{"id":4867,"date":"2026-09-25T10:39:25","date_gmt":"2026-09-25T03:39:25","guid":{"rendered":"https:\/\/blog.datacore.vn\/?p=4867"},"modified":"2026-09-25T10:39:26","modified_gmt":"2026-09-25T03:39:26","slug":"ai-model-distillation-risk","status":"publish","type":"post","link":"https:\/\/blog.datacore.vn\/en\/ai-model-distillation-risk\/","title":{"rendered":"AI Model Distillation: Anthropic's 7-Lab Allegation and the Essential Questions Enterprise AI Buyers Should Ask"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>TL;DR:<\/strong> On 10 September 2026 Anthropic, the United States artificial intelligence (AI) company behind the Claude family of models, published a threat intelligence report alleging industrial scale <strong>AI model distillation<\/strong> attacks against Claude by seven AI labs based in China. Anthropic named Alibaba, Moonshot AI, DeepSeek, Zhipu (also trading as Z.ai), Xiaomi, SenseTime and MiniMax. Every statement about those companies here is an allegation made by a commercial rival. None has been tested in court, and DataCore has not independently verified any of it. What follows explains what AI model distillation is, what Anthropic says it measured, and what a procurement team should ask an AI vendor before signing anything.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Anthropic alleges seven China based labs ran AI model distillation campaigns against Claude, detected from February 2026 onward, in activity the report covers through August 2026.<\/li>\n<li>Anthropic attributes the largest campaign, tracked as GTG-16005, to Alibaba affiliated operators, and puts it at more than 151 million exchanges between May and July 2026.<\/li>\n<li>Anthropic says AI model distillation access was obtained through proxy services, thousands of fraudulent accounts, stolen payment cards and illegally harvested application programming interface (API) keys.<\/li>\n<li>Anthropic says some captured AI model distillation exchanges contained sensitive material from individual users, large multinational companies and state affiliated actors.<\/li>\n<li>For an enterprise buyer the useful question is not who is guilty. It is whether your own prompts could be routed somewhere you never agreed to send them.<\/li>\n<li>Nothing in this article establishes that any named company broke any law. Treat every item as an unproven allegation.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"630\" src=\"https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore.jpg\" alt=\"AI model distillation allegations and the questions enterprise AI buyers should ask\" class=\"wp-image-4866\" srcset=\"https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore.jpg 1200w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore-300x158.jpg 300w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore-1024x538.jpg 1024w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore-768x403.jpg 768w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore-18x9.jpg 18w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What exactly did Anthropic allege about AI model distillation?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic published its threat intelligence report, titled Detecting and countering misuse of AI, on 10 September 2026. The report covers activity the company says it disrupted between December 2025 and August 2026 across seven areas of harm. One of those areas is what Anthropic calls illicit distillation, the AI model distillation pattern at the centre of this story. Reporting the following day, The Hacker News (11 September 2026) summarised that section and quoted the report directly. Anthropic says it identified and disrupted industrial scale AI model distillation attacks against Claude originating from seven labs based in China.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The wording of the AI model distillation claim matters. Anthropic does not describe ordinary competition, and it does not describe a lawsuit. It describes a pattern of access it says breached its terms of service, measured in exchanges with its own models. In the report language quoted by The Hacker News on 11 September 2026, Anthropic states that DeepSeek, Xiaomi and Moonshot fed conversations between their own models and users into Claude, then used Claude responses as training data with which to distil Claude capabilities. Anthropic adds that some of those exchanges included sensitive information, including from individual users, major multinational companies and state affiliated actors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two framing points deserve emphasis before anyone repeats this. First, an AI model distillation allegation of this kind is made by the party that owns the logs. Anthropic can see its own traffic. It cannot see inside another lab training pipeline, so the final step of the claim, that harvested data actually became training data, is an inference from observed behaviour rather than a directly observed fact. Second, the named companies are entitled to respond, and this article does not carry their side. If they issue statements, those statements belong in any fair account of the dispute.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Separately, and in the same week, United States cybersecurity and intelligence agencies accused China based AI companies of systematic extraction of proprietary capabilities from American frontier models through distillation attacks, as reported by The Hacker News on 11 September 2026. That is a second set of allegations, from government bodies rather than from a competitor. It does not prove the commercial claims. It does mean the AI model distillation question has become a policy matter and not only a vendor dispute.