Newsletter

Who Owns AI? Anthropic Accuses China of “Stealing” From Claude

September 20, 2026

On September 10, Anthropic accused several Chinese AI companies of trying to extract capabilities from Claude. And the numbers are huge.

Anthropic says Alibaba alone made more than 151 million exchanges with Claude between May and July, using thousands of accounts. It also accused DeepSeek, Moonshot, Zhipu and Xiaomi of doing something similar, collecting Claude’s outputs to improve their own models. Washington is now calling this “industrial‑scale” AI theft.

But Anthropic’s report raises a bigger question: Who gets to define AI theft?

The controversy here is not about distillation itself. Distillation is a standard technique in AI development, where one model learns from the outputs of another. And Anthropic itself acknowledges that frontier AI companies routinely use distillation to create smaller and more efficient models. The controversy is about where that normal technique crosses into unauthorized use.

Anthropic says some Chinese companies used fake accounts, proxy networks and other methods to get around its restrictions. Anthropic calls these operations “illicit distillation.”

But where exactly is the line between learning from a competitor and stealing from one? What was Claude itself trained on? And where does the knowledge inside these AI models actually come from? AI companies don’t create all that knowledge from scratch. They learn from information created and accumulated by the world. So when one AI learns from another, is that really “stealing” knowledge — Or is it learning from a technology that was itself built on humanity’s existing knowledge?

And there’s another difference that often gets overlooked. Many Chinese AI models have embraced open source, allowing others to study, modify and build on them. Some of the most powerful U.S. models, by contrast, remain behind closed doors. If AI is going to reshape the world, should its most powerful capabilities belong to a handful of closed companies, or should they become increasingly accessible to the rest of the world?

China’s Commerce Ministry has rejected the allegations, calling distillation a widely used technology and accusing Washington of turning a technical and commercial issue into a tool for restricting competition.

At the same time, the U.S. government is increasingly treating AI competition with China as a national security issue. As Chinese companies develop increasingly competitive AI systems, the ways they gain access to frontier technology are becoming part of that same security debate. And that changes the context of the argument.

If access to the frontier is restricted, competition does not simply stop. Companies look for other ways to learn, develop and close the gap. That is where distillation becomes particularly important. A model may be closed. Its weights may be protected. Its training data may be secret. But its capabilities are visible every time someone interacts with it. And those interactions can become a source of training data.

There are also signs that the story of AI competition may be more complicated than a simple “China copied America” narrative. DeepSeek’s R1 research, later published in Nature, describes a training process centered on reinforcement learning and its own model‑development pipeline. And Kimi K3 appeared only about two weeks after Anthropic released its Fable model. Some AI researchers questioned whether there was even enough time to collect sufficient data, train a model and reproduce that level of capability through distillation alone.

These cases do not settle the broader dispute. But they do highlight a basic problem with measuring AI progress: It is becoming increasingly difficult to identify exactly where a model’s capabilities come from. A model can learn from many sources. Researchers can combine different datasets, training methods and models. And capabilities can spread through the industry much faster than the companies developing them can control.

In the past, controlling a technology often meant controlling the hardware, the patents or the manufacturing process. With AI, the line is blurrier. You can restrict the chips. You can restrict access to the model. You can restrict the API. But once a powerful model is out in the world, controlling everything others can learn from it becomes much harder.

And that may be the real challenge for Washington. Not simply whether China is learning from American AI, but how quickly that learning can turn into competition.

And this is where the story gets even more complicated. Just days after releasing its threat report, Anthropic CEO Dario Amodei called for slowing the development of increasingly powerful AI, warning about potentially catastrophic risks. Other major AI leaders, including OpenAI CEO Sam Altman and Elon Musk, have also called for greater caution. At the same time, Washington continues to emphasize the importance of keeping America ahead of China in AI.

So two priorities are now running in parallel. One is to control the risks of increasingly powerful AI. The other is to make sure America remains ahead in the global AI race. And that brings us back to the question at the center of this story: Who gets to decide the rules of AI competition? If AI’s progress is built on the knowledge and work of previous generations, then the bigger question may not be simply who copied whom.

It is whether the progress of AI should be controlled by a few companies, or shared by humanity as a whole.

Share This Post

Leave a Reply