Anthropic has accused Chinese artificial intelligence companies and other foreign actors of using large-scale networks of fraudulent accounts to extract capabilities from its Claude models and build cheaper competing systems, escalating a broader battle over AI model distillation, intellectual property and national security.
Jacob Klein, Anthropic’s head of threat intelligence, said the company supports legitimate competition but has identified what it describes as an illicit ecosystem designed to circumvent its safeguards and obtain access to Claude at enormous scale.
“There’s an entire illicit ecosystem to try to gain access to Claude and other models,” Klein told CNBC. “This ecosystem goes through any means necessary to evade our controls, so they can spin up accounts at extreme scale.”
Anthropic alleges that foreign AI developers can then repeatedly query Claude, collect millions of responses, and use those outputs to train their own models. The process, known as distillation, can substantially reduce the cost and time required to develop competing AI systems because a developer can learn from the behavior of an already capable model rather than building every capability from scratch.
The practice itself is not inherently illegal. Model developers can use distillation legitimately when they have permission to access and use another system’s outputs and comply with intellectual-property, contractual, and export-control requirements.
Anthropic’s allegation is that some actors are deliberately bypassing those restrictions.
Anthropic has singled out several Chinese AI laboratories, including Moonshot AI, DeepSeek and MiniMax, alleging that they have distilled capabilities from its frontier models.
Klein specifically accused Moonshot’s Kimi K3 model, which gained significant attention after its launch in July, of being trained illegally using the latest version of Claude.
“We’ve seen a fair amount of this from China,” Klein said. “This is something that the industry writ large is dealing with.”
Kimi K3 has attracted adoption in Silicon Valley partly because of its lower cost and the ability for businesses to customize the model more easily. If Anthropic’s allegations are substantiated, the episode would illustrate the competitive advantage that can be gained by extracting capabilities from a more expensive frontier model and subsequently offering them at a lower price.
Anthropic has also accused Alibaba, the developer of the Qwen family of AI models, of conducting what it described as a large-scale “distillation attack” against Claude.
Anthropic is not alone in raising concerns. OpenAI and Google have separately published research and reports about model distillation and have said they are taking measures to prevent unauthorized extraction of their models’ capabilities.
The issue is gaining broader attention as the performance gap between frontier models and cheaper competitors narrows. Distillation can allow developers with significantly smaller budgets to reproduce particular capabilities without incurring the same level of training expenditure as the original model developer. But that creates a difficult commercial equation for frontier AI companies. Billions of dollars can be spent developing a highly capable model, only for competitors to potentially extract useful behaviors through repeated interactions and incorporate them into cheaper systems.
Fake Accounts Create An Enforcement Problem
According to Klein, the problem extends beyond conventional account abuse.
He said some foreign actors are creating tens of thousands, potentially hundreds of thousands, of fraudulent accounts to access Anthropic’s services and generate enormous volumes of model responses. The accounts can allegedly be created using stolen payment-card information, compromised infrastructure, and other illicit resources, including marketplaces operating on the dark web.
Once inside Anthropic’s systems, an attacker can issue large numbers of queries and collect Claude’s responses. Those responses can subsequently become training material for another model, effectively turning Anthropic’s commercial AI service into a source of data for a competing system.
The scale makes detection difficult.
A normal user might make dozens of queries. A distillation operation could generate thousands or millions of interactions, potentially distributed across a vast number of accounts so that the activity resembles legitimate usage.
“It’s very hard to fully stop this as a problem, but I think slowing it down is good and worthwhile,” Klein said.
Travis Lanham, technology chief at cybersecurity firm Armadin and a former Google engineer, said the enormous volume of traffic handled by major AI companies makes sophisticated abuse difficult to isolate.
“These companies are serving billions of requests,” Lanham said. “The millions are relatively small compared to everything and it’s just sneaking in and trying to look like the rest of the crowd.”
The development has created a classic security problem for AI providers because aggressive controls can reduce abuse but can also make legitimate services more difficult for ordinary customers to access.
The National-Security Dimension
Anthropic’s concerns extend beyond commercial competition.
Klein said unauthorized access could allow actors that would otherwise have limited access to advanced AI systems to acquire capabilities they could use for surveillance, cyber operations, or potentially biological-weapons development.
He also pointed to what he described as a specific campaign by a China-based entity that used Anthropic’s technology for espionage at scale.
“There is a national security concern at play if malicious actors, bad actors who we don’t trust are gaining access to more capable models than they could have otherwise through the act of distillation,” Klein said.
The argument adds another layer to Washington’s increasingly contentious debate over advanced AI exports and access to frontier models. The Trump administration said in an April policy memorandum that distillation that undermines American research and proprietary information was “unacceptable” and said it would explore measures to hold foreign actors accountable.
The issue is particularly sensitive because the United States is simultaneously trying to maintain its lead in frontier AI while preventing advanced technology from reaching foreign actors that Washington considers security risks.
Thus, distillation is becoming one of the less visible but potentially consequential fronts in the global AI competition.
Training a frontier model requires enormous quantities of computing power, specialized chips, data, and engineering talent. Distillation can change the economics by allowing a smaller developer to learn from an existing model’s responses rather than independently reproducing the entire development process.
That does not necessarily mean a distilled model will replicate the original model’s full capabilities. The student model may reproduce specific reasoning patterns, coding abilities, or domain expertise while lacking other characteristics of the teacher model.
But even partial capability transfer can be commercially significant when the resulting system is cheaper, easier to customize, or subject to fewer restrictions. This creates an unusual incentive structure for frontier AI companies. Their models must be accessible enough to generate revenue and support developers, but every additional interaction can potentially provide information that a competitor could use to improve its own system.
Anthropic’s position is therefore not that competition itself is the problem.
“I think competition is great,” Klein said. “The concern here is if you are taking our model, distilling it through fraudulent means, creating millions of fake accounts using stolen credit cards and stolen infrastructure, to then produce a model that doesn’t have safeguards in place.”
Industry analysts expect that situation to become increasingly necessary as AI companies, regulators and governments attempt to establish where legitimate model development ends and unauthorized capability extraction begins.





