Anthropic has publicly identified seven artificial intelligence laboratories based in China that it says conducted coordinated, large-scale efforts to extract capabilities from its Claude models through a technique known as model distillation. The disclosure, confirmed through The Hacker News, represents the most specific list of accused parties the company has released since it began tracking these activities. It adds significant detail to an ongoing story about how frontier AI capabilities are allegedly being copied without authorization.
What Is Model Distillation and Why Does It Matter?
Model distillation is a process by which a smaller or less capable AI model is trained to mimic the outputs of a larger, more powerful one. By feeding massive volumes of queries to a target model and using the responses as training data, a competing lab can bootstrap its own system's capabilities at a fraction of the cost of original research. Anthropic argues this crosses a clear line, both legally and ethically, when it is done without permission and at industrial scale. The seven labs named in this latest disclosure allegedly ran automated pipelines generating enormous query volumes, specifically designed to harvest Claude's reasoning and language capabilities. Details on the specific firms were reported through Anthropic's ongoing transparency efforts, which have grown more assertive in recent months.
Key Facts
- Seven China-based AI labs were identified by Anthropic as having conducted distillation attacks.
- The attacks used automated, high-volume query systems targeting Claude models.
- Distillation allows competitors to train rival models on Claude's outputs without building those capabilities from scratch.
- Anthropic has been tracking and publicly disclosing these incidents with increasing frequency.
- The company has taken enforcement actions including account terminations and platform bans.
The scale of the operations described by Anthropic goes well beyond opportunistic probing. According to the company, these were structured campaigns, with dedicated infrastructure built to query Claude repeatedly across different accounts and IP addresses. In one previously documented case, Alibaba was linked to some 25,000 fake accounts created specifically to extract Claude's outputs. That earlier episode helped set the context for the broader pattern now being described. Anthropic has framed these incidents collectively as an organized effort to shortcut the expensive and time-consuming work of building capable AI from the ground up.
These are not isolated incidents. They represent a systematic effort to use Claude as an unpaid research and development resource.Anthropic, via The Hacker News
Anthropic's Response and the Wider Implications
Anthropic has responded to these attacks through a combination of technical countermeasures, account enforcement, and public disclosure. The company has terminated accounts, worked with platform partners, and, in some cases, contacted the organizations directly. Earlier reporting identified Alibaba, Moonshot AI, and DeepSeek as among the firms involved in distillation activity, and this latest disclosure expands that list to seven named labs. The pattern suggests the problem has been wider than initially understood.
The competitive pressure driving these attacks is real. Building a frontier model requires billions of dollars and years of work. Distillation, if successful, can compress that timeline significantly. The issue has spread beyond corporate actors, with some distillation activity linked to underground markets and anonymous operators. That evolution complicates enforcement, since terminating known corporate accounts does not address the broader ecosystem that has grown around extracted model outputs.
For Anthropic, the decision to go public with specific names is a notable shift in strategy. Naming specific organizations raises the reputational stakes for those labs and signals that the company intends to document these incidents rather than handle them quietly. It also invites scrutiny of how Anthropic monitors usage patterns and what legal remedies it may pursue going forward. The company has not yet announced litigation against any of the seven labs, but the detailed record it is building could serve that purpose.
The broader question this episode raises is how AI developers protect their models when the core product is, by design, accessible via an API. Every legitimate user query looks similar to a distillation query at the infrastructure level. Distinguishing between the two at scale is a genuinely hard problem, and one that the entire industry is now watching Anthropic try to solve in public. How the company handles the next phase, whether through technical controls, legal action, or further disclosure, will likely shape norms across the sector for years to come.
“This is a wake-up call for every organisation relying on AI APIs: if state-linked labs are systematically extracting Claude's capabilities at industrial scale, your competitive advantage built on frontier models is far thinner than you think, and access controls need to be treated as seriously as any other security perimeter.”
Leon Tindemans, AI expert and entrepreneur specialising in Claude, Copilot and ChatGPT. Learn more with AI literacy training by TTM Communicatie.