The Accusation

On February 23, 2026, Anthropic published a blog post that sent shockwaves through the AI industry. The company had detected what it called "industrial-scale distillation attacks" on its Claude models. The alleged perpetrators: three Chinese AI labs — DeepSeek, Moonshot AI, and MiniMax.

The numbers tell the story. According to Anthropic, the three companies created over 24,000 fraudulent accounts and generated more than 16 million exchanges with Claude, systematically extracting its capabilities to train their own models. DeepSeek was responsible for over 150,000 exchanges, Moonshot for more than 3.4 million, and MiniMax for over 13 million. Anthropic claimed the campaigns targeted Claude's most differentiated capabilities: agentic reasoning, tool use, and coding.

Anthropic's framing was unambiguous. This was not casual experimentation. This was "industrial-scale" theft, conducted through fraudulent accounts and proxy services, in violation of its terms of service and regional access restrictions. The company also raised national security concerns, arguing that illicitly distilled models could be redeployed without safety guardrails — potentially for malicious cyber operations or surveillance.

But the story is not that simple.

The Industry's Contradiction

Within hours of Anthropic's post, Elon Musk — never one to miss an opportunity — offered a characteristically blunt response. "How dare they steal what Anthropic stole from human programmers," he wrote on X. "Anthropic stole massive amounts of training data and paid billions in settlements for it. That is an undisputed fact."

Musk was referring to a September 2025 settlement in which Anthropic agreed to pay $1.5 billion to resolve a class-action lawsuit brought by authors who accused the company of using pirated books to train Claude. The settlement, which received final court approval in July 2026, covered approximately 500,000 copyrighted works. Anthropic had allegedly downloaded millions of pirated books from sites like LibGen and PiLiMi.

The contradiction is glaring. Anthropic trained its models on copyrighted material — often without permission — and now claims ownership over the outputs those models generate.

Counterpoint Research vice president Neil Shah put it bluntly: "Just as many of the foundation models have been built by indexing the vastness of the internet, often without the explicit consent of creators or piggybacking on other search engines' content, the newer entrants are in many instances going through the same routes of distillation and optimization."

The distinction between "training on public data" and "training on model outputs" is, legally speaking, largely undefined.

Silicon Valley's Own Copyright Reckoning

Anthropic is not alone in facing uncomfortable questions about how it acquired its training data.

On July 9, 2026, The New York Times, the New York Daily News, and 15 other media organizations filed a motion asking a federal court to sanction OpenAI. The publishers accused OpenAI of withholding evidence about how its AI systems are trained and used, violating court rules during the fact discovery phase of the copyright lawsuit.

The Times had sued OpenAI in late 2023, accusing the company of using "millions" of its articles without permission to train ChatGPT. Other publishers followed, and many of the cases were consolidated. In June 2026, more than 30 local newspaper publishers banded together to sue OpenAI and Microsoft, accusing them of the "systematic and willful theft of hundreds of thousands of copyrighted articles."

Even Anthropic's $1.5 billion settlement — which was finalized in July 2026 — came with uncomfortable admissions. The company had, according to court findings, downloaded and stored millions of pirated books.

The pattern is consistent: American AI companies built their models on vast datasets scraped from the public internet, often without permission. Now they are accusing others of doing the same thing — just one step removed.

The Distillation Debate

Distillation is not inherently controversial. It is a standard AI technique in which a smaller "student" model is trained on the outputs of a larger "teacher" model. Companies routinely use distillation to create cheaper, faster versions of their own models. Even Anthropic acknowledged this in its own report: "Distillation is a legitimate practice: AI labs use distillation to create smaller, cheaper models for their customers."

What Anthropic objected to was not distillation itself — but who was doing it.

As one Chinese media analysis noted, "Anthropic's logic is: distillation itself is innocent, but when Chinese companies do it, it becomes 'illegal theft'."

Skeptics have also questioned the technical plausibility of Anthropic's claims. AI researcher Nathan Lambert noted that even if the numbers were accurate, 150,000 exchanges — DeepSeek's alleged total — is "almost negligible in the scale of training a large language model." "It looks like they were just doing experiments with some scoring criteria and small-scale tests on sensitive queries," he wrote.

Microsoft CEO Satya Nadella recently criticized what he called the "double standard" of major AI labs: "Model providers claim fair use when training on public data, but then impose restrictive terms on distillation."

Hugging Face CEO Clem Delangue offered an even more pointed observation: "If distillation alone were enough to build good AI models, the U.S. would have many better open-source AIs. The reality is that China has very strong research teams, and they do AI in a much more open and collaborative way than the U.S."

The White House Escalation

The debate escalated in July 2026, when White House science and technology adviser Michael Kratsios publicly accused Moonshot AI of using distillation to develop its Kimi K3 model. Kratsios claimed that Moonshot had built an internal platform for large-scale distillation against U.S. models. He also alleged that Moonshot had acquired Nvidia GB300 servers and accessed them in Thailand, potentially violating U.S. export controls.

China's Assistant Foreign Minister Liu Bin responded at the World AI Conference in Shanghai: "Some countries hype up distillation" — and warned that such accusations are "misguided and counterproductive." He added that efforts to "belittle China's independent innovation capabilities by hyping the so-called distillation concept are entirely malicious."

The Chinese embassy in Washington called the allegations "completely unfounded."

Rules for Thee, Not for Me

The distillation controversy is not about right and wrong. It is about who gets to define the rules.

Silicon Valley companies built their empires by scraping the public internet — often without permission, often in defiance of copyright law. They argued that training AI on publicly available information is comparable to human learning. That argument is now being used against them.

When Anthropic accuses Chinese companies of "stealing" its model outputs, it is deploying the same logic that publishers have used against Anthropic. The difference is that Anthropic is on the other side of the argument now.

The pattern is familiar. Those who get to the table first write the rules. Those who arrive later are expected to follow them. When later arrivals find ways to compete, the rule-makers accuse them of cheating.

As one industry observer put it: "When OpenAI, Google, and Anthropic themselves are all using large-scale, unlicensed data to train their models, their accusations of 'distillation' look more like a defensive reaction to protect vested interests."

The question is not whether distillation is theft. The question is whether the same standards apply to everyone. And on that question, the record is not encouraging.

📊 See both sides clearly

This isn't about taking sides — it's about understanding how the rules get written. apick.net covers the tech story behind the headlines, every week.

Read more analysis →

📎 Limitations & Caveats:
This article covers events through July 23, 2026. The legal proceedings against OpenAI and Anthropic are ongoing, and new developments may emerge after publication. The specific claims about distillation attacks are based on Anthropic's own disclosures and have not been independently verified by third-party auditors. Chinese companies named in the article have denied the allegations.

Sources:
Anthropic official blog post, "Detecting and preventing distillation attacks" (February 23, 2026) — verified; ET Edge Insights (February 25, 2026); InfoWorld (February 24, 2026); eWEEK (February 24, 2026); NYU Shanghai RITS (February 25, 2026); The New York Times (July 9, 2026); Bloomberg (July 18, 2026); The Next Web (July 22, 2026).

Disclaimer:
The analysis above is based on publicly available data as of July 23, 2026. All claims regarding distillation attacks, legal settlements, and government statements are sourced from the respective companies' official publications and major news outlets. I am not affiliated with Anthropic, DeepSeek, Moonshot AI, MiniMax, or any of the companies mentioned. For the most current information, please visit the official sources listed above.