Anthropic Accuses Chinese AI Labs of Distilling Claude: What It Means

by
0 comments
Anthropologist vs. Sugar Dealer: The Problem of Distillation

Anthropic, which markets itself as a security-first AI company, has accused three Chinese AI developers, DeepSeek, MiniMax and Moonshot AI, of covertly extracting capabilities from its Claude models to improve their own. In a February 2026 disclosure, Anthropic alleged that the firms generated more than 16 million exchanges with Claude through roughly 24,000 fraudulent accounts, using a technique known as distillation, and argued that the activity poses a national-security concern because stripping out Claude’s safety guardrails could help produce models with dangerous capabilities.

What distillation actually is

Distillation is a standard machine-learning method in which a smaller “student” model is trained to mimic the outputs of a larger, more capable “teacher” model. It is widely used and entirely legitimate in normal circumstances; frontier labs routinely distill their own models to create cheaper, faster versions for customers. What Anthropic objects to is not the technique but the alleged manner and scale of its use: large-scale extraction through fake accounts that violated its terms of service and regional access restrictions. Because Anthropic does not offer commercial Claude access in China, the firms reportedly used commercial proxy services to route tens of thousands of accounts around those restrictions. By Anthropic’s account, the volume was uneven across the three: MiniMax drove the most traffic, with more than 13 million exchanges, Moonshot AI was second at over 3.4 million, and DeepSeek accounted for the smallest share. Anthropic said the campaigns targeted specific capabilities, with DeepSeek, for example, focused on reasoning data across a range of tasks.

The dangers Anthropic points to

Anthropic frames the issue as more than a competitive grievance. Stripping a model’s safety guardrails during extraction, it argues, can yield systems more willing to produce harmful content, and replication at industrial scale undermines the economic case for the enormous investment that frontier models require. The company also tied the episode to US export policy, arguing on its blog that restricted access to advanced chips limits both direct model training and the scale of illicit distillation, a stance consistent with its recent support for US chip export controls.

Industry analysts see both substance and irony in the claims. The pattern Anthropic describes, millions of API calls across thousands of coordinated accounts, looks less like ordinary benchmarking and more like systematic replication, and if competitors can cheaply extract the fruits of multibillion-dollar research, the incentive to fund that research erodes. At the same time, some note the awkwardness of American labs raising appropriation concerns when several of them face lawsuits over using copyrighted material without permission or payment to train their own models. Large-scale extraction is a real problem, but it lands amid an unresolved debate about how AI systems are built in the first place.

How Anthropic says it responded

Anthropic has said it detected the activity and moved to block the offending accounts and proxy networks, and it published its findings partly to push for industry-wide norms and detection methods against this kind of extraction. The disclosure doubles as a warning to other model providers that face the same exposure and as a marker in the broader contest over how access to frontier models should be controlled.

The Chinese AI market is more than a copy

Analysts also caution against reducing Chinese AI progress to imitation. Chinese developers compete fiercely with one another and with firms such as OpenAI, Anthropic, Alibaba and Baidu, and observers argue their success cannot be explained by borrowing alone: whatever they may have learned from US models, they have layered their own innovations on top. The reputational risk, however, is significant. Once a developer is labeled a copycat, it becomes difficult to separate genuine, independent advances from accusations of appropriation, which complicates the brand even where the underlying engineering is strong.

What it means for enterprises

For organizations choosing which models to deploy, the dispute sharpens two practical questions. The first is the integrity of a model’s safety guardrails: a system distilled from another, with protections removed, may behave less predictably on sensitive inputs. The second is provenance. The lineage of training data is increasingly a board-level concern, because uncertainty about how a model was built can carry legal, security, and reputational risk downstream. Enterprises that depend on AI for regulated or high-stakes work benefit from asking vendors not just how a model performs, but where its capabilities came from, much as they would scrutinise any other part of a governed AI deployment.

The bigger picture

Anthropic’s allegations sit at the intersection of technology, commerce, and geopolitics. They highlight a genuine vulnerability, the difficulty of preventing a determined competitor from learning from a model exposed through an API, while also advancing Anthropic’s alignment with US policy interests. The episode is unlikely to be the last of its kind: as long as powerful models are accessible over the internet, the line between studying a competitor and copying it will remain contested, and training-data provenance will only grow as a strategic and regulatory issue.

Related Articles