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How does AI model distillation actually work?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Knowledge distillation, the general and lawful form of AI model distillation, is a legitimate and well documented machine learning technique. A large, capable model acts as a teacher. A smaller or faster model acts as a student. The student is trained to reproduce the teacher outputs, so it inherits much of the teacher behaviour at a fraction of the training cost. Laboratories run AI model distillation on their own models constantly. Nothing about the method is inherently improper, and the word distillation on its own carries no accusation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What Anthropic describes is a narrower form of AI model distillation. It uses the term illicit distillation for an industrial scale campaign that covertly extracts a model capabilities and replicates them in another model without authorisation, typically through networks of fake accounts created with stolen credit cards, stolen login credentials and stolen API keys. The technique is the same. The consent, the payment and the identity of the account holder are what Anthropic says were not legitimate. That distinction is the whole substance of the AI model distillation dispute.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The valuable material in AI model distillation, on Anthropic account, is not the final answer text. It is the reasoning. Anthropic says the campaigns targeted chain of thought reasoning transcripts, the intermediate steps a model produces on the way to an answer. Those transcripts are dense supervision. They show a student model not only what to say but how the teacher got there. Anthropic says the targeted capabilities included agentic behaviour and tool use, software engineering, kernel development, data analysis and long horizon tasks, which are precisely the capabilities that command enterprise prices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Understanding this mechanism is what turns AI model distillation from a headline into a procurement issue. If reasoning traces are the prize, then any system that sits between your staff and a frontier model is a potential collection point. That includes resellers, aggregator gateways, cheap API brokers, browser extensions and coding assistants with opaque backends. The risk is structural, and it does not depend on which company turns out to be at fault in this particular case.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"960\" height=\"720\" src=\"https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-neural-network.gif\" alt=\"Neural network layers illustrating how AI model distillation transfers capability from teacher to student\" class=\"wp-image-5864\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Which AI model distillation campaigns did Anthropic describe, and how large were they?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic assigns each alleged AI model distillation campaign an internal tracking code and states a measured volume of exchanges. The table below reproduces the figures as reported by The Hacker News on 11 September 2026, drawing on the Anthropic report of 10 September 2026. Every row is an AI model distillation allegation by Anthropic. Where Anthropic gives no volume or no date range, the cell says so rather than guessing.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Campaign code<\/th><th>Lab named by Anthropic<\/th><th>Exchanges Anthropic says it observed<\/th><th>Period stated<\/th><th>Method described by Anthropic<\/th><\/tr><\/thead><tbody>\n<tr><td>GTG-16005<\/td><td>Alibaba affiliated operators<\/td><td>151 million<\/td><td>May to July 2026<\/td><td>Targeted chain of thought transcripts from Claude Opus 4.6 and 4.7, peaking near 3 million exchanges per day from more than 3,500 fraudulent accounts<\/td><\/tr>\n<tr><td>GTG-16002<\/td><td>Moonshot AI<\/td><td>23 million<\/td><td>May to July 2026<\/td><td>Rerouted customer requests to Claude instead of its own Kimi model, using a proxy network of 5,380 fraudulent accounts mostly in Singapore and Japan<\/td><\/tr>\n<tr><td>GTG-16001<\/td><td>DeepSeek<\/td><td>More than 12.1 million<\/td><td>14 days in July 2026<\/td><td>Silently relayed customer exchanges to Claude and extracted reasoning transcripts<\/td><\/tr>\n<tr><td>GTG-16006<\/td><td>Zhipu, also trading as Z.ai<\/td><td>More than 3.4 million<\/td><td>17 days in June and July 2026<\/td><td>Reasoning extraction pipeline replaying Claude traces back through Claude, rotating 273 fraudulent accounts<\/td><\/tr>\n<tr><td>GTG-16008<\/td><td>Xiaomi<\/td><td>More than 400,000<\/td><td>20 days in March and April 2026<\/td><td>Replayed user conversations and coding sessions from its own MiMo models into Claude through coding harnesses<\/td><\/tr>\n<tr><td>GTG-16012<\/td><td>SenseTime<\/td><td>No volume stated<\/td><td>No period stated<\/td><td>Purchased transcripts of user exchanges with Claude from third party data vendors<\/td><\/tr>\n<tr><td>GTG-16003<\/td><td>MiniMax<\/td><td>No volume stated<\/td><td>No period stated<\/td><td>Built a proxy network service through a shell company offering access to models from more than one United States lab<\/td><\/tr>\n<\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Takeaway: the alleged AI model distillation volume is concentrated. One campaign accounts for roughly four fifths of the total, so a buyer who reacts by treating every Chinese model as identical is reading the table less carefully than the table deserves.