Morning Edition LIVE
Vol. I · No. 1
Est.
MMXXVI

The A.I. Beat

Dispatches from the frontier of machine intelligence
Three
Dollars
← Front page Opinion September 11, 2026 · 5 min read
Opinion

Anthropic's Distillation Report Is a Warning Shot AI Companies Can't Ignore

Chinese AI labs are allegedly stealing Western models through API abuse, and the industry's response will determine whether open competition survives.
Anthropic's Distillation Report Is a Warning Shot AI Companies Can't Ignore

Anthropic just published something most AI companies would rather keep quiet: a detailed report naming Alibaba, Moonshot AI, and DeepSeek for what it calls “persistent distillation attacks.” This isn’t vague hand-wringing about IP theft. It’s a named-and-shamed list with receipts.

If you’re not deep in AI development, distillation sounds technical and abstract. It’s not. It’s closer to industrial espionage with a API key. Here’s how it works: you don’t have the compute, data, or research talent to build a frontier AI model yourself. So instead, you send thousands or millions of queries to someone else’s model through their API, collect the outputs, and use that data to train your own smaller, cheaper model that mimics the original’s behavior. You’re essentially stealing the intelligence without stealing the weights.

The practice sits in a legal and ethical gray zone. You’re not hacking into servers or downloading model files. You’re just a very, very enthusiastic customer. Except your enthusiasm is designed to extract maximum value while giving minimum back. And according to Anthropic, that’s exactly what these Chinese labs have been doing, with campaigns that have “escalated in recent months as competition in the space has intensified.”

Why This Matters More Than You Think

The easy take here is to frame this as US versus China tech competition. That’s partly true, but it misses the bigger threat. Distillation attacks don’t just hurt the companies being targeted. They break the entire economic model that makes frontier AI research possible.

Building a state-of-the-art model costs hundreds of millions of dollars. Companies like Anthropic, OpenAI, and Google recoup those costs partly through API access, but also by maintaining a performance lead that justifies premium pricing and attracts top talent. If smaller labs can systematically copy that intelligence for a fraction of the cost, the investment case for pushing the frontier collapses.

This isn’t hypothetical. We’ve already seen it play out in other industries. When intellectual property protections are weak or unenforced, the companies that invest in R&D get undercut by fast followers who didn’t pay the development costs. Innovation slows. Everyone converges on the same capabilities. The frontier stops moving.

Some people will argue that this is fine, that AI capabilities should be freely available, that distillation is just another form of knowledge transfer. I think that’s dangerously naive. There’s a difference between open research (where findings are published and built upon) and systematic value extraction (where one party invests, another copies, and nothing flows back). One model produces more research. The other produces less.

The Industry Has Three Options

Anthropic chose public disclosure. That’s notable because most companies handle this quietly, through lawyers and private pressure. By publishing names and details, Anthropic is forcing the industry to pick a side.

Option one: treat this as business as usual. Let distillation happen, accept that frontier models will be copied within months, and compete on speed and scale rather than sustained advantage. This is basically surrendering to a race to the bottom.

Option two: lock down API access so aggressively that legitimate uses become impossible. Require enterprise contracts for anything beyond trivial use. Build technical barriers that make distillation harder but also make the models less useful for everyone else. This kills one of the main benefits of AI as a platform.

Option three: create industry norms with teeth. Not just terms of service that ban distillation, but actual enforcement mechanisms, coordinated responses, and pressure on companies that enable or profit from these practices. This requires cooperation among competitors, which is hard but not impossible.

I don’t think option three is realistic without external pressure. The AI industry has shown zero ability to self-regulate on anything that meaningfully constrains growth. We can’t even agree on basic safety standards. Expecting voluntary coordination against distillation is probably wishful thinking.

What Happens Next

Anthropic’s report doesn’t just document the problem. It sets a precedent for how to respond. Other labs now have to decide whether to follow suit with their own disclosures or stay quiet and hope their own losses stay private. If multiple companies start naming bad actors, we might see something like industry-wide blocklists or pressure on cloud providers to crack down on suspicious usage patterns.

China-based labs, meanwhile, have to calculate whether the reputational hit and potential restrictions are worth the capability gains. Being publicly accused of distillation by a major AI lab isn’t nothing, especially if you’re trying to build partnerships or credibility outside China.

The real test is whether this changes behavior. If six months from now we’re reading similar reports with the same names, we’ll know that public shaming doesn’t work and stronger measures are needed. If the attacks slow down or shift tactics, it means reputation still matters and the industry can use that as leverage.

Either way, Anthropic just made this everyone’s problem. And that’s probably the right call. Distillation attacks were happening whether we talked about them or not. Now at least we’re talking about them.

The companies that invest billions in pushing AI forward deserve to capture some of that value. The alternative isn’t a world where everyone benefits equally. It’s a world where nobody invests in the hard problems because the returns get arbitraged away before they materialize. We should care about that, even if the victims are huge corporations. When the frontier stops moving, everyone loses.

opinion industry