For the first time in the brief but turbulent history of the artificial intelligence industry, OpenAI, Anthropic, and Google have set aside their fierce rivalry to address a shared threat: the systematic extraction of their most advanced model capabilities by Chinese AI developers. The three companies announced on April 6 that they are forming a joint technical and policy working group specifically focused on combating the practice known as API distillation, a technique in which competitors query a frontier model through its public API at scale, then use the outputs to train a cheaper, locally hosted model that mimics the original’s behavior. The move marks a significant escalation in the US-China AI competition and signals that Western AI labs have concluded the problem is too large for any single company to address alone.
What Is API Distillation and Why Does It Matter
API distillation is not a new concept in machine learning — it has been used legitimately for years to compress large models into smaller, more efficient ones. What has changed is the scale and intent of the practice. According to reporting by Bloomberg and the Japan Times, US AI labs have accumulated substantial evidence that Chinese developers have been systematically querying their APIs — sometimes through intermediary accounts or third-party resellers to circumvent geographic restrictions — and using the resulting input-output pairs to fine-tune open-source base models. The result is a model that can replicate much of the reasoning and instruction-following capability of a frontier system at a fraction of the cost, without the years of investment in pretraining data, compute, and alignment research.
The practice poses a direct threat to the business models of OpenAI, Anthropic, and Google, all of which rely on API revenue to fund their ongoing research. More broadly, it raises questions about whether the massive capital investments required to develop frontier AI models can be sustained if the competitive advantages they confer can be eroded within months by well-resourced competitors using distillation techniques. For the US government, the issue carries an additional national security dimension: if Chinese developers can reliably extract capabilities from US frontier models, export controls on AI chips and model weights become significantly less effective as a tool of technological containment.
The Joint Working Group: Technical and Policy Tracks
The working group announced by the three companies will operate on two parallel tracks. On the technical side, it will develop shared detection methods to identify unusual API usage patterns consistent with large-scale distillation — including anomalous query volumes, systematic coverage of model capabilities, and the use of adversarial prompts designed to probe the limits of a model’s knowledge. The group will also explore cryptographic and watermarking techniques that could allow companies to trace the provenance of model outputs even after they have been incorporated into a third-party system.
On the policy side, the working group will engage with the US Commerce Department and the Office of Science and Technology Policy to explore whether API access to frontier models should be subject to the same kind of end-use and end-user restrictions that currently govern the export of advanced AI chips. This would represent a significant expansion of the US export control regime, extending it from physical hardware into the domain of software and services — a legally and technically complex undertaking that would require new regulatory frameworks and international coordination.
The formation of the group is notable not just for what it will do, but for what it represents: an acknowledgment by three companies that are otherwise locked in an existential competition for market share that some threats require collective action. OpenAI, Anthropic, and Google compete directly for enterprise customers, developer mindshare, and top research talent. The decision to collaborate on this issue suggests that their leadership teams view the distillation threat as serious enough to justify the reputational and strategic risks of being seen to coordinate with rivals.
China’s Response and the Broader Implications for the AI Race
Chinese AI developers and government officials have not yet formally responded to the announcement, but the move is likely to be characterized in Beijing as another example of US efforts to maintain technological hegemony by restricting access to advanced AI capabilities. Chinese AI labs have consistently argued that their models are the product of independent research and development, and that accusations of distillation are either exaggerated or reflect a misunderstanding of how modern AI systems are trained.
The broader implications of the joint working group extend well beyond the immediate question of API distillation. If the three companies succeed in developing effective detection and attribution methods, it could fundamentally change the dynamics of the global AI competition by making it significantly harder for any actor — state-sponsored or commercial — to free-ride on the investments of frontier labs. Conversely, if the effort fails or is circumvented, it may accelerate the push in Washington for more aggressive regulatory interventions, including restrictions on the public availability of API access to the most capable AI systems. For the global AI industry, this is a landmark moment — the first time the leading US labs have formally acknowledged that the competitive threat from China has reached a level requiring a coordinated institutional response.
