim to extract the internal chain of thought from Anthropic's models to train smaller models, impacting the security and intellectual property of frontier AI development.
Anthropic's head of threat intelligence, Jacob Klein, stated that foreign adversaries, particularly Chinese AI labs, are illegally accessing and distilling its Claude models to train competing AI technology and sell cheaper copycat versions. This practice, which Anthropic considers theft of intellectual property, is intensifying as the company approaches a potential IPO and has prompted concerns from the U.S. government regarding undermined American research.