Frontier AI Under Siege: Chinese Labs Distilling Claude Capabilities

Anthropic, a leading AI safety and research company, has reported that seven laboratories in China are engaged in large-scale illicit distillation attacks targeting its Claude models. This represents a significant escalation in the race to replicate advanced AI capabilities without investing in independent development.

The Mechanics of Model Cloning

The process involves extracting core functionalities from frontier models like Claude through distillation—a legitimate training method when properly authorized. However, Anthropic defines illicit distillation as “an industrial-scale, covert campaign” that bypasses proper licensing and oversight. These operations often rely on networks of fake accounts using stolen credentials to access and replicate the target model.

Risks Associated with Unauthorized Replication

Beyond intellectual property concerns, this practice poses several risks:

  • Security vulnerabilities: Safeguards built into original models are not transferred during distillation
  • Dangerous capabilities: Cloned models can be modified to achieve unintended or harmful outcomes
  • Data privacy: User data transmitted through third-party services may be exposed

Anthropic is actively developing countermeasures while unauthorized actors seek new ways around security protocols.

Broader Implications for AI Security

This situation highlights a growing challenge in the AI landscape—the vulnerability of proprietary models to theft and replication. As Google Threat Intelligence Group noted, these “model extraction attacks” represent a new form of intellectual property crime enabled by the widespread adoption of large language models.

Concerns extend beyond commercial interests, with some policymakers considering measures to protect US AI innovation from foreign exploitation. Treasury Secretary Scott Bessent recently suggested that the White House is weighing sanctions against entities engaged in unauthorized model replication.