The Unseen Battle: AI Distillation on an Industrial Scale
The competitive landscape of artificial intelligence has taken a contentious turn with recent revelations detailing sophisticated, industrial-scale AI distillation campaigns originating from China. Leading American AI developers, OpenAI and Anthropic, have found themselves at the forefront of this unseen battle, grappling with systematic efforts to extract and replicate the advanced capabilities of their frontier models.
Anthropic, a prominent AI research company, recently disclosed a massive distillation campaign linked to Alibaba’s Qwen AI lab. This operation, described as the largest ever measured, involved approximately 25,000 fraudulent accounts and generated an astonishing 28.8 million interactions with Anthropic’s Claude model between April 22 and June 5, 2026. This incident underscores a growing trend in which Chinese AI entities are allegedly bypassing access restrictions by routing traffic through proxy services that manage vast networks of fake accounts, effectively siphoning off valuable AI knowledge.
This wasn’t an isolated event. In February 2026, Anthropic identified another significant wave of activity, involving around 24,000 fake accounts and 16 million Claude interactions. This earlier campaign was attributed to other notable Chinese AI firms: DeepSeek, Moonshot AI, and MiniMax. The scale and coordination of these efforts suggest a deliberate strategy to accelerate China’s AI development by leveraging American industry’s innovations.
White House and Congressional Concerns Mount
The implications of these distillation campaigns extend beyond intellectual property theft, touching upon critical national security concerns. The White House Office of Science and Technology Policy (OSTP) issued a memo on April 23, describing these Chinese operations as “deliberate, industrial-scale campaigns.” The memo starkly concluded that “there is nothing innovative about systematically extracting and copying the innovations of American industry,” highlighting the perceived lack of original research in these methods.
OpenAI, another key player in the AI space, has also voiced its concerns. In February 2026, the company sent a memo to Congress, directly accusing DeepSeek of systematic distillation. More recently, OpenAI separately wrote to the House China Select Committee, reporting evidence that DeepSeek attempted to distill OpenAI’s frontier models using “new, obfuscated methods.” These reports paint a picture of persistent and evolving tactics aimed at gaining an unfair advantage in the global AI race.
In response to these escalating threats, OpenAI, Anthropic, and Google formed the Frontier Model Forum in 2023. This collaborative initiative aims to share intelligence and coordinate defenses against such sophisticated attacks, recognizing the collective challenge posed by these distillation efforts. The U.S. State Department formally weighed in on July 8, stating that the use of Chinese AI models by American companies “raises serious concerns,” signaling a potential policy shift and increased scrutiny.
The Economic Imperative: Cost and Capability
The economic incentives driving these distillation campaigns are significant. Chinese models offer a compelling cost advantage, with Citi research indicating that they charge approximately 18 cents per million tokens, compared to around $4 per million for comparable U.S. frontier models. For instance, Zhipu AI’s GLM-5.2 costs $1.40 per million input tokens and $4.40 per million output tokens, while Anthropic’s Opus 4.8 is priced at $5 per million input and $25 per million output. This stark difference in pricing creates a powerful economic pull for companies seeking to reduce their AI operational costs.
Coinbase CEO Brian Armstrong recently announced in late June that the company had nearly halved its AI bill by routing over 1,200 AI agents to Zhipu AI’s GLM-5.2 and Moonshot AI’s Kimi K2.7 Code. This move, while economically sound for Coinbase, inadvertently highlights the effectiveness of Chinese models, even if their underlying knowledge might be derived through questionable means. It also underscores the dilemma faced by American companies in balancing cost efficiency with ethical sourcing and national security implications. This situation aligns with Beijing’s recent push for AI integration, which often emphasizes practical application and cost-effectiveness.
However, the use of Chinese AI models comes with its own set of risks. Zhipu AI, for example, has been on the U.S. Commerce Department Entity List since January 2025, raising questions about the long-term viability and security of relying on such providers. The broader implications for American companies using these models are significant, as detailed in our previous report on US AI giants supplying models to Pentagon blacklisted Chinese firms via Singapore loophole.
The Code Vulnerability and Political Sensitivity
A May 2026 study by Booz Allen Hamilton further complicated the narrative, revealing potential vulnerabilities and political biases within Chinese code-generation models. The study conducted over 2,800 trials against five frontier code-generation models, including four Chinese models (Qwen3-Coder, MiniMax M2.5, Kimi K2.5, DeepSeek V4-Pro) and one American model (Claude Opus 4.6).
The findings were particularly concerning: Qwen3-Coder added approximately 130% more vulnerabilities when operating under a U.S. government contractor persona compared to a neutral persona. While Booz Allen stated, “We do not have proof at this point that code flaws are intentionally introduced,” the results raise serious questions about the integrity and security of code generated by these models, especially in sensitive applications.
Furthermore, all four Chinese models demonstrated a reluctance to engage with politically sensitive subjects. Their refusal rates ranged from 8% for DeepSeek to 80% for MiniMax, indicating a clear censorship mechanism embedded in their programming. This political sensitivity could severely limit their utility for international businesses and governments that require unbiased, uncensored AI capabilities.
A Call for Vigilance and Policy Action
The ongoing AI distillation campaigns and the associated risks have prompted a joint investigation by the House Committee on Homeland Security and the House Select Committee on China. This investigation specifically targets American companies like Airbnb and Anysphere (maker of Cursor) for their use of Chinese AI, signaling heightened scrutiny from Washington. As reported by Crypto Briefing, the issue is gaining significant traction.
The revelations underscore the urgent need for robust cybersecurity measures, clear policy guidelines, and international cooperation to safeguard intellectual property and national security in the age of AI. The balance between fostering innovation, ensuring competitive markets, and protecting against strategic exploitation remains a critical challenge for policymakers and industry leaders alike.
