On February 24, the parent company of Claude, Anthropic, published a highly flawed manifesto that escalated its accusations against three Chinese AI companies — DeepSeek, Moonshot, and MiniMax — to the level of national security. A close reading shows that the article was calibrated to please Washington just enough.
According to Anthropic, the three companies used roughly 24,000 fake accounts to generate more than 16 million interactions with Claude, with the goal of “illegally extracting” its capabilities to train their own models.
Anthropic labels this behavior “distillation attacks,” elevating it to a national-security concern. It claims the actions not only violated its terms of service but also “reinforce the rationale for export controls,” and could even help “deploy frontier AI for offensive cyber operations, disinformation campaigns, and mass surveillance.”
The post further asserts that through IP correlations, request metadata, and infrastructure indicators, Anthropic attributed the activity to specific labs — and even individual researchers — with “high confidence.”
At first glance, the technical evidence appears solid. On closer inspection, however, it does not hold up. For the most technically advanced AI company to publish such a porous document suggests intent. Read carefully, and it becomes clear that Anthropic is not trying to persuade the technical community, but Washington. The technical ambiguities are part of the performance.

Less Than 1% DeepSeek, 100% of the Headline
Start with the numbers. The scale of distillation varied dramatically across the three companies: MiniMax accounted for more than 13 million interactions; Moonshot for over 3.4 million; DeepSeek for only about 150,000. In other words, DeepSeek represented less than 1% of the total 16 million interactions.
Yet in Anthropic’s blog title, its social posts, and nearly all subsequent English-language media coverage, the ordering is consistently “DeepSeek, Moonshot, and MiniMax.”
Anthropic’s descriptions are equally telling. MiniMax carried out the largest-scale extraction and showed the most adaptive strategy, redirecting nearly half of its traffic to Anthropic’s new system within 24 hours of a model release, focusing on programming and tool-use capabilities. Moonshot’s efforts were the most technically ambitious, targeting agent reasoning, programming, and computer vision, and later attempting to extract and reconstruct Claude’s reasoning traces.
By contrast, DeepSeek’s 150,000 interactions are technically negligible — yet Anthropic devotes the most narrative attention to it. Why? Because DeepSeek contains the details most legible to Washington’s threat perception.

Anthropic orders the companies by political salience in Washington. Since early 2025, DeepSeek has become one of the most symbolic names in U.S. AI policy debates, standing in for export-control controversies, anxiety over U.S.–China AI competition, and the core question of whether “Chinese AI truly relies only on indigenous innovation.”
Putting DeepSeek first automatically activates this entire political narrative framework. The details Anthropic singles out — such as “safety alternative responses” — are of minimal technical significance but precisely calibrated to hit geopolitical nerve endings. In this, Anthropic knows exactly what it’s doing.
“Distillation Attacks”: A Weaponized Term
Knowledge distillation is a mature and widely used machine-learning technique, dating back to research by Rich Caruana and colleagues at Cornell University. The core idea is to train a smaller “student” model using outputs from a larger “teacher” model. Every major AI lab uses distillation. Anthropic itself admits that “frontier AI labs regularly distill their own models to offer smaller, cheaper versions to customers.”
Using a competitor’s API outputs to train models is an open secret in the industry. When DeepSeek released its R1 model in early 2025, Databricks CEO Ali Ghodsi stated plainly that distillation is “extremely powerful, extremely cheap, and available to anyone.”
Just two weeks earlier, Google’s threat-intelligence team reported that in 2025 it had “identified and disrupted model extraction activities by researchers and private companies around the world.” This is not unique to Anthropic — it is a structural reality of the entire industry.
Developers have even repeatedly demonstrated traces of DeepSeek distillation appearing within Anthropic model interactions.
Did these actions violate terms of service? Yes. Not just Anthropic’s — all major providers now explicitly prohibit using their services to train competing AI models.

But it is crucial to note that AI outputs are not protected by copyright under U.S. law. In January 2025, the U.S. Copyright Office reaffirmed that copyright protection requires human authorship and that “providing prompts alone does not render outputs copyrightable.” Legally, this resembles a breach-of-contract dispute, not intellectual-property theft.
Anthropic nevertheless performs a conceptual sleight of hand, redefining what is essentially a contractual violation as an “attack.”
By pairing the neutral technical term “distillation” with the militarized word “attack,” and surrounding it with repeated references to “national security,” “bioweapons,” “authoritarian regimes,” and “export controls,” Anthropic elevates a commercial dispute into a security incident. The post even uses militarized language like “hydra cluster” to describe network architecture. This rhetorical framing is deliberate and systematic.
Why Now: A Timeline Few Noticed
To understand the post, it must be placed in its broader context.
On February 16, Axios reported that the Pentagon warned Anthropic it would “pay a price” and threatened to designate it a “supply-chain risk” — a label typically reserved for foreign adversaries. The conflict centered on Anthropic’s refusal to allow Claude to be used for mass surveillance or fully autonomous weapons, while the Pentagon demanded access for “all lawful purposes” without conditions.
On February 18, CNBC reported contract negotiations had stalled. On February 20, NBC reported relations had “reached a boiling point” after Anthropic questioned Claude’s use in a January U.S. military raid targeting Venezuelan President Maduro. According to reports, an Anthropic executive asked its partner Palantir whether Claude had been used in the operation, triggering strong military backlash. The Pentagon announced it was “reviewing its relationship” with Anthropic.

