Anthropic has confirmed what security researchers have suspected for months: foreign actors, many believed to be linked to China, are illegally siphoning outputs from its Claude models to train cheaper knockoff systems, then hawking those copies on dark web marketplaces, according to CNBC. The revelation puts fresh urgency behind Washington's push to lock down American AI IP.
Anthropic just confirmed a problem that's been quietly gnawing at the entire AI industry for the better part of a year. Foreign actors, some allegedly tied to Chinese state-linked operations, have been illegally scraping and querying Claude at scale, using those outputs to train copycat systems that then get resold on dark web marketplaces for a fraction of what legitimate access costs, according to CNBC's reporting. It's the kind of story that sounds niche until you realize how much money and strategic advantage is riding on it.
The technique at the center of this is called model distillation, where a smaller or cheaper model is trained to mimic the outputs of a larger, more expensive one by essentially learning from its answers. It's not inherently illegal or even unusual. Plenty of legitimate AI labs use distillation to compress their own models. The problem is when someone else's frontier model, one they didn't pay to access at scale or agree to terms of service for, becomes the free teacher.
This isn't the first time this exact fight has played out in public. OpenAI accused DeepSeek of doing something strikingly similar last year, claiming the Chinese startup's surprisingly cheap and capable model owed its performance to unauthorized distillation of GPT outputs. DeepSeek denied wrongdoing, but the episode rattled Silicon Valley and helped kick off a broader reckoning over how exposed American AI labs are once their models are live and answering millions of queries a day.
What's different this time, based on the CNBC account, is the dark web angle. Instead of a rival lab quietly building a competing product, the allegation is that stolen or distilled versions of Claude are being packaged and sold directly to buyers looking for a discount alternative to Anthropic's own API pricing. That's a more direct hit to the business model. Every dollar spent on a black-market clone is a dollar that never touches Anthropic's revenue line, and it undercuts the pricing power labs like Anthropic, OpenAI, and Google DeepMind rely on to fund the next generation of frontier training runs.
Anthropic has reportedly been tightening its defenses, things like rate-limiting suspicious query patterns, watermarking outputs, and monitoring for the kind of high-volume, repetitive prompting that distillation attempts typically require. But security researchers say the cat-and-mouse dynamic favors the attacker in the short term. "These labs are basically running an API that anyone with a credit card and a VPN can hit millions of times a day," one cybersecurity researcher told CNBC. "Detecting distillation in real time is hard, and by the time you catch it, the damage is already baked into someone else's model weights."
The China angle is what will get Washington's attention fastest. Lawmakers have spent the past two years tightening export controls on advanced chips from Nvidia and others specifically to slow China's AI progress. If foreign actors can simply distill their way around those chip restrictions by borrowing the intelligence baked into American models rather than the hardware used to train them, the entire export control strategy starts to look like it's fighting the wrong battle. Expect renewed congressional interest in extending IP protections and possibly new legal frameworks around unauthorized API-based training, something that barely existed as a policy category two years ago.
For Anthropic specifically, this is also a trust problem. Enterprise customers paying premium rates for Claude access want assurance that the model they're licensing isn't simultaneously being reverse-engineered and resold at a discount by someone who never signed a contract. How aggressively Anthropic can defend that moat, through technical countermeasures, legal action, or lobbying for stronger federal protections, will say a lot about whether frontier AI labs can actually protect their core asset once it's out in the world answering questions.
This story is really about who gets to profit from the billions being poured into frontier AI training. If distilled clones can undercut the labs that built the original models, the economics of the entire industry shift, and fast. Anthropic's next moves on detection, legal enforcement, and possibly pushing for federal IP protections will be worth watching closely, as will whether OpenAI, Google, and other frontier labs start reporting similar theft. The distillation fight that started as a DeepSeek controversy just got a lot more adversarial, and a lot more geopolitical.