
Head of threat intelligence Jacob Klein claims foreign actors are using fraudulent means to steal Claude's capabilities for competing models.
AI-generated summary
Distillation is a process where a model developer uses output from another company's technology to create a competitive offering. Anthropic is currently a private company valued at nearly $1 trillion.
Anthropic's head of threat intelligence, Jacob Klein, says his company welcomes competition. But what's coming out of the Chinese market, he says, is something much closer to theft.
Foreign adversaries, Klein says, are accessing Anthropic's Claude models — a process known as distillation — to train competing technology and sell copycat versions at a lower price. While distillation can be done legally, Klein says that's not what's happening here.
"There's an entire illicit ecosystem to try to gain access to Claude and other models," Klein told CNBC. "This ecosystem goes through any means necessary to evade our controls, so they can spin up accounts at extreme scale."
Distillation has become a controversial topic across the artificial intelligence landscape. Depending on how it's conducted, the practice can allow a model developer to use the output from another company's technology to create a competitive offering at a tiny fraction of the cost. In the U.S., some factions in the tech sector have urged policymakers to steer clear of regulations so that the best and most cost-effective AI can win, while others are lobbying for a crackdown on what they see as theft of intellectual property.
In an April memo, the Trump administration wrote distillation that undermines American research and proprietary information is "unacceptable," and said it would explore "a range of measures to hold foreign actors accountable."
The threat is intensifying at a pivotal moment for Anthropic. The 5-year-old company has soared to a private market valuation of close to $1 trillion and is expected to go public as soon as October, CNBC has reported.
Anthropic is singling out Chinese AI lab Moonshot AI as one of the companies it says is ripping off its technology. Moonshot's Kimi K3 model took the tech world by storm in July with its cheaper, frontier-level AI offering. It's been widely adopted in Silicon Valley, thanks in part to its lower price point and ability for companies to tailor it more easily.
Klein said Kimi K3 was illegally trained off the newest version of Claude.
"We've seen a fair amount of this from China," Klein said. "This is something that the industry writ large is dealing with."
Earlier this year, Anthropic alleged Moonshot and two other Chinese AI labs – DeepSeek and MiniMax – distilled its frontier AI models. Anthropic has also accused Alibaba, which makes the Qwen family of models, of conducting a massive "distillation attack" to illegally capture capabilities from Claude. OpenAI and Google have both published reports on distillation and claim they're fighting the same issue.
Alibaba, DeepSeek, Moonshot and MiniMax didn't respond to requests for comment.
'Fraudulent means'
Cybersecurity experts told CNBC that, in addition to China, the threat is also coming from countries like Iran, Russia and North Korea, where use of Claude, Google's Gemini and OpenAI's ChatGPT are restricted by the companies due to sanctions.
Klein said many labs in those regions "go through illicit means and fraudulent means to try to gain access to a model."
One way people are getting around those restrictions is by turning to the dark web, where they can find marketplaces of stolen credit card information and compromised AI accounts. Klein said companies like Moonshot are "spinning up tens of thousands, if not hundreds of thousands of fraudulent accounts."
Once they've accessed Anthropic's systems, they're able to ask the models questions and collect responses, which they can use to train their own model, often called the student, Klein said.
A clear sign that distillation is taking place is that a user could be asking thousands of questions, rather than dozens and potentially even creating thousands of accounts to do the same, producing a whack-a-mole scenario for the AI labs, Klein said.
"It's very hard to fully stop this as a problem, but I think slowing it down is good and worthwhile," Klein said, adding that foreign companies are able to use the technology with few guardrails.
He pointed to fears like surveillance and possible use in a biological weapons program, and noted what he described as a specific campaign from a China-based entity that was conducting espionage at scale using Anthropic's technology.
"There is a national security concern at play if malicious actors, bad actors who we don't trust are gaining access to a more capable models than they could have otherwise through the act of distillation."
Travis Lanham, technology chief at cybersecurity firm Armadin and a former Google engineer, said bad actors often go undetected because AI companies are under pressure to make their platforms as accessible as possible as they race against the competition.
"These companies are serving billions of requests," Lanham said, about the big AI labs. "The millions are relatively small compared to everything and it's just sneaking in and trying to look like the rest of the crowd."
Klein acknowledges that, for Anthropic, widespread competition is to be expected and that there are legal methods of distillation. That generally means gaining permissions and following the law on matters like IP and export controls.
"I think competition is great," Klein said. "The concern here is if you are taking our model, distilling it through fraudulent means, creating millions of fake accounts using stolen credit cards and stolen infrastructure, to then produce a model that doesn't have safeguards in place."

TCL has unveiled its P80 smartphone series, headlined by the P80 Ultra. It is the first device to combine a 6.83-inch 120Hz OLED display with Nxtpaper anti-glare technology, allowing users to toggle between a standard flagship mode and a power-efficient e-reader mode.
2026中国国际福祉博览会暨中国国际康复博览会在北京国家会议中心开幕。本届博览会展览面积约2.8万平方米,吸引全球504家企业参展,首次设立脑机接口专区,并发布61款创新辅具产品,旨在推动康复辅助器具产业发展。

蔡司半导体部门负责人罗蒙德表示,中国研发EUV光刻机可能需15年。他认为出口管制可能加速中国创新,并强调蔡司在光学技术上仍保持领先地位。

تستعرض شركة «المناعي لتكنولوجيا المعلومات» و«مجموعة stc» حلولاً رقمية متطورة في معرض «ليب 2026» بالرياض لدعم رؤية 2030، بالتزامن مع ترويج فندق فورسيزونز الإسكندرية لفلله الشاطئية كوجهة عائلية للزوار السعوديين والخليجيين.
上海首个“信息安全实验室”于9月3日在奉贤区揭牌,将提供安全检测与应急响应服务。同时,奉贤区推出“有数”计划,旨在构建区域数据流通生态,解决中小企业面临的安全防护困境及数据孤岛问题,推动区域数字化转型。

A study by Chinese military researchers reveals that China's military AI models lag behind foreign equivalents and focus primarily on support functions rather than combat.