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two rows carry no numbers at all. That is deliberate on our part. Anthropic did not publish volumes for the SenseTime and MiniMax campaigns in the material we could verify, and inventing a figure to fill a cell would be worse than leaving it blank. Readers should also note that an exchange is not a fixed unit of value. A one line prompt and a thirty step agentic session both count as exchanges, so the headline totals measure activity rather than harm.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How did the alleged operators get access in the first place?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The access layer is the part of the AI model distillation story that should worry buyers most, because it involves ordinary users who did nothing wrong. Anthropic describes proxy services, sometimes called transfer stations or relay stations, that open thousands of accounts under fictitious identities using fake or stolen credit cards and API keys harvested from legitimate companies and individuals. Requests are then routed through those accounts so that traffic looks like scattered individual usage rather than one concentrated AI model distillation pipeline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic describes a second AI model distillation channel that is arguably more uncomfortable. It says unauthorised labs also buy transcripts of user exchanges with United States frontier models from third party resellers, and that those resellers are proxy operators who save conversations without the knowledge or consent of the users who typed them. In this account the person whose data is collected is not a party to the dispute at all. They simply used a cheap gateway and never read what it did with their prompts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic also alleges rerouting. In the campaigns it attributes to Moonshot AI and DeepSeek, it says customer requests were quietly sent to Claude rather than handled by the provider own model, with the Claude response shown back to the user. If accurate, that means some customers believed they were using one model and were in fact using another, while a subset of those exchanges was retained for training. That is the sharpest consumer protection question in the entire AI model distillation story.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"720\" src=\"https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-network-cables.jpg\" alt=\"Network switching hardware representing the proxy relay layer central to AI model distillation allegations\" class=\"wp-image-5865\" srcset=\"https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-network-cables.jpg 1280w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-network-cables-300x169.jpg 300w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-network-cables-1024x576.jpg 1024w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-network-cables-768x432.jpg 768w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-network-cables-18x10.jpg 18w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What has Anthropic changed in response?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic lists three AI model distillation countermeasures. It bans reseller accounts and accounts operating from unsupported regions, naming China, Iran and Russia, when the user fails identity verification. It changed model behaviour so that Claude summarises its internal reasoning before responding, which makes any captured transcript far less useful as training supervision. And it introduced a feature it calls preserved thinking in Fable 5.1, which stops new API accounts from altering the system prompt, the tools or the messages that precede a reasoning step in a multi turn conversation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The technical logic of the second measure is worth spelling out, because it explains why the industry is likely to move the same way. If the prize in AI model distillation is the reasoning trace, then a provider can defend itself by not emitting a clean reasoning trace. Summarising the reasoning degrades its value as supervision while keeping it useful to a human reader. Expect competing labs to follow, and expect the visible chain of thought that researchers currently enjoy to get thinner over the next year.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is a cost to that defence, and buyers should price it in. Less visible reasoning means less auditability. A Vietnamese bank that wants to show a regulator why a model declined an application benefits from detailed reasoning output. If frontier vendors suppress reasoning to blunt AI model distillation, explainability becomes a paid enterprise feature rather than a default. That trade off will show up in contracts before it shows up in headlines.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does an AI model distillation allegation change for whom?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Banks, insurers and securities firms.<\/strong> These are the buyers with the least room to be relaxed about AI model distillation. If a model provider reroutes traffic, customer records, credit assessments and internal risk language can leave the jurisdiction you promised your regulator they would stay in. The control that matters is not a clause about intellectual property. It is a contractual guarantee of which model serves each request, which region it runs in, and a log you can inspect. Ask for that log before you ask about price.