Anthropic Accuses Chinese AI Firms of Industrial-Scale Model Distillation
The AI developer alleges that three Chinese companies used thousands of fake accounts to illicitly extract capabilities from its Claude model.
U.S. government officials and AI developer Anthropic have accused several Chinese firms of engaging in "malicious" and "industrial-scale" distillation of U.S. AI technology. The allegations frame this activity as a direct threat to U.S. national security and a violation of existing AI export controls.
According to Anthropic, three specific Chinese AI laboratories—DeepSeek, Moonshot AI, and MiniMax—conducted coordinated campaigns to illicitly extract capabilities from the Claude AI model. To bypass security measures, the firms allegedly deployed more than 24,000 fraudulent accounts. These accounts were used to generate over 16 million exchanges with Claude, allowing the firms to harvest high-quality outputs to train their own systems. Anthropic stated it identified these "industrial-scale campaigns" designed to improve the performance of competing Chinese models.
The Mechanics of Distillation
AI distillation is a standard training technique in which a smaller, less advanced "student" model learns to mimic the behavior and outputs of a larger, more sophisticated "teacher" model. While this process is common in legitimate academic and industrial research to create more efficient models, the U.S. government alleges that the scale and methodology used in this instance constitute intellectual property theft. By using API access and fake accounts, the accused firms are alleged to have bypassed the immense financial and computational costs required to develop frontier-level models from scratch.
Implications for Export Controls
This dispute underscores a critical vulnerability in current U.S. AI export controls. For years, the U.S. has relied heavily on hardware restrictions, such as bans on high-end GPU chips, to slow the development of advanced AI in China. However, if Chinese firms can effectively "distill" the intelligence of frontier models via software interfaces, hardware bans may be significantly less effective in maintaining U.S. technological leadership. The ability to extract capabilities through API access suggests that the "moat" protecting U.S. AI superiority is more porous than previously assumed.
Geopolitical Friction
Beyond the technical theft, the accusations signal escalating geopolitical tensions between Washington and Beijing. The framing of these activities as national security threats suggests that AI capabilities are now viewed as strategic assets similar to military hardware. As both nations move toward high-level diplomatic summits, the dispute over model distillation is likely to become a central point of contention regarding trade and technology transfers.
What remains to be seen is how the U.S. government will respond to these findings. While Anthropic has publicized the breach, it is unclear if the U.S. will implement stricter API monitoring or introduce new sanctions against the named firms. The accused companies—DeepSeek, Moonshot AI, and MiniMax—have not yet provided a detailed public rebuttal to the specific account numbers cited by Anthropic.