Anthropic published a report Thursday accusing three Chinese AI companies of running coordinated campaigns to distill knowledge from its Claude models. The company named Alibaba, Moonshot AI, and DeepSeek, and said the attempts have intensified in recent months.
Distillation is the practice of using a powerful AI model to generate training data for a smaller, cheaper one. You feed the big model thousands of prompts, collect its responses, and use that dataset to teach a smaller model to mimic its behavior. It’s controversial because it lets competitors copy years of research and billions in compute costs for a fraction of the price.
Anthropic didn’t detail exactly how it detected the campaigns or what technical measures it’s taking to stop them. The company did say the activity has escalated as competition in the AI space has gotten fiercer, which tracks with what we’re seeing in the broader market. Chinese labs are racing to close the gap with US frontier models, and distillation is one of the fastest ways to do it.
The timing is significant. All three companies Anthropic named are major players in China’s AI ecosystem. Alibaba runs one of the country’s largest cloud platforms and has been pushing hard into AI infrastructure. Moonshot AI, valued at over $3 billion, operates the Kimi chatbot, which has become one of China’s most popular AI assistants. DeepSeek is known for trying to build competitive models on a budget.
If Anthropic’s claims are accurate, this isn’t just a terms-of-service violation. It’s a systematic effort by well-funded companies to shortcut the development process. And it raises questions about how AI companies can actually protect their models when the attack vector is just using the product as intended, at scale.
The report also lands at a moment when AI companies are already nervous about where this is all heading. OpenAI put its Pro subscriptions on hold this week because demand for its new Astra model is overwhelming its systems. The company said Pro users put the most strain on capacity, so it paused sign-ups while it adds more GPUs. That’s a rare move for a company that’s been trying to grow revenue as fast as possible.
And there’s growing anxiety inside the big labs about whether they can even coordinate a slowdown if they wanted to. OpenAI has been asking lawyers whether antitrust law would allow frontier labs to agree to pause development if things start moving too fast. The fact that they’re even exploring the question tells you how seriously some people are taking the risks.
Anthropic’s decision to name names is unusual. Most AI companies don’t publicly call out competitors for distillation, even though everyone knows it happens. By going public, Anthropic is signaling that the problem has crossed a line. It’s also putting pressure on the named companies to respond, which could get messy if they push back or if other labs start releasing similar reports.
The bigger question is what Anthropic or anyone else can actually do about it. Rate limiting helps, but sophisticated actors can work around it by spreading requests across many accounts. Watermarking outputs might help with detection, but it’s not clear how enforceable that is across borders. And there’s no international framework for dealing with this stuff yet.
For now, the report is mostly a warning shot. But it’s also a sign that the competitive dynamics in AI are shifting in ways that make the big US labs uncomfortable. Distillation isn’t going away, and it’s only going to get more sophisticated as models get better and cheaper to run.
One email at dawn. The five stories that mattered, with the bits removed and the meaning kept. Free, for now.