Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says
Source Entity
US Top News and Analysis

Anthropic has released a report detailing unauthorized 'distillation' attacks by Chinese AI labs like Alibaba, Moonshot AI, and DeepSeek. These firms are accused of using Claude’s outputs to train their own models, sparking a debate on model security versus open-market competition.
The Escalation of Model Distillation Warfare
A recent report from Anthropic has brought the contentious issue of AI model distillation to the forefront of the global technology landscape. The report alleges that China-based AI companies, specifically identifying Alibaba, Moonshot AI, and DeepSeek, have engaged in persistent and increasingly sophisticated campaigns to harvest the capabilities of U.S.-based frontier models. This practice, known as distillation, involves using the outputs of a highly capable model to train a less capable one, effectively allowing the illicit transfer of intellectual property and reasoning capabilities.
The Mechanics of Illicit Distillation
At its core, distillation is a technical process, but in this context, it has become a significant security concern for American AI labs. Anthropic’s findings indicate that unauthorized actors are bypassing security defenses to gain access to Claude’s specialized functions, such as agentic capabilities, tool use, coding, data analysis, and logical reasoning. By repeatedly querying these models and recording the outputs, these labs are essentially 'cloning' the intelligence of frontier systems to bolster their own domestic alternatives, often without the consent or knowledge of the original developers.
Privacy and Security Implications
The implications of these campaigns extend far beyond simple intellectual property theft. Anthropic’s report highlights that the unauthorized exchanges often included sensitive data from individual users, major multinational corporations, and even state-affiliated actors. This raises severe concerns regarding data privacy and compliance with international regulations. By harvesting data in this manner, these labs may be violating both their own terms of service and global privacy standards, creating a potential minefield for the users whose data is inadvertently being used to train foreign AI systems.
Historical Context and Industry Response
This is not the first time such activity has been documented. Anthropic previously raised alarms about distillation in February, and OpenAI has similarly reported activity attributed to DeepSeek. This pattern suggests a systemic effort by specific Chinese entities to close the technological gap between their domestic models and U.S. frontier AI. The escalation of these campaigns signifies a shift in the competitive landscape, where model security has become as critical as the underlying architecture of the AI itself.
The Counter-Narrative: The 'Do Nothing' Perspective
While major AI firms and national security experts are calling for strict regulations and defensive measures, the industry is not unified in its approach. Garry Tan, CEO of the renowned startup accelerator Y Combinator, recently voiced a dissenting opinion. During Y Combinator’s annual Demo Day, Tan suggested that he would 'do nothing' regarding distillation, arguing that the focus should perhaps shift toward creating an American distillation regime rather than attempting to halt the practice entirely. This highlights a deep philosophical divide in Silicon Valley between those who view AI capabilities as protected national assets and those who view the rapid dissemination of technology as an inevitable, if not beneficial, market force.
Future Trends and Strategic Outlook
Moving forward, the tension between AI labs and those utilizing distillation techniques is likely to intensify. As U.S. firms continue to fortify their defenses, attackers will inevitably develop more sophisticated methods to circumvent these barriers. The debate will likely shift from purely technical discussions to complex geopolitical and legal battles. Whether through stricter export controls, enhanced cybersecurity protocols, or new international frameworks, the industry is clearly entering a phase where the protection of frontier model 'weights' and outputs will define the next chapter of the global AI arms race.
Multiple Citing Sources