虎嗅

"The founder of China's large-scale AI models is politically naive."

原文:中国大模型创始人在政治上很愚蠢

In-Depth Analysis: The Capital, Political, and Technological Gamble Behind Anthropic's Allegations of "Distillation" by Chinese Large Models

Hello everyone, I'm your financial journalist. Today, we're talking about a big story that's caused a stir in both the tech and financial communities: Anthropic (the parent company of Claude) has accused several leading Chinese large-model companies (such as Alibaba, DeepSeek, and Moon's Dark Side) of stealing their model capabilities through a process called "distillation" and leaking sensitive data.

This article is quite long and contains a lot of information. To help you understand this complex situation easily, I've broken it down into a core summary and a detailed analysis from five different perspectives. We'll use plain language to explain the ins and outs, the involved interests, and the potential impacts.

---

**Core Content Summary**

In short, Anthropic released a 154-page report claiming that Chinese large-model companies have purchased fake accounts, used unauthorized intermediaries, and extensively called Claude's API to obtain its "CoT" (the model's reasoning process) for training their own models. They also allegedly silently transferred sensitive data of real users overseas.

But this is more than just a technical accusation; it's a carefully orchestrated "agenda trap":

1. Blurred Definitions: Anthropic has bundled three fundamentally different issues—breach of API terms, fraud (creation of fake accounts), and data leakage (cross-border transmission)—under the term "distillation attack."

2. Political Pressure: From the technical exposure to a White House memorandum, to Senate hearings and threats of sanctions, the timing is precisely coordinated to push for U.S. legislation that would make it illegal to use competitor outputs for model training, thereby hindering China's AI development.

3. Double Standards: Anthropic itself has previously paid huge settlements for copyright violations, and its models have had identity confusion issues, yet it tries to present itself as a "victim" with a moral high ground.

4. Industry Shift: This incident accelerates the separation of "technical capability" from "trustworthiness." In the future, the valuation of large models will not only depend on performance but also on data compliance and risk isolation capabilities.

5. Shift in Pricing Power: Chinese large models once enjoyed high valuations due to "geopolitical premiums," but this advantage is disappearing. The market is re-evaluating their technical independence, and the valuation framework will shift from a "global AGI vision" to a focus on "local infrastructure providers."

---

**Dimension One: Anthropic's "Agenda Trap" – Bundling Three Issues into One**

The cleverest part of Anthropic's report is not whether its accusations are 100% true, but how it defines these issues. It's playing a classic game of agenda setting.

  • Misuse of Terms: The report mixes three different things:
  • Using API outputs to train competitor models is a breach of contract. Anthropic's terms prohibit using its outputs for this purpose. It's like buying KFC chicken and using it to teach someone to cook chicken; it's a civil dispute at best, resulting in fines or account bans.
  • Creating fake accounts to bypass restrictions is fraud. Using stolen credit cards and fake identities to create thousands of accounts is illegal, but it's a criminal act unrelated to the "distillation" technology itself.
  • Silently transferring user data is a combination of consumer fraud and data violations. Sending users' private information to other servers or third parties is a serious violation of privacy and security.

Where's the Trap?

Anthropic uses the neutral technical term "distillation attack" to bundle these three issues.

  • If you argue that "distillation is a common practice in the industry," you're implying they are the same thing, and you're also accepting that "distillation" has a negative connotation.
  • If you only focus on the technology, you ignore the serious legal and data breaches.
  • The Smart Response from the Ministry of Commerce: Instead of arguing about whether distillation occurred, China's Ministry of Commerce focused on the definition of the term, pointing out that it's a neutral technical method used globally, including by American companies. This directly undermines Anthropic's moral high ground.
  • The Timing Reveals True Intentions:

Anthropic's actions are well-paced:

  • February: Blog post with direct accusations (technical exposure).
  • April: White House memorandum (political intervention).
  • June: Letter to the Senate (legislative pressure).
  • July: Threat of sanctions (economic pressure).
  • September: Release of a detailed 154-page report (solid evidence).

A company that makes money from selling APIs would have been content with sending a legal notice. Instead, it went to Congress, claiming that someone stole its models, with the real goal of pushing for legislation that would make it illegal to use American model outputs for training Chinese models. If this law passes, not only the accused companies but also all companies that rely on open-source and distillation technologies will be affected.

  • The Embarrassing Double Standard:

Anthropic itself has a history of paying large settlements for copyright violations, and its models have made identity confusion mistakes. Yet it tries to portray itself as a "victim" with a moral advantage.

---

**Dimension Two: Chinese Founders' "Political Blind Spot" – Why Did Smart People Make Such Mistakes?**

Many might wonder: Aren't the Chinese the most politically astute and strategic? Why did so many top tech experts fail in such a sensitive matter?

  • Mismatch in Skills: We often talk about "political understanding" in the context of domestic policy coordination, resource allocation, and interpersonal relationships in China.

This incident requires a different set of skills: understanding how the U.S. Congress, intelligence agencies, and IPO narratives work together.

In the U.S., a commercial API dispute can quickly escalate into a "national security issue."

