China’s government has formally rejected accusations from Anthropic and other US AI firms that Chinese labs are running industrial-scale “distillation” campaigns to extract capabilities from American frontier models, calling the claims “misguided” and arguing that AI development is a global endeavour that risk undermining international collaboration. The dismissal, reported by Bloomberg on July 18, comes three months after US AI companies began publicly coordinating a response and one month after Anthropic escalated its accusations specifically against Alibaba.
🔍 THE BOTTOM LINE
The denial is diplomatically predictable, but the underlying numbers — 25,000 fraudulent accounts, 28.8 million dialogue exchanges in 44 days, a US–China model gap that industry officials say is narrowing from 6–9 months — make this less a disagreement about facts than a disagreement about what those facts mean. Beijing frames distillation as legitimate model compression; Anthropic frames it as theft. Both can be technically true, and that ambiguity is exactly why the dispute is so hard to resolve.
What Anthropic Actually Alleged
Anthropic’s June letter to the Senate Banking Committee, addressed to Senators Tim Scott and Elizabeth Warren, accused Alibaba and its AI lab Qwen of carrying out “the largest known distillation attack on Anthropic to date.” The specifics: operators affiliated with Alibaba ran roughly 25,000 fake accounts and exchanged 28.8 million cases of dialogue with Claude over 44 days, effectively extracting what Anthropic describes as the model’s entire data lineage.
This is not a one-off. As The New York Times reported on July 6, Anthropic’s February blog post accused three Chinese companies — DeepSeek, Moonshot AI and MiniMax — of setting up more than 24,000 fraudulent Claude accounts and prompting the model more than 16 million times to siphon training signal. OpenAI, Anthropic and Google have since begun sharing intelligence through the Frontier Model Forum to coordinate a clampdown, as we reported in April.
China’s Counter-Narrative
Beijing’s response has two strands. The first, carried by the Global Times, frames Anthropic’s accusations as “technological hegemony anxiety” — an attempt to “kick away the ladder” after Western labs built their own capabilities on permissive data regimes. The piece, citing a former SenseTime institute dean, leans heavily on Anthropic’s own $1.5 billion copyright settlement with authors in September 2025: if Anthropic trained on copyrighted books without permission, the argument goes, the company is in no position to lecture anyone about data extraction.
The second strand is the formal diplomatic line. A White House Office of Science and Technology Policy memorandum released April 23 claimed the US government had information indicating “foreign entities, principally based in China, are engaged in deliberate, industrial-scale campaigns to distill US frontier AI systems.” Chinese Foreign Ministry spokesperson Guo Jiakun responded April 24 that the accusations were “groundless” and “deliberate attacks on China’s development and progress in the AI industry.”
Why the Techniques Keep Evolving
The most revealing reporting on this story isn’t the diplomatic back-and-forth — it’s the technical detail. Chosun Ilbo’s July 15 piece describes a shift from “copying the answer key at the back of a textbook” to “multi-stage deep distillation,” which extracts the high-dimensional logical structures models use to derive answers and implants them into domestic models. In plain terms: the early distillation copied Claude’s outputs; the current generation copies how Claude reasons.
The same piece reports Chinese firms are disguising IP addresses as US or European to bypass geofencing, and distributing the distilled models globally as open-source software — a “reverse export” strategy that puts the replicated capabilities into the hands of developers everywhere, including in jurisdictions where US export controls have no reach. One industry official quoted anonymously puts the current US–China gap at 6–9 months and warns it could “narrow rapidly if unauthorized distillation methods are left unchecked.”