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Software teams and engineering leaders.<\/strong> Coding assistants are the highest value AI model distillation target named in the Anthropic account, and they are also where shadow procurement is easiest. A developer adds a browser extension or a cut price API key and an entire private repository begins flowing through an unknown relay. The AI model distillation reporting gives engineering managers a concrete reason to inventory every AI endpoint their code touches, which is a task most teams have quietly deferred.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Startups and small and medium enterprises (SMEs).<\/strong> Cheap gateway pricing is exactly the offer Anthropic says AI model distillation proxy operators use to attract traffic worth harvesting. That does not make every discount reseller malicious. It does mean that an unusually cheap frontier model, sold by an intermediary you cannot identify, deserves a direct question about who operates the endpoint and what is retained.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Public sector and state owned enterprises.<\/strong> The Anthropic claim that some captured exchanges involved state affiliated actors moves AI model distillation from commercial risk into policy risk. Procurement rules in most countries were written for software licences, not for a supply chain where the vendor model may be a thin wrapper over somebody else model. Anyone drafting AI procurement standards in 2026 should treat routing transparency as a mandatory clause rather than a nice to have.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Individual users.<\/strong> The uncomfortable conclusion of the AI model distillation reporting is that ordinary users may already have contributed to a training set without consenting, simply by using a low cost frontend. Nobody has published a way for an individual to check this. That is a real gap, and honesty requires saying so rather than pretending a checklist exists.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"1926\" src=\"https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-datacenter.jpg\" alt=\"Data centre server racks representing the compute scale behind AI model distillation campaigns\" class=\"wp-image-5863\" srcset=\"https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-datacenter.jpg 1280w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-datacenter-199x300.jpg 199w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-datacenter-681x1024.jpg 681w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-datacenter-768x1156.jpg 768w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-datacenter-1021x1536.jpg 1021w, https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/distillation-datacenter-8x12.jpg 8w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">An illustrative example: how could AI model distillation exposure reach a Vietnamese lender?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The following scenario is invented for teaching purposes. No part of it is reported fact. There is no such lender, the numbers are arbitrary, and nothing here describes anything Anthropic or any named company has said happened.<\/strong> It exists only to show how the AI model distillation mechanism described above could translate into an operational problem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine a mid sized consumer lender in Ho Chi Minh City. Its collections team adopts an AI assistant to draft customer messages. Procurement never sees the purchase because the tool costs under two million Vietnamese dong per seat per month and is expensed. The vendor advertises a frontier class model at roughly a third of the list price of the same model bought directly. Over nine months, forty collections agents paste borrower names, outstanding balances, employment details and repayment histories into the tool.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nothing visible goes wrong, and no AI model distillation alarm sounds. Response quality is good, because the traffic is genuinely reaching a frontier model. What the lender does not know, in this invented scenario, is that the gateway stores every exchange. Two things then become possible. The stored transcripts can be sold onward to a lab as AI model distillation input. And the borrower data inside them has now left the lender control, with no record of where it went and no contractual counterparty who admits holding it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The failure in this illustration is not the AI. It is that no one could answer a simple question: which company operates the endpoint our staff are sending borrower data to? A lender that could answer that question in week one would never have reached month nine. That is the entire practical lesson of the AI model distillation reporting, and it is available to any organisation that takes an inventory seriously.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two further points about this illustration. The cost saving is what made it attractive, so the control must sit with finance as well as with security. And the exposure would exist even if every allegation Anthropic made turned out to be unfounded, because the weakness is the unidentified intermediary, not the accused lab. We have used a lending example because it is familiar, but the same pattern fits a brokerage, a hospital or a law firm without changing a single step.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What should enterprise AI buyers ask a vendor about AI model distillation?