Distillation Wars
Anthropic sent a letter to the US Senate this week accusing Alibaba of running the largest distillation campaign ever documented against a frontier AI model. According to the letter, operators linked to Alibaba's Qwen AI lab used nearly 25,000 fraudulent accounts to make approximately 29 million exchanges with Claude between April and June [1].
That is not a typo. Twenty-nine million queries, targeted at the model's most commercially valuable capabilities: software engineering and agentic reasoning.
What is distillation, and why does it matter?
Distillation is the practice of feeding carefully constructed queries to a frontier AI model, collecting its responses, and using those responses to train a cheaper rival system that approximates the original's capabilities [2]. You do not need the model's weights. You do not need its training data. You just need API access and a lot of patience.
The economics are brutal for the defender. Training a frontier model costs hundreds of millions of dollars in compute alone. Distilling it costs whatever the API bills come to, which in this case was apparently less than the cost of pretending to be 25,000 separate users. Anthropic said the Alibaba campaign exceeded the combined volume of three earlier distillation campaigns by Chinese labs DeepSeek, MiniMax, and Moonshot AI, which together generated about 16 million exchanges through 24,000 accounts [3].
The timing is not subtle
The Alibaba campaign reportedly took place after a White House memo in April that flagged distillation as a national security concern and committed the government to sharing intelligence with US AI labs about foreign extraction campaigns [4]. Anthropic explicitly noted this in its letter, framing the campaign as a deliberate defiance of the administration's warnings.
Alibaba itself is already on defense in Washington. The Pentagon added the company to its Chinese military companies blacklist on June 8 [5]. Alibaba sued the Defense Department this week to get off that list, calling the designation baseless. The distillation accusation opens a second front, reframing Alibaba not just as a company with alleged military ties but as an active participant in what Anthropic calls the systematic theft of American AI capabilities.
Anthropic's awkward position
Here is where the story gets complicated. Anthropic needs the US government to crack down on Chinese labs extracting its technology. But Anthropic is simultaneously fighting the same government's decision to restrict its own products. Less than two weeks ago, Commerce Secretary Howard Lutnick signed an order blocking foreign nationals from accessing Anthropic's Fable 5 and Mythos 5 models, citing security concerns. Anthropic disabled both models to comply [6].
So Anthropic is asking the government for protection from foreign distillation while fighting the government's decision to restrict its model access. The letter to senators is an attempt to separate these issues, arguing that protecting US models from extraction and allowing those models to be deployed commercially are complementary goals, not contradictory ones.
Whether Washington agrees will shape the regulatory environment for the entire AI industry. Lawmakers are already moving. Senators Bill Hagerty and Andy Kim plan to introduce an amendment to defense legislation that would blacklist or sanction any Chinese firm found to be improperly accessing US AI model output. A bipartisan House bill is also in the works [7].
The IPO angle
Anthropic is now valued at $965 billion after a $65 billion Series H round and filed confidentially for an IPO this month [8]. The threat of cheaper imitation products from China that siphon away customers is a material risk for a company heading to public markets. US officials have estimated that unauthorised distillation costs Silicon Valley labs billions of dollars. Anthropic's calls for government support are, at least in part, a pitch to potential investors that the regulatory environment will protect its intellectual property.
What this means for the rest of us
If you build on AI APIs, this story has two takeaways. First, the models you depend on can disappear for reasons entirely outside your control, whether because of export controls or geopolitical disputes. Second, the gap between frontier models and their distilled copies is narrowing, and the companies building frontier models know it, which means expect more restrictions, more rate limits, and more aggressive detection of unusual API usage patterns.
The distillation war is just getting started. The question is whether it gets fought through legislation, through API lock-downs, or through something messier.
← All postsSources
- Bloomberg: "Anthropic accuses Alibaba of illicitly accessing its AI models." bloomberg.com, June 24, 2026. ^
- The Next Web: "Anthropic accuses Alibaba of running the largest distillation campaign yet against Claude." thenextweb.com, June 25, 2026. ^
- Ibid. ^
- The Next Web: "US White House flags AI model distillation as national security concern." thenextweb.com, April 2026. ^
- The Next Web: "Pentagon adds Alibaba to Chinese military companies blacklist." thenextweb.com, June 8, 2026. ^
- TechPolicy.Press: "Commerce eased its block on Anthropic's Mythos, but major questions remain." techpolicy.press, June 27, 2026. ^
- CNBC: "Anthropic accuses Alibaba of campaign to 'brazenly' and 'illicitly' extract AI capabilities." cnbc.com, June 24, 2026. ^
- The Next Web: "Anthropic files confidentially for IPO." thenextweb.com, June 2026. ^