Full Breakdown
Chinese Labs Allegedly Exploit U.S. AI Technology Through Distillation Campaigns
2/24/2026, 12:18:02 AM
Allegations of Distillation Attacks
Anthropic, a leading artificial intelligence firm based in the United States, has accused three China-based AI laboratories—DeepSeek, Moonshot AI, and MiniMax—of employing approximately 24,000 fraudulent accounts to conduct a coordinated campaign aimed at siphoning advanced U.S. AI capabilities. This operation allegedly resulted in over 16 million exchanges with Anthropic's Claude chatbot, which the company claims was part of a "distillation" effort to extract high-value model outputs. Jacob Klein, Anthropic’s head of threat intelligence, stated that the labs targeted Claude’s advanced features, including complex reasoning and coding, rather than typical consumer interactions.
Implications of Distillation
Distillation is a technique used in AI training where a less capable model learns from a more advanced one. While this method is common within the industry for creating cost-effective versions of AI systems, Anthropic asserts that the campaigns it uncovered were unauthorized and aimed at bypassing years of research and reinforcement learning. Klein emphasized that the implications of these unauthorized distillation efforts extend beyond mere intellectual property theft; they pose a risk of enabling authoritarian regimes to utilize unprotected AI capabilities for military and surveillance purposes.
Concerns Over U.S. Export Controls
The allegations raise significant questions regarding the effectiveness of current U.S. export controls, which primarily focus on restricting access to advanced AI chips and direct model transfers. Klein noted that distillation targets a different layer of competitive advantage, specifically the reinforcement learning processes that refine AI models post-training. He argued that while advanced chips remain crucial, policymakers need to adopt a more holistic approach to safeguard U.S. AI technologies.
Responses from the AI Community
Anthropic has shared its findings with relevant U.S. government entities and industry partners, suggesting that publicly naming the implicated labs could lead to meaningful government action. However, the company clarified that it has no evidence of direct coordination between the Chinese government and the labs involved. The situation has drawn attention from other major players in the AI field, with OpenAI alleging that DeepSeek systematically "stole" its intellectual property through similar distillation tactics. Google’s Threat Intelligence Group has also reported observing campaigns targeting its Gemini models, further highlighting the prevalence of distillation attacks.
Criticism and Broader Context
The allegations against the Chinese labs have sparked discussions about the ongoing U.S.-China AI race and the challenges of protecting frontier American systems. Anthropic's recent tensions with the Pentagon over the military applications of its AI models have added another layer to the narrative, as the company seeks to clarify its stance on the use of its technology in military operations.
Verbatim Quotes
- “We have high confidence these labs were conducting distillation attacks at scale,” — Jacob Klein, Head of Threat Intelligence, Anthropic
- “ "What we can say with confidence is they distilled us at scale," he said.” — Jacob Klein, Head of Threat Intelligence, Anthropic
- “If you think about how you stay ahead in the AI race, compute is one piece of that," Klein said.” — Jacob Klein, Head of Threat Intelligence, Anthropic
The unfolding situation underscores the complexities of safeguarding technological advancements in an increasingly competitive global landscape.