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ask which model serves each request, by name and version, and ask for it in writing. Ask whether the vendor ever routes a request to a third party model, and under what conditions. Ask where inference physically runs. Ask what is retained, for how long, and whether retention can be switched off for your tenant. Ask whether your prompts or outputs may be used for training by the vendor or by anyone the vendor supplies. Ask for a routing log you can audit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then ask the questions that the AI model distillation reporting specifically exposes. Is the vendor a direct customer of the model provider, or an intermediary? If an intermediary, who is the underlying contract with? Does the vendor resell capacity to anyone else? Has the vendor ever had accounts suspended by a model provider? A vendor that answers all of these cleanly is not necessarily safe, but a vendor that cannot answer them has told you something important.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Inside your own organisation, the equivalent work is an inventory. List every AI endpoint any system or employee calls, including extensions, plugins and personal accounts used for work. Match each one to a contract. Anything unmatched is an unmanaged AI model distillation exposure by definition, regardless of who operates it. This is unglamorous, and it is the single highest value control available to most companies right now. For a related discussion of quality risk in enterprise deployments, see our piece on <a href=\"https:\/\/blog.datacore.vn\/en\/ai-slop-enterprise-vietnam\/\">AI slop and enterprise output quality<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How should Vietnamese enterprises weigh this?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Vietnam sits in an unusual position. Chinese models are cheap, capable, increasingly strong in regional languages, and heavily used by local developers. American models are expensive and, for some workloads, still ahead. A reflex to ban one country models would be both impractical and poorly reasoned, because the AI model distillation allegations concern how certain labs allegedly obtained training data, not whether their released models are technically sound. Those are separate questions and should be assessed separately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A more defensible policy has three parts. Classify data before choosing a model, so that regulated or personal data is handled only by endpoints you can name. Require routing transparency from every vendor regardless of origin, because a European or American reseller can relay traffic just as easily. And keep a written record of the decision, so that when a regulator or a client asks why you chose a provider, the answer is a document rather than a memory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This also sits inside a wider national picture. Vietnam has set out its own artificial intelligence ambitions, which we covered in our analysis of the <a href=\"https:\/\/blog.datacore.vn\/en\/vietnam-ai-strategy-2030\/\">national AI strategy to 2030<\/a>, and the regional compute and chip supply story continues to move quickly, as in our coverage of <a href=\"https:\/\/blog.datacore.vn\/en\/china-ai-chip-surge-ox-alpha\/\">China domestic AI chip momentum<\/a>. Sovereignty debates are downstream of exactly the routing questions above.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What this article is not<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is not a finding of wrongdoing. Anthropic has published allegations against named competitors. No court has ruled on them, no regulator cited here has completed a proceeding against any of the named companies, and the companies themselves may dispute the account in full. It is also not a recommendation to avoid any specific provider. It is a description of a mechanism, plus the questions that mechanism makes worth asking. Readers who need a definitive account should read the Anthropic report and any responses in full.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently asked questions about AI model distillation<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Is AI model distillation illegal?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Distillation as a training method is not illegal and is used widely across the industry. What Anthropic alleges is a specific pattern it calls illicit distillation, involving fraudulent accounts, stolen payment details and harvested API keys. Whether that pattern breaks a particular law depends on jurisdiction and has not been settled by any court in the cases described. As of 22 September 2026 these remain allegations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Did Anthropic name specific companies?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. In its 10 September 2026 threat intelligence report Anthropic identified seven China based labs: Alibaba affiliated operators, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. Naming is not proof of AI model distillation. It records what one company says its own traffic logs show, and the named parties have the right to rebut it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Could my company data be caught up in AI model distillation?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Possibly, if your staff use an intermediary gateway rather than a direct contract with a model provider. Anthropic says proxy operators saved user exchanges without consent and sold them onward as AI model distillation input. Neither we nor anyone else can tell you whether your specific traffic was affected, because that information sits with the operators. The practical response is an endpoint inventory, not speculation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does this mean Chinese AI models are unsafe to use?