Analysis
Anthropic disclosed Thursday that the distillation campaigns it first flagged in February against three Chinese AI labs have evolved into an organized market that uses dark-web forums and commercial proxy services to help foreign labs bypass its access controls entirely, CNBC reported. "There's an entire illicit ecosystem to try to gain access to Claude and other models," said Jacob Klein, Anthropic's head of threat intelligence.
Anthropic, founded in 2021 by former OpenAI researchers Dario and Daniela Amodei, builds the Claude family of models and has positioned itself as the frontier lab most willing to publicly name and quantify misuse of its own product -- a stance that doubles as a national-security argument for why Washington should restrict rival labs' access to US-made models. Distillation is a standard, often legal AI training technique in which a smaller model learns by studying a stronger one's outputs; Anthropic's argument is that what it's tracking isn't legitimate research use but industrial-scale extraction run through fraudulent accounts and access markets built specifically to evade its terms of service and export restrictions.
Four Labs, Two Disclosed Campaigns
- DeepSeek, Moonshot AI, MiniMax -- accused in February of running roughly 24,000 fraudulent accounts that generated more than 16 million exchanges with Claude, extracting outputs to train and improve their own models, per Anthropic's own writeup.
- Alibaba and Alibaba Qwen -- accused separately of a larger campaign running April 22 through June 5, 2026, generating more than 28.8 million exchanges targeting agentic reasoning, software engineering and long-horizon task capabilities specifically, Mobile World Live reported.
The scale gap between the two disclosed campaigns is itself notable -- Alibaba's alone, at 28.8 million exchanges, is nearly double the combined 16 million Anthropic attributed to DeepSeek, Moonshot and MiniMax together. All four labs compete directly with Anthropic and OpenAI for both Chinese domestic AI leadership and international enterprise customers who might otherwise buy API access to Claude or GPT models -- a cheaper, distilled model with comparable benchmark performance directly undercuts the pricing power frontier labs depend on to justify tens of billions of dollars in compute spending.
The Trump administration's April memo called distillation that undermines American research and proprietary information "unacceptable" and committed to sharing threat intelligence with US AI companies. Thursday's disclosure is Anthropic operationalizing that commitment publicly rather than waiting for government action -- naming specific companies, specific numbers and a specific evasion mechanism.
For VCs with China AI exposure, the practical read is that access to a frontier US model, even indirectly through a proxy service, is now something regulators are actively hunting rather than a gray-area workaround -- and any Chinese AI lab racing toward a public listing, like Moonshot's confidential Hong Kong IPO filing this week, carries fresh disclosure risk if it's one of the labs named in an active US distillation dispute.
What Anthropic's disclosure doesn't establish is causation between distillation and any specific downstream harm -- the company argues distilled models are unlikely to retain frontier safety guardrails, but that's a stated risk, not a documented instance of harm. Anthropic is also not a neutral party: it has commercial interest in both the White House restricting rival labs' access to its technology and in a public narrative that positions Claude as too valuable to let China copy cheaply, alongside its own multi-billion-dollar compute commitments the disclosure indirectly helps justify.
The dark-web and proxy-service angle is the new detail worth tracking -- if evading Anthropic's access controls has become a commercial service with its own market, the response required is different and harder than blocking fraudulent sign-ups one account at a time.