← All stories
● Covered by 5 sources · 9 reportsMedium impact4 negative5 neutral

Anthropic Accuses Chinese AI Labs of Illegally Distilling Claude Models

🔄 Updated 3d ago — new reporting from Hacker News Front Page
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Anthropic alleges illegal distillation of Claude models by Chinese AI labs.
  • Distillation allows creation of cheaper, competitive AI models.
  • Moonshot AI, DeepSeek, MiniMax, and Alibaba are accused.
  • U.S. government memo called distillation undermining American IP "unacceptable."
  • Anthropic's report was released on Thursday.
  • Distillation campaigns target Claude's agentic capabilities, tool use, coding, data analysis, and logical reasoning.
  • Anthropic observed nearly 200 million exchanges linked to distillation attacks.
  • Five separate campaigns are attributed to the distillation attacks.
  • Alibaba's campaign involved over 151 million exchanges between May and July.
  • Moonshot routed Kimi user requests to Claude to train its models.
  • Alibaba used Claude outputs to train its Qwen models.
  • The activity peaked at nearly 3 million exchanges per day.
  • Y Combinator CEO Garry Tan said regulators should 'do nothing' about distillation.
  • OpenAI believes DeepSeek's V3 and R1 models were distilled from GPT-4 and GPT-4o.
  • The U.S. National Security Agency, CISA, and FBI released a cybersecurity advisory on Tuesday.
  • Seven China-based AI labs ran distillation attacks.
  • Z.ai (aka Zhipu) is accused of distillation.
  • Illicit distillation uses fake accounts with stolen credentials.
  • Google and OpenAI also reported distillation attacks.
  • Labs use prompt manipulation tricks to bypass defenses.
  • Y Combinator CEO Garry Tan wants U.S. open-weight AI labs to distill frontier models.
  • Anthropic CEO Dario Amodei previously called on U.S. regulators to crack down on distillation.
  • Distillation attacks may help Russia develop AI models.
  • China pledged countermeasures if the U.S. uses allegations to contain Chinese AI development.
  • Western AI labs pledged to work together against distillation attacks earlier this year.
  • Foreign actors purchase logs of third-party conversations using legitimate accounts.
  • Aidan Gomez, CEO of Cohere, disputes that all of China's AI progress is due to distillation.
  • Gomez states recent Chinese models show independent, world-class capabilities.
  • Gomez co-authored the 2017 research paper "Attention Is All You Need."
  • Nvidia CEO Jensen Huang characterized AI model distillation as "competition."
  • Treasury Secretary Scott Bessent described distillation as "theft" in July.
  • Scott Bessent threatened sanctions against overseas companies using distillation.

Allegations of Illegal Model Distillation

Anthropic's head of threat intelligence, Jacob Klein, has accused foreign adversaries, specifically Chinese AI labs, of illegally accessing and distilling its Claude models. Distillation involves using the output of one AI model to train another, which can significantly reduce development costs for the new model. Klein states that this is not legal competition but rather theft, with an "illicit ecosystem" working to evade Anthropic's controls and create accounts at scale.

Impact on Anthropic and the AI Industry

This issue is emerging at a critical time for Anthropic, a company valued at nearly $1 trillion and expected to go public soon. The alleged illegal distillation allows competitors to offer similar AI capabilities at a much lower price, potentially impacting Anthropic's market position. The practice has become a controversial topic in the AI landscape, with some advocating for regulation against intellectual property theft and others arguing for an open market.

Accused Chinese AI Labs

Anthropic has specifically named Chinese AI labs Moonshot AI, DeepSeek, MiniMax, and Alibaba as engaging in these distillation practices. Moonshot AI's Kimi K3 model, which gained attention for its lower price and adaptability, is alleged by Klein to have been illegally trained using the newest version of Claude. Anthropic has also accused Alibaba of a "massive distillation attack" to capture capabilities from its frontier AI models.

Government Response and Broader Concerns

The U.S. government has also expressed concerns regarding this issue. An April memo from the Trump administration stated that distillation undermining American research and proprietary information is "unacceptable" and indicated that measures would be explored to hold foreign actors accountable. This highlights a broader industry concern about intellectual property protection in the rapidly evolving AI sector.