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No, and the report does not claim that. The AI model distillation allegations concern how training data was allegedly acquired, not whether the resulting models behave badly. Model quality, licensing and data handling are three separate assessments. Conflating them produces bad procurement decisions in either direction.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How can a buyer detect rerouting?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Contractually, by requiring the vendor to name the serving model and region per request and to expose an auditable routing log. Technically, detection from the outside is hard and no reliable public test exists. We are not going to pretend otherwise. The leverage is in the contract and in refusing vendors who will not answer.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What changed on the Anthropic side after the report?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic says it bans reseller accounts and unverified accounts from unsupported regions, that Claude now summarises internal reasoning before responding so captured transcripts are less useful for training, and that a preserved thinking feature in Fable 5.1 prevents new API accounts from editing the context preceding a reasoning step.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Where can I read the primary source?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic published the report on its own site on 10 September 2026 under the title Detecting and countering misuse of AI. The Hacker News published a detailed summary of the distillation section on 11 September 2026. Both are worth reading before forming a view.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DataCore builds verified Vietnamese company, market and location datasets, and we care about provenance for the same reason this story matters: data is only as trustworthy as the chain that delivered it. If you want to see how a documented data supply chain looks in practice, explore the <a href=\"https:\/\/datacore.vn\/en\/services\" target=\"_blank\" rel=\"noopener\">DataCore services overview<\/a> or try the <a href=\"https:\/\/datacore.vn\/en\/demo\/company-trial\" target=\"_blank\" rel=\"noopener\">company data trial<\/a>. No pressure, and no proxy in the middle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Published 22 September 2026. All allegations described above are attributed to Anthropic threat intelligence report of 10 September 2026 as reported by The Hacker News on 11 September 2026. DataCore has not independently verified them.<\/em><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Anthropic alleges AI model distillation attacks by seven China based labs in its September 2026 report. What enterprise AI buyers should verify next.<\/p>\n","protected":false},"author":19,"featured_media":4866,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_uag_custom_page_level_css":"","_swt_meta_header_display":false,"_swt_meta_footer_display":false,"_swt_meta_site_title_display":false,"_swt_meta_sticky_header":false,"_swt_meta_transparent_header":false,"footnotes":""},"categories":[6],"tags":[3648,3649,531,3647],"class_list":["post-4867","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-ai-governance-2026","tag-ai-model-distillation-risk","tag-anthropic","tag-enterprise-ai-vendor-risk"],"uagb_featured_image_src":{"full":["https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore.jpg",1200,630,false],"thumbnail":["https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore-150x150.jpg",150,150,true],"medium":["https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore-300x158.jpg",300,158,true],"medium_large":["https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore-768x403.jpg",768,403,true],"large":["https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore-1024x538.jpg",1024,538,true],"1536x1536":["https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore.jpg",1200,630,false],"2048x2048":["https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore.jpg",1200,630,false],"trp-custom-language-flag":["https:\/\/blog.datacore.vn\/wp-content\/uploads\/2026\/09\/anthropic-china-ai-model-distillation-2026-datacore-18x9.jpg",18,9,true]},"uagb_author_info":{"display_name":"DataCore Marketing","author_link":"https:\/\/blog.datacore.vn\/en\/author\/datacore_marketing\/"},"uagb_comment_info":0,"uagb_excerpt":"Anthropic alleges AI model distillation attacks by seven China based labs in its September 2026 report. What enterprise AI buyers should verify next.","_links":{"self":[{"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/posts\/4867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/comments?post=4867"}],"version-history":[{"count":15,"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/posts\/4867\/revisions"}],"predecessor-version":[{"id":5895,"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/posts\/4867\/revisions\/5895"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/media\/4866"}],"wp:attachment":[{"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/media?parent=4867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/categories?post=4867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.datacore.vn\/en\/wp-json\/wp\/v2\/tags?post=4867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}