Anthropic disclosed Thursday that it disrupted large-scale unauthorized distillation attacks against its Claude AI model originating from seven Chinese AI laboratories. The companies identified include Alibaba, Moonshot, DeepSeek, Zhipu (Z.ai), and MiniMax, among others.
The attacks involved what researchers call knowledge distillation, a machine learning technique where a larger AI model teaches a smaller one by extracting and transferring learned patterns. While distillation serves legitimate purposes in AI development, Anthropic determined these operations were conducted without authorization and at industrial scale, representing a systematic effort to extract Claude's capabilities into competing models.
Knowledge distillation works by having a large trained model, the "teacher," guide a smaller "student" model through pattern matching and inference. The student learns to replicate the teacher's behavior without accessing the underlying code or weights. This approach reduces computational requirements and allows smaller models to perform tasks comparable to larger ones. In legitimate contexts, companies use distillation on their own models or with explicit permission. The unauthorized extraction of proprietary model knowledge constitutes intellectual property theft and violates service terms.
Anthropic's detection identified the attacks through API usage patterns consistent with systematic data harvesting rather than normal user interaction. The affected organizations likely submitted thousands or millions of queries to Claude's API, carefully designed to extract behavioral patterns, reasoning steps, and response characteristics. These extracted patterns then fed into competitor models to improve their performance without the computational investment or training data Anthropic invested.
The discovery reflects mounting tensions in AI development around model security and competitive advantage. Large language models represent billion-dollar investments in compute, training data, and research talent. Knowledge distillation attacks allow competitors to capture value from these investments with minimal legitimate expenses. Anthropic's action follows similar incidents across the AI industry where organizations attempted to reverse-engineer or extract capabilities from commercial models.
The specific targeting of Chinese labs carries geopolitical implications. China has positioned itself as a global AI competitor, and many of its major technology companies, including Alibaba and others on this list, actively develop large language models. Distillation attacks represent a cost-effective route to competitive performance, particularly for organizations with substantial capital but facing computational constraints or data limitations.
Anthropic disrupted these attacks by blocking API access from identified accounts and infrastructure. The company did not announce legal action against the targeted organizations, though such cases raise complex jurisdictional questions. U.S. law provides some intellectual property protections for AI models, but enforcement against foreign entities remains challenging and often depends on bilateral agreements.
This incident raises questions about API security monitoring and detection capabilities across AI providers. Claude's API operates at scale, processing legitimate queries from thousands of organizations globally. Distinguishing between normal high-volume use and orchestrated extraction campaigns requires sophisticated behavioral analysis and threat intelligence.
Anthropic's disclosure serves as notice that systematic model extraction attempts will face detection and enforcement action. Other AI companies operating public APIs, including OpenAI and Google, likely face similar extraction pressure. The incident underscores that as AI models become more commercially valuable, protecting proprietary capabilities becomes central to competitive strategy.