Updates

🕒 2026-09-28 · new reporting from Hacker News Front Page
  • Nvidia CEO Jensen Huang characterized AI model distillation as "competition."
  • Treasury Secretary Scott Bessent described distillation as "theft" in July.
  • Scott Bessent threatened sanctions against overseas companies using distillation.
🕒 2026-09-18 · new reporting from CNBC Technology
  • Aidan Gomez, CEO of Cohere, disputes that all of China's AI progress is due to distillation.
  • Gomez states recent Chinese models show independent, world-class capabilities.
  • Gomez co-authored the 2017 research paper "Attention Is All You Need."
🕒 2026-09-18 · new reporting from Tom's Hardware
  • Distillation attacks may help Russia develop AI models.
  • China pledged countermeasures if the U.S. uses allegations to contain Chinese AI development.
  • Western AI labs pledged to work together against distillation attacks earlier this year.
  • Foreign actors purchase logs of third-party conversations using legitimate accounts.
🕒 2026-09-11 · new reporting from TechCrunch
  • Y Combinator CEO Garry Tan wants U.S. open-weight AI labs to distill frontier models.
  • Anthropic CEO Dario Amodei previously called on U.S. regulators to crack down on distillation.
🕒 2026-09-11 · new reporting from The Hacker News
  • Seven China-based AI labs ran distillation attacks.
  • Z.ai (aka Zhipu) is accused of distillation.
  • Illicit distillation uses fake accounts with stolen credentials.
  • Google and OpenAI also reported distillation attacks.
  • Labs use prompt manipulation tricks to bypass defenses.
🕒 2026-09-11 · new reporting from CNBC Technology
  • Alibaba's campaign involved over 151 million exchanges between May and July.
  • Moonshot routed Kimi user requests to Claude to train its models.
  • Alibaba used Claude outputs to train its Qwen models.
  • The activity peaked at nearly 3 million exchanges per day.
  • Y Combinator CEO Garry Tan said regulators should 'do nothing' about distillation.
  • OpenAI believes DeepSeek's V3 and R1 models were distilled from GPT-4 and GPT-4o.
  • The U.S. National Security Agency, CISA, and FBI released a cybersecurity advisory on Tuesday.
🕒 2026-09-10 · new reporting from TechCrunch
  • Anthropic's report was released on Thursday.
  • Distillation campaigns target Claude's agentic capabilities, tool use, coding, data analysis, and logical reasoning.
  • Anthropic observed nearly 200 million exchanges linked to distillation attacks.
  • Five separate campaigns are attributed to the distillation attacks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Nvidia CEO Jensen Huang characterized AI model distillation as "competition," contrasting with the White House's view of it as "theft." This statement comes amidst rising US-China tensions regarding AI supremacy and accusations against Chinese companies for using distillation.

The U.S. government and companies accuse Chinese AI labs of using "distillation" to advance their models, which involves training AI with output from more advanced models. Aidan Gomez, CEO of Cohere, disputes this, stating that while distillation occurred, recent Chinese models demonstrate independent, world-class capabilities that sometimes surpass U.S. models.

US AI developers and the government are concerned about distillation attacks on Western Frontier AI models, which may help China and Russia develop similar AI capabilities at lower costs. China has denied these claims but stated it will enact "countermeasures" if the US uses these allegations to constrain Chinese AI development. Distillation allows smaller models to emulate advanced models by analyzing their outputs, raising concerns when applied to competitors' models.

Y Combinator CEO Garry Tan stated that U.S. AI labs should use distillation techniques on frontier models to create more open-weight options, rather than regulators restricting the practice. This stance contrasts with calls from some AI companies, like Anthropic, for stricter controls on distillation, particularly regarding illicit activities.

Anthropic identified and disrupted illicit distillation attacks against its Claude AI model by seven China-based AI labs, including Alibaba, Moonshot, DeepSeek, Z.ai, and MiniMax. These labs used sophisticated methods to extract Claude's capabilities for training their own models, raising concerns about intellectual property theft and data privacy in the AI industry.

Y Combinator CEO Garry Tan stated that regulators should "do nothing" about AI model distillation, a process where smaller models are trained using outputs from larger models. This stance contrasts with concerns raised by companies like OpenAI and Anthropic, who accuse Chinese firms of illicit distillation, and a recent cybersecurity advisory from U.S. agencies. Tan suggests focusing on balancing open-weight and frontier models to ensure business model feasibility.

Anthropic detected and disrupted unauthorized large-scale efforts by Chinese AI labs, including Alibaba, Moonshot, and DeepSeek, to train their models using outputs from Claude. This "illicit distillation" involved using Claude's responses to replicate its capabilities, with Alibaba's campaign alone involving over 151 million exchanges.

Anthropic released a report detailing persistent and escalating distillation attacks by China-based AI companies, including Alibaba, Moonshot AI, and DeepSeek. These campaigns aim to extract the internal chain of thought from Anthropic's models to train smaller models, impacting the security and intellectual property of frontier AI development.

Anthropic's head of threat intelligence, Jacob Klein, stated that foreign adversaries, particularly Chinese AI labs, are illegally accessing and distilling its Claude models to train competing AI technology and sell cheaper copycat versions. This practice, which Anthropic considers theft of intellectual property, is intensifying as the company approaches a potential IPO and has prompted concerns from the U.S. government regarding undermined American research.