On February 23, Axios reported that Defense Secretary Hegseth would summon CEO Dario Amodei the next day for what officials described as a showdown. One senior official said bluntly: “Dario’s problem is that this is ideological for him. We know who we’re dealing with.”
That same day, xAI, founded by Elon Musk, signed an agreement with the Pentagon accepting the “all lawful uses” clause — setting a compliant benchmark directly in front of Anthropic.
Also on February 23, Anthropic published its distillation blog post.
A report saturated with national-security language, export controls, and the “China threat,” released one day before the CEO’s Pentagon meeting; while a $200 million defense contract hung in the balance; one week after being threatened with a “supply-chain risk” designation; and on the very day a competitor pledged unconditional compliance — this timing is not accidental.
If this were purely a technical disclosure, why not publish it when the activity was detected? Why wait until relations with the Pentagon reached freezing point?
After the post went live, Amodei reportedly traveled to the Pentagon on February 24. Should Anthropic ultimately concede on its original principles, this threat-laden “technical report” would conveniently serve as justification.

“I Can Distill the World’s Knowledge — But You Can’t Distill My Outputs”
Anthropic’s moral position faces another embarrassment.
Just one month earlier, more than 4,000 unsealed court documents revealed details of Anthropic’s “Project Panama.” The company spent tens of millions of dollars purchasing physical books from second-hand sellers, slicing off their spines with industrial hydraulic cutters, scanning every page at high speed, and then destroying and recycling the books. Internal documents describe the project’s goal as “destructively scanning the world’s books,” with a plan to process 500,000 to 2 million volumes within six months.
Before that, Anthropic co-founder Ben Mann had downloaded millions of pirated books from LibGen for early model training. Last year, Anthropic settled related copyright lawsuits for $1.5 billion without admitting wrongdoing.

On one side, a company that distilled humanity’s collective works to train its models. On the other, accusations that others distilling its model outputs constitute a national-security threat.
This double standard has not gone unnoticed. Tech commentator Gergely Orosz wrote on X: “Anthropic scrapes copyrighted material online, builds a paid model, and pays no compensation — that’s fair? But now it complains that others pay to use its model to build models anyone can use for free — that’s unfair?”
Others noted that “distillation isn’t an attack — it doesn’t impact your servers at all. If distillation is wrong, it’s certainly less wrong than destroying copyrighted works and distilling the world’s human output.”
Legally, the two cases differ. The former involves copyrighted human works; the latter involves AI outputs that lack copyright protection. Even if Anthropic proves distillation occurred, it likely does not own the extracted data. Contract law — not IP law — would be the more viable legal path.
But morally and rhetorically, a company built on distilling human knowledge accusing others of “attacking” it by distilling its outputs faces an obvious credibility gap.
As a result, following the blog’s release, criticism of Anthropic on X and elsewhere has outweighed discussion of the alleged distillation itself.
Anthropic is surely aware of this — but chose to feign ignorance. Because the purpose of this post was never mere technical disclosure.
It was a strategic statement amid a Pentagon relationship crisis: real technical evidence wrapped in a national-security narrative serving corporate survival. Its audience was not engineers, but policymakers in Washington.
This is not unprecedented. In October last year, Trump-era AI advisor David Sacks publicly accused Anthropic of pursuing a “fear-based regulatory capture strategy.” The timing and rhetoric of the distillation post only reinforce that assessment.
Anthropic has long tried to balance its identity as an “AI safety leader” with its role as a defense contractor. It brands itself around safety and restricts military use, yet it was the first AI company to deploy models on classified military networks and holds a $200 million defense contract. When these identities clash — when the Pentagon demands concessions — Anthropic needs a story to reaffirm its value to national security.
Accusing Chinese companies of distilling Claude provides exactly that story.
When a company learns to package commercial competition as national-security risk, to frame contract breaches as “attacks,” and to portray industry-wide gray zones as unilateral victimhood, perhaps the question is not only “who is distilling Claude,” but also “what is Anthropic distilling?”
It is distilling, from real technical events, a narrative tailored for its own political survival.
Editor: Zhongxiaowen




