Anthropic published a report today accusing three Chinese AI labs of running an industrial-scale distillation operation against Claude. DeepSeek, Moonshot AI, and MiniMax allegedly created over 24,000 fake accounts and ran more than 16 million exchanges through Claude’s API to extract its most advanced capabilities. Agentic reasoning. Tool use. Coding. The specific things that make Claude worth paying for.
The findings are credible. Anthropic says it tracked DeepSeek running 150,000 exchanges targeting foundational logic and alignment, specifically probing how Claude handles censorship-sensitive queries. Moonshot AI was more aggressive, with 3.4 million exchanges aimed at agentic reasoning, tool use, coding, and computer vision. MiniMax fell somewhere in between. The scale was significant enough that Anthropic built behavioral fingerprinting tools to detect the patterns in API traffic and is now sharing technical indicators with other AI labs and cloud providers.
None of this is surprising. Distillation is how smaller labs have always bootstrapped their models. You take outputs from a frontier system, use them as training data, and your model learns to mimic the behavior without incurring the full cost of developing it independently. OpenAI sent a memo to House lawmakers earlier this month making similar accusations against DeepSeek. Google has been dealing with API abuse at scale since long before the current AI generation. This is a known technique with known countermeasures.
The Timing Tells the Story
What matters more than the distillation itself is when Anthropic chose to publish this. The report dropped the same week that Congress is actively debating AI chip export controls. Last month, the Trump administration formally allowed Nvidia to export H200 chips to China, loosening restrictions that had been tightening since 2022. Critics have been screaming about it. Anthropic’s report explicitly argues that distillation attacks “require access to advanced chips” and that these findings “reinforce the rationale for export controls.”
That’s not a security disclosure. That’s a policy position with a security disclosure stapled to the front.
Anthropic benefits directly from tighter export controls. If Chinese labs can’t get advanced chips, they can’t train competitive models, which means they stay dependent on API access to Western systems. If they stay dependent on API access, Anthropic and OpenAI collect the revenue. Restricting chips doesn’t stop distillation (you can distill with consumer hardware), but it slows down the development of independent Chinese AI capabilities. That’s good for Anthropic’s business whether or not it’s good for national security.
The House Homeland Security Committee has asked Dario Amodei to testify about the implications. That’s the real deliverable here. Not the technical report. The hearing invitation.
The Legal Gray Zone Nobody Wants to Address
Distillation is not theft. It’s not hacking. It’s not even clearly a terms-of-service violation in every jurisdiction. The technique involves sending legitimate API queries and using the legitimate outputs for training. Anthropic’s terms prohibit it. But terms of service are contractual agreements, not laws. Enforcing them against entities operating in China through fake accounts routed through intermediary jurisdictions is, practically speaking, impossible.
There’s a reason Anthropic didn’t announce lawsuits today. They announced a report. Lawsuits require legal standing in a jurisdiction where you can actually enforce a judgment. Reports require a PDF and good timing.
The harder question is whether distillation should be illegal. If you buy API access, you get outputs. If you use those outputs to train a model, you’ve created a derivative work. But derivative of what? The model weights? Those weren’t copied. The training data? That wasn’t accessed. The “style” of reasoning? Good luck defining that in a courtroom.
Copyright law doesn’t map cleanly onto AI model outputs. Patent law is even worse. The closest precedent is database protection law, and that varies so wildly across jurisdictions that it’s not precedent at all. Congress could write a law specifically prohibiting model distillation. Congress could also cure cancer. Neither appears imminent.
What This Actually Changes
Practically, very little. Anthropic will improve its detection systems. The Chinese labs will improve their evasion techniques. The arms race between API providers and distillation operations will continue at increasing sophistication on both sides, just like the arms race between ad platforms and click fraud, or streaming services and credential sharing, or any other system where the economics of cheating outpace the economics of enforcement.
Politically, quite a lot. Anthropic’s report gives export control hawks exactly the ammunition they need during exactly the debate they’re having. The narrative is clean: American AI companies build frontier capabilities, Chinese labs steal them, and the only solution is to restrict the chips that make it possible. That narrative is compelling whether or not it’s complete.
The part nobody is saying out loud: if distillation is this effective, it means Anthropic’s models contain enough concentrated capability that a smaller lab can extract meaningful value from just the outputs. That’s simultaneously a security vulnerability and the best advertising Anthropic has ever received.