Anthropic accuses Chinese AI labs of illegally distilling Claude models
Anthropic accuses Chinese AI labs of illegally distilling its Claude models, a practice its security chief calls a national-security risk.
Distillation has become a point of controversy across the AI industry. Some in the U.S. tech sector have urged policymakers to allow the market to choose the best and most cost-effective AI; others want a crackdown on what they view as intellectual-property theft. In an April memo, the Trump administration said distillation that undermines American research and proprietary information is "unacceptable" and said it would explore measures to hold foreign actors accountable.
Klein singled out Chinese lab Moonshot AI as one company ripping off Anthropic's work, saying its Kimi K3 model—which took the tech world by storm in July—was illegally trained on the newest version of Claude. Anthropic earlier this year accused Moonshot, DeepSeek and MiniMax of distilling its frontier models, and separately accused Alibaba of conducting a massive "distillation attack" to capture Claude's capabilities. OpenAI and Google have both published reports making similar claims. Alibaba, DeepSeek, Moonshot and MiniMax did not respond to requests for comment.
Cybersecurity experts told CNBC that the threat also comes from Iran, Russia, North Korea and other countries where Claude, Google's Gemini and OpenAI's ChatGPT are restricted by the companies because of sanctions. Klein said many labs in those regions use "illicit means and fraudulent means" to obtain access. One route is the dark web, where stolen credit-card data and compromised AI accounts are bought and sold. Klein said companies such as Moonshot are "spinning up tens of thousands, if not hundreds of thousands of fraudulent accounts."
Klein said a clear sign of distillation is a user asking thousands of questions or creating thousands of accounts, creating a whack-a-mole problem for AI labs. "It's very hard to fully stop this as a problem, but I think slowing it down is good and worthwhile," he said. He warned that outside attackers can gain access to more capable models than they otherwise could have, pointing to surveillance and possible use in a biological weapons program, and citing a campaign from a China-based entity conducting espionage at scale using Anthropic's technology.
The allegations come at a critical time for Anthropic. CNBC has reported the company has reached a private-market valuation of close to $1 trillion and is expected to go public as soon as October.