Summary of Key Points
The American AI company Anthropic has accused an Alibaba-related entity of using 25,000 fake accounts to interact with its Claude model 28.8 million times, describing this as the “largest model distillation attack” to date, which caused Alibaba’s ADR (Average Daily Return) to drop by 2%. However, Anthropic itself has been sued in the past for using copyrighted books and music to train its models. Now, it is prohibiting others from “learning” from its own models. This is not just a simple intellectual property dispute; rather, it is part of Anthropics lobbying efforts with the U.S. Congress to push for the regulation of model capabilities under national security laws. Essentially, it reflects the strategy of leading American companies in the AI race to maintain their advantages by defining the rules.
1. Anthropic’s Double Standards: Stealing Data Itself, but Not Allowing Others to Learn from Its Models?
Anthropics accuses others of “stealing” its model capabilities, yet it has a own dark history. Last year, it was sued for downloading millions of copyrighted books from pirated websites to train Claude and later settled the lawsuit by paying damages. It has also been accused by music publishers and Reddit of using unauthorized content to train its models. In other words, when AI was still in its early stages of development, Anthropic, like other companies, exploited publicly available global data as a free resource. Now that it has become a leader in the industry, it suddenly claims that its model outputs cannot be used by others—similar to how people once competed to mine gold without clear boundaries, only to claim ownership once a few succeeded.
2. The Accusations Are Not for Litigation, but to Provide Legislative Material
Anthropics’ letter is not addressed to courts or the media; instead, it is sent to the chairman of the Senate Banking Committee and senior senators, just in advance of an AI hearing. At this time, the White House has ordered Anthropic to prohibit foreigners from using its latest models, and lawmakers are drafting legislation to sanction Chinese companies that use American-made AI models. By making these accusations, Anthropics is providing evidence to support these policies, arguing that Chinese companies are leveraging its models to gain advanced capabilities and need to be regulated. Its real goal is to incorporate model capabilities into the national security framework, which could lead to controls over not only chips but also model weights, API access, and even the content produced by these models.
3. Model Distillation: A Common Industry Practice, Yet Considered a “Attack”?
“Model distillation” sounds complex, but it simply involves using the outputs of larger models to train smaller ones. For example, Claude can be seen as a top student, and Alibaba’s model as a student using Claude’s answers to improve its own performance. This technique has been around for over two decades, and companies like Anthropic, OpenAI, Google, and Meta all use it to create more efficient models. The difference lies in how it is perceived: when used internally, it’s called “technical optimization”; when applied to others’ models, it’s labeled a “security threat.” This is not about technology per se, but about the dominant companies trying to define what constitutes innovation and infringement.
4. New Tactics in the U.S. AI Race: From Chip Embargoes to Model Capability Regulation
In the past, the U.S. tried to restrict China’s AI capabilities through chip exports. However, Chinese models like DeepSeek and Tongyi Qianwen have still made significant progress. Therefore, the U.S. is shifting its approach by focusing on regulating model capabilities as a strategic resource. Anthropics’ letter supports this strategy, proposing that model outputs should be classified as “non-learnable resources” to prevent Chinese companies from accessing American-made models through APIs or interactions. This could lead to two separate AI ecosystems: one dominated by the U.S. and another outside its control, each using different chips, models, and standards that are not interoperable.
5. A Warning for Chinese AI: The Era of API Benefits May Be Ending, and Independent Development Is Imperative
This development serves as a warning to Chinese AI companies. In the past, they could quickly improve their capabilities by using American model APIs, but this path may now be blocked. Today it’s Claude; tomorrow it could be ChatGPT, and who knows what American models might become unavailable in the future. China must accelerate its independent research and development, covering all aspects from model training to computing power and data acquisition, to avoid being constrained in the same way as with chips. Anthropics’ letter is like a starting gun, signaling that the U.S. is establishing new rules, and China will have to find its own solutions.