The fight over who gets to learn from the world’s most advanced artificial intelligence systems — and on what terms — is rapidly hardening from a commercial dispute into a geopolitical one.

Anthropic, the maker of the Claude chatbot, has accused several Chinese companies of using vast numbers of fake accounts and technical workarounds to siphon off Claude’s responses and use them to improve rival models. What might once have sounded like a quarrel over terms of service is now being cast by Washington as a matter of national security, with U.S. agencies warning this week that China-based firms are carrying out “industrial-scale” distillation of American frontier A.I.

The argument has widened just as quickly as it has sharpened. Chinese officials have rejected the allegations as baseless and warned against using them to justify pressure on Chinese technology companies. In Silicon Valley, some investors and startup leaders are also pushing back on the idea that distillation is an urgent strategic crisis, arguing that copying model behavior through outputs may be difficult to police and less decisive than leading A.I. companies contend.

And in a telling twist, a Chinese robotics startup backed by Ant has now tried to turn the accusation around, publicly suggesting that OpenAI borrowed from its ideas as it unveiled a new robotics model this week.

A technical practice becomes a security flashpoint

Distillation is a common technique in artificial intelligence. In broad terms, developers use the outputs of a larger, more capable model to train a smaller or cheaper one. The process can be legitimate and routine in research and product development.

What Anthropic says happened, however, was something different: not ordinary experimentation, but a large-scale effort to extract the behavior of its systems through deception.

The company has said that China-based labs including DeepSeek, Moonshot and MiniMax generated more than 16 million Claude exchanges using roughly 24,000 fraudulent accounts. Reuters reported in June that Anthropic separately accused operators linked to Alibaba of generating 28.8 million Claude exchanges through nearly 25,000 fraudulent accounts. Anthropic has said some actors used proxy infrastructure and access from unsupported regions to evade restrictions.

Those claims gained new force on Sept. 8, when the National Security Agency, the Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency issued a joint advisory saying that China-based A.I. companies were engaging in “industrial-scale” distillation of U.S. frontier models.

That intervention matters because it signals that the U.S. government is no longer treating the issue primarily as a private dispute between companies. Instead, officials are linking model-copying accusations to broader concerns about military modernization, cyber capabilities and surveillance — and to the possibility that Chinese firms could narrow the performance gap with American leaders without making equivalent investments in computing power or research.

The evidence question

Even so, major uncertainties remain.

Anthropic’s allegations are detailed and serious, but the underlying technical evidence has not been fully made public. It is also unclear how much of the rapid progress by Chinese A.I. companies can actually be attributed to prohibited extraction of model outputs, rather than to independent research, open-weight models, synthetic data techniques or ordinary competitive catch-up.

That ambiguity has helped fuel a broader debate over how actionable the problem really is. Anthropic argues that illicit distillation can strip away safeguards built into leading systems and reduce the effectiveness of export controls designed to limit access to advanced chips and models. Critics counter that once a model is available through an interface, some degree of imitation is nearly inevitable, and that the competitive landscape may be shaped more by deployment, cost and openness than by any single company’s guardrails.

Those competing views were on display on Thursday, when Garry Tan, the chief executive of Y Combinator, said regulators should “do nothing” about alleged Chinese distillation and instead focus on maintaining competition between open-weight systems and tightly controlled frontier models. His comments reflected a strand of opinion in the tech industry that sees the alarm over distillation as overstated, or at least as secondary to bigger market questions.

China rejects the accusations

The timing is especially delicate. Reuters reported last week that the United States and China were preparing for an A.I.-safety dialogue in mid-September, even as frictions over model copying and technology controls intensified.

Beijing has rejected the latest accusations and warned against using them as a pretext to suppress Chinese A.I. companies. That response fits a broader pattern in the technology rivalry between the two countries, in which export controls, investment restrictions and security allegations increasingly overlap with commercial competition.

If Washington moves beyond warnings — for example through sanctions, tighter cloud-enforcement rules or expanded export controls — the distillation dispute could become another major front in the U.S.-China contest over advanced computing.

A rhetorical boomerang

The debate also spilled into robotics this week, underscoring how elastic the term “distillation” has become.

On Sept. 10, JoyIn, a humanoid robotics startup backed by Ant, released its Aether model. Around the launch, the company’s chief executive published comments in Chinese suggesting that OpenAI had effectively “distilled” JoyIn’s ideas. CNBC reported that the claims had not been independently verified and that OpenAI had not responded.

The episode did not mirror Anthropic’s specific allegations of mass extraction through fraudulent accounts. Instead, it suggested something broader and more slippery: that “distillation” is increasingly being used in public fights not only to describe training on model outputs, but also to imply borrowing of research framing, architecture choices or product concepts.

That rhetorical shift matters because it makes an already technical dispute harder to define. In one sense, the argument is about measurable behavior — millions of prompts, suspicious account patterns, proxy networks and output replication. In another, it is becoming a more generalized accusation about intellectual influence in a field where ideas move quickly, many papers are public and systems often converge on similar designs.

Why this matters now

For all the uncertainty, the stakes are rising because the frontier of A.I. is no longer just a race for better chatbots. The companies involved are building systems that could shape software development, cyberoperations, scientific research and defense applications. If one side can cheaply reproduce the capabilities of another through output extraction, that could compress years of advantage.

But there is still no consensus on whether the threat is technically containable, strategically decisive or even fully provable from the outside. That lack of agreement is now part of the story.

Anthropic and U.S. officials are framing the issue as an urgent challenge to both commercial rights and national security. Chinese officials call it a political weapon. Some figures in Silicon Valley see it as a problem that may be impossible to stop and perhaps not worth overregulating. And startups, in the United States and China alike, are increasingly borrowing the language of copying and distillation to wage their own public battles.

What began as a dispute over chatbot outputs is turning into a larger test of how the A.I. superpowers define theft, competition and technological advantage in an industry where imitation has always been part of the game — but where the consequences of falling behind are now far greater.

Sources

Further reading and reporting used to add context: