
antropic Jacob Klein, director of threat intelligence, said his company welcomes competition. But he says what’s coming out of the Chinese market is much more like theft.
Klein said foreign adversaries have access to Anthropic’s Claude model (a process known as distillation) to train competing techniques and sell copycat versions at lower prices. Distillation can be done legally, but that’s not what’s happening here, Klein said.
“There’s a whole illicit ecosystem trying to gain access to Claude and other models,” Klein told CNBC. “This ecosystem is able to open very large accounts, doing whatever it takes to circumvent our control.”
Distillation has become a controversial topic throughout the world of artificial intelligence. Depending on the implementation, model developers can use the artifacts of other companies’ technologies to create competitive products at a fraction of the cost. In the United States, some factions of the tech industry are urging policymakers to avoid regulation to allow the best and most cost-effective AI to win, while others are lobbying for a crackdown on what they see as intellectual property theft.
In an April memo, the Trump administration called distillation that undermines U.S. research and classified information “unacceptable” and said it would consider “a wide range of measures to hold foreign actors accountable.”
At a pivotal time for Anthropic, threats are intensifying. The five-year-old company has seen its private market valuation soar to nearly $1 trillion, and is expected to go public as early as October, CNBC reported.

Anthropic has named Moonshot AI, a Chinese AI research institute, as one of the companies plagiarizing its technology. Moonshot’s Kim K3 model took the tech world by storm in July with its inexpensive, frontier-level AI products. It has been widely adopted in Silicon Valley because of its low price and ease of customization by companies.
Klein said Kimi K3 was illegally trained using the latest version of Claude.
“We’ve seen quite a bit of this from China,” Klein said. “This is something the whole industry is working on.”
Earlier this year, Anthropic claimed that Moonshot and two other Chinese AI labs (DeepSeek and MiniMax) had extracted its cutting-edge AI models. Anthropic also condemns alibabacreate a model of the Kwen family and carry out a large-scale “distillation attack” to illegally take away Claude’s abilities. OpenAI and google Both have published reports on distillation and claim to be fighting the same problem.
Alibaba, DeepSeek, Moonshot and MiniMax did not respond to requests for comment.
“unauthorized means”
In addition to China, the threat comes from countries such as Iran, Russia, and North Korea, where sanctions have restricted companies from using Claude, Google’s Gemini, and OpenAI’s ChatGPT, cybersecurity experts told CNBC.
Klein said many labs in these regions are “trying to access the models through illegal and fraudulent means.”
One way to get around these restrictions is to turn to the dark web. On the dark web, you can find a marketplace of stolen credit card information and compromised AI accounts. Klein said companies like Moonshot are “spinning up tens, if not hundreds of thousands, of fraudulent accounts.”
Once you have access to Anthropic’s system, you can ask questions of the model, collect the answers, and use them to train your own models, often called students, Klein said.
A clear sign that distillation is occurring is that users may ask thousands of questions instead of dozens, and potentially create thousands of accounts to do the same thing, potentially creating a whack-a-mole scenario for AI labs, Klein said.
“It’s very difficult to completely stop this as a problem, but I think slowing it down is a good thing and worth it,” Klein said, adding that foreign companies can take advantage of the technology with few guardrails.
He cited concerns such as possible use in surveillance and biological weapons programs, and said this was a specific campaign by a China-based organization using Anthropic’s technology to carry out large-scale espionage operations.
“It raises national security concerns if malicious actors, actors we don’t trust, gain access to models that are even more capable than they would otherwise be able to obtain through the act of distillation.”

Travis Lanham, head of technology at cybersecurity firm Almadine and a former Google engineer, said bad actors often go undetected because AI companies are under pressure to make their platforms as accessible as possible as they compete with competitors.
“These companies are responding to billions of requests,” Lanham said of large AI labs. “The millions are relatively small compared to everything else, and they’re just trying to sneak in and make it look like the rest of the crowd.”
Klein expects widespread competition for Anthropic and acknowledges there are legal distillation methods. This usually means obtaining permits and following laws regarding things like intellectual property and export controls.
“I think competition is great,” Klein said. “The concern here is that you’re illicitly extracting our models, using stolen credit cards and stolen infrastructure to create millions of fake accounts, and then generating unsecured models.”
Watch: Humanity enters the physical world

