Anthropic has published a detailed report naming Alibaba, Moonshot AI, and DeepSeek as actors engaged in persistent distillation campaigns targeting its Claude models. Distillation attacks involve querying a proprietary model at scale to generate training data, effectively transferring its capabilities into a competitor's system without licensing or consent.
This matters because distillation is one of the most cost-effective ways to bootstrap a competitive model. Rather than investing billions in original research and compute, an attacker can systematically mine outputs from a frontier model and use them to fine-tune a cheaper alternative — essentially free-riding on another company's R&D.

According to Anthropic, these campaigns have grown more aggressive in recent months, tracking closely with the broader acceleration of AI competition. The implication is that as the performance gap between frontier and second-tier models narrows, the incentive to close it through distillation rather than original training increases.
For builders and technical teams, this report is a useful reminder that API access to powerful models carries terms of service that explicitly prohibit using outputs to train competing systems. If you're building on top of any major model provider, review those clauses carefully — enforcement is clearly becoming a priority.
Anthropics's willingness to name specific companies publicly also signals a shift toward harder enforcement postures across the industry. Expect other frontier labs to follow with similar disclosures, and expect API usage monitoring and anomaly detection to become standard practice on the provider side.
