TLDRocket
Sign in

China closes AI gap with distillation attack

morningbrew.com

Anthropic says Alibaba ran 25,000 fake accounts to siphon Claude's answers for training. Alibaba's response: ban staff from using Anthropic at all.

Based on reporting by morningbrew.com — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Distillation used to be a wonky term reserved for machine-learning papers. Now it's the accusation at the center of a very public spat between Anthropic and Alibaba. Anthropic claims it caught roughly 25,000 accounts, allegedly tied to Alibaba, systematically querying Claude to harvest outputs that could then be used to train or fine-tune Alibaba's own models. That's not a rounding error. That's an operation.

Alibaba didn't exactly deny wrongdoing so much as change the subject. Its answer was to bar its own employees from using Anthropic's products altogether, a move that reads less like contrition and more like damage control dressed up as retaliation. It's the corporate equivalent of getting caught peeking at a neighbor's exam and then drawing the blinds on your own house.

The bigger story here isn't really about one company's scraping habits. Distillation, the practice of training a smaller or newer model on a larger one's outputs, has become a shortcut that lets fast-moving labs catch up without footing the bill for original research. DeepSeek faced similar accusations earlier this year, and the pattern suggests Chinese AI firms have found that querying Western frontier models at scale is cheaper than building frontier-level training infrastructure from zero.

Anthropic, for its part, has leaned hard into the narrative that it's defending intellectual property built on billions of dollars of compute and years of alignment work. Whether that framing survives scrutiny is another matter, since Claude itself was trained partly on scraped web data that plenty of publishers never consented to. Glass houses, stones, all that.

What's actually new is the openness of the confrontation. Companies have quietly suspected distillation attacks for a while, but naming names and banning tools turns a technical grievance into a geopolitical one. Given how central AI has become to the US-China rivalry, expect this kind of accusation to become a recurring headline rather than a one-off.

My take — AI-written commentary, not fact-checked reporting

I run TLDRocket because I think AI news deserves plain language instead of lab-speak, and this story is a perfect example of why: everyone's outraged about theft except the part where frontier labs built their empires on scraped data too. My take is that distillation bans are security theater dressed as principle, and the real fight isn't about ethics, it's about who controls the compute and the data pipes going forward. Closed labs love to play victim right up until they're the ones doing the copying.

Read more about this at: morningbrew.com

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.