The Legal Vacuum Nobody Wants to Name
Here’s the uncomfortable structural fact underneath all of this: there is no clear international legal framework that defines distillation as theft. Anthropic’s Terms of Service prohibit using Claude outputs to train competing models, and US export controls restrict access to the most advanced weights. But a Chinese operator routing through a US-based VPN, prompting Claude through a fraudulent account, and then training a domestic model on the resulting dialogue data is operating in a zone where:
- US contract law has no extraterritorial reach over a Chinese national in China
- Export controls apply to model weights, not to the text outputs those weights generate
- Copyright law protects expression, not the statistical patterns a model learns from its outputs
- Chinese law does not recognise US ToS restrictions as binding
This is why Anthropic has shifted its lobbying from “enforce our contracts” to “treat this as a national security issue” — the national security framing opens the door to sanctions, export-control expansion, and law enforcement action that contract law alone cannot reach. It’s also why the Chinese government’s “misguided” dismissal is rhetorically careful: it doesn’t deny that the accounts existed or that the dialogue happened. It denies that the activity constitutes wrongdoing.
NZ Angle
For a small open economy that imports its frontier AI capability wholesale, the distillation fight matters in a specific way. New Zealand developers building on Claude, GPT, or Gemini inherit whatever access restrictions the US government imposes. If Anthropic tightens API access to counter distillation — stricter identity verification, lower rate limits for suspicious patterns, regional access cuts — NZ builders pay the friction cost of a fight they have no stake in. The counter-case, that distilled open-source models from Chinese labs give NZ developers cheaper access to near-frontier capability, is real but comes with the integrity questions we’ve covered before. There’s no clean side to pick here, only a cost-benefit calculation each builder has to run themselves.
❓ FAQ
Is distillation actually illegal? In most jurisdictions, no — not clearly. It violates the model provider’s Terms of Service, which is a contract breach, not a crime. US export controls cover weights, not outputs. Anthropic’s push to reframe it as a national security issue is an attempt to move it from contract law (weak, no extraterritorial reach) into sanctions law (strong, extraterritorial).
If China dismisses the claims, why do the numbers still matter? Because the numbers — 25,000 accounts, 28.8 million exchanges — come from Anthropic’s server logs, not from an intelligence assessment or a media report. Beijing isn’t disputing that the traffic happened; it’s disputing the interpretation. That’s a meaningful distinction: the factual baseline isn’t contested, only the legal framing.
Does this affect normal Claude or GPT users? Not yet directly. But if providers tighten anti-distillation controls — stricter identity checks, rate limiting, regional restrictions — the friction lands on legitimate users too. The Moonshot AI funding round and the broader Chinese open-source push are partly a downstream consequence: if you can’t access Western models cleanly, you build your own and open-source it.
What’s the realistic endgame? Two parallel tracks. Track one: sanctions and export-control expansion against named Chinese AI firms, slower and politically contested. Track two: technical countermeasures — output watermarking, rate-limit pattern detection, identity verification — that providers deploy unilaterally. Track two is already happening. Track one depends on whether the US can prove the distillation campaigns are state-directed, not just company-directed.
🔍 THE BOTTOM LINE
China’s “misguided” dismissal is the diplomatic equivalent of a no-comment — it doesn’t engage with the evidence, it reframes the question. That’s fine as a negotiating position, but it doesn’t change the underlying reality: the gap between US and Chinese frontier models is closing, distillation is one of the mechanisms closing it, and no one — not Anthropic, not the Frontier Model Forum, not the US government — has a clean legal tool to stop it. The fight is now less about whether it’s happening and more about whether the US can build a sanctions regime that treats it as something more serious than a ToS violation. Watch the Senate Banking Committee and the Commerce Department’s Bureau of Industry and Security over the next quarter. That’s where this actually gets decided.
📰 Sources
- AInvest — China says AI distillation allegations are “misguided”
- Bloomberg — China Dismisses Claim that It Illicitly Extracts Foreign AI Tech
- CNBC — Anthropic accuses Alibaba of campaign to extract AI capabilities
- The New York Times — Why A.I. Distillation Has Become a Hot Topic in the Race with China
- Global Times — Anthropic’s ‘distillation’ claims against Chinese firm lack substance
- Chosun Ilbo — Chinese AI ‘Knowledge Distillation’ Advances Escalate U.S. Tech Tensions
- Anthropic — Detecting and Preventing Distillation Attacks
- Forbes — Distillation: The New US-China AI Fight