This "weaponization of cross-border issues" is something Chinese large-model founders generally lack. They see themselves as participants in a global tech race, but their American competitors see them as part of a national strategic game.

  • Short-Sightedness in the Mechanism: This isn't just about individual stupidity; it's a systemic issue in the venture capital market.
  • Short Venture Capital Terms: VC funds have a lifespan of 5-7 years, focusing on short-term returns. Long-term geopolitical risks are not part of their KPIs.
  • Ranking Anxiety: The 2023-2025 large-model arms race is focused on performance metrics. High computing costs and rapid spending drive investment, with engineers and founders focusing on improving model performance.
  • Marginalized Risk Teams: Compliance and risk management teams are often overlooked. Tail risks (low probability, high impact) are systematically underestimated. The worst-case scenario was seen as an account ban, not a national security issue.
  • Engineering Blind Spot: Engineers focus on creating high-quality thought processes but don't evaluate the input side: What real users are sending? Some may be transmitting code, internal secrets, or surveillance footage.
  • Misaligned Benefits and Risks: The desire for training data leads to ignoring serious data security risks. This is an engineering flaw, not a moral issue, but the consequences can be catastrophic.
  • What Needs to Be Learned:
  • Compliance is a structural issue, not just a legal one: Simply issuing prohibitions is ineffective; risks must be addressed at the code level.
  • Avoid relying on unauthorized intermediaries: Each link in the chain (fake accounts, intermediaries, APIs) can become evidence against you.
  • Redefine Risk: The real question is whether you can prove your innocence if things go public. If not, don't engage in such practices.

---

**Dimension Three: Zhang Yiming's "Lesson Learned" – The Legacy of TikTok**

In this incident, ByteDance stood out with a clear stance. Zhang Yiming publicly stated that they would not engage in distillation, even if it meant temporary lagging behind.

  • Why Didn't ByteDance Make the Mistake?

It's not that Zhang Yiming is smarter than others; TikTok has paid a heavy price for similar issues: data localization, algorithm retraining, board localization, and security audits.

ByteDance is wary of data cross-border transfers and algorithm blackboxes. When developing its large models, it realized that using Claude's APIs would be similar to TikTok's past mistakes.

  • The Value of Organizational Memory: Other companies lack this experience, so their assumptions about risks are less credible. ByteDance has strict policies against distillation and enhanced API restrictions.
  • Costs and Benefits: ByteDance's large language models perform poorly, and employees complain about the lag, but its video generation model, Seedance, is strong globally. This "delayed satisfaction" is a result of lessons learned from TikTok's crisis.

---

**Dimension Four: The Silently Compromising Intermediate Parties**

In this entire chain, the most problematic and overlooked part are the intermediaries.

  • What are intermediaries?

They are gray-market entities that help Chinese companies obtain more Anthropic API quotas or avoid tracking.

They create fake accounts and use stolen credentials to bypass restrictions, storing and selling user data to labs.

  • Irony in Technology: Intermediaries have control over routing traffic. They may use cheaper models instead of Claude, leading to mixed results in the trained models.
  • Data Disappearance: User data may end up with other services, regardless of the agreements.
  • Regulatory Action Approaching: National security authorities are investigating AI intermediaries, and some have been criminally charged.

Legal platforms must differentiate themselves from illegal activities.

  • New Business Models: This incident will change the data security business, shifting the pricing logic.
  • Data Security as a Business: It's no longer just an optional expense; it's a prerequisite for market entry.
  • Changing Regulations: Chinese laws require proof of data integrity. New business models will emerge, such as selling security solutions based on risk exposure.

---

**Dimension Five: The Shift in Data Security and Pricing Power**

This incident is a turning point for the industry, changing two core aspects: data security business models and the valuation of Chinese large models.

  • Data Security: It's no longer just an optional expense; it's a prerequisite for market entry.
  • Valuation Logic: The market no longer values only performance but also data compliance.
  • Value Reconfiguration: Past valuations were based on American benchmarks and geopolitical premiums. Now, the market considers both cash flow and data security.
  • New Business Models: Companies selling security solutions or access based on risk will thrive.
  • The Dark Moment for Chinese AI?

Some see this as a dark moment, but I see it as a shift in pricing power.

  • Past Valuation Logic: Based on American models and domestic peers, with geopolitical premiums.
  • Current Crisis: Anthropic's accusations target these premiums. If the market believes high-level reasoning comes from unauthorized sources, the illusion of a unique path is shattered.
  • Valuation Shift: The market values cash flow and data security, not just revenue.
  • Future Paths: Valuations will shift from global AGI to local AI infrastructure providers.

China has a global advantage in token usage and low computing costs. Open-source criticism may actually accelerate its globalization.

---

**Conclusion**

Anthropic's report exposes vulnerabilities in China's large-model industry. It shows that technical neutrality doesn't exempt companies from the risks associated with their operations. Engineers focus on functionality, but founders must consider the broader impacts.

For Chinese companies, compliance is no longer a cost but an asset. For investors, valuation depends on compliance. For the industry as a whole, proving data integrity will be key to entering new markets.

This incident marks a transition from chaotic growth to mature compliance. It's a painful process, but necessary for China's AI to mature.