Anthropic Details Distillation Attacks From Alibaba, Moonshot AI, and DeepSeek

A Thursday report alleges persistent model-copying campaigns by China-based labs that have escalated as competition intensified

Published: 2026-09-11 Category: Quick Take Sources: TechCrunch

The accusation, in public

Anthropic released a report on Thursday alleging persistent distillation attacks by China-based AI companies — naming Alibaba, Moonshot AI, and DeepSeek. Model distillation is the practice of using one model's outputs to train another, effectively copying its behavior without paying for the underlying research. Anthropic says these campaigns have escalated in recent months as competition in the space has intensified.

Distillation is not new, and it is not always nefarious. Open-weight models are explicitly designed to be fine-tuned and distilled. The controversy is when a closed, proprietary model is reverse-engineered through API calls and its distilled behavior shipped commercially — a gray zone that sits uneasily between copying and legitimate research, and one the frontier labs increasingly want policed.

Why now

The timing tracks the broader escalation in the US-China AI rivalry. Anthropic has been among the most vocal Western labs on the subject, and it has a business interest in drawing a bright line: if its flagship Claude models are being cheaply cloned by rivals, that undermines the moat its multi-billion-dollar training runs are meant to build. Publicly naming specific companies is a deliberate escalation — going from anonymous warnings to on-the-record accusations that invite legal and diplomatic consequences.

It also lands as the US government has signaled friendlier ground for AI labs on copyright and model protection, a political tailwind Anthropic may be relying on. Whether that backdrop turns this report into the basis for enforcement action, or just another salvo in the narrative wars, remains to be seen.

The uncomfortable middle

The harder truth is that distillation lives in a genuine gray zone. Enforcing against it requires proving intent and harm, and the tools used — querying an API, logging outputs, fine-tuning on them — are the same ones used in legitimate model research and security auditing. That makes it easy for either side to cast the other's behavior as either theft or standard practice. What Anthropic's report does is force the question into the open and put a clear set of named targets on the record, raising the cost of denial. Whether that translates into actual protection for frontier models, or just sharper corporate messaging, is the part that still has to be fought out.

Source: TechCrunch, "Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek" (Sept 10, 2026).