
Anthropic Says 7 Chinese Labs Used Illicit Distillation to Clone Claude
Anthropic said seven labs based in China targeted its generally available Claude models through illicit distillation attacks, using industrial-scale methods to extract and replicate capabilities without authorization. The company detailed the activity in a report released Thursday, Sept. 10, 2026.
Illicit distillation defined as covert capability extraction
Anthropic defined illicit distillation as an industrial-scale, covert campaign to extract a model’s capabilities and replicate them in another model without authorization. It said the process is typically enabled by fraud, including sophisticated networks of fake accounts created with stolen credit cards, login credentials, and API keys.
Why safeguards do not carry over
Anthropic said safeguards built into Claude do not transfer when models are distilled by an unauthorized lab. It also warned that distilled models derived from frontier models can help achieve dangerous capabilities.
Risks from third-party model routing and exposed data
The report also cited a data exposure risk tied to exchanges relayed from users of third-party model routing services. Anthropic said those exchanges may contain users’ sensitive data.
Ongoing disruption and broader IP theft concerns
Anthropic said it is developing more effective methods to combat illicit distillation as unauthorized labs adapt and bypass hurdles. It added that findings from investigations and disruptions will continue to inform safeguards.
Separately, Google Threat Intelligence Group (GTIG) said in a February blog post that distillation attacks, also called model extraction attacks, represent a new form of intellectual property theft tied to the growing adoption of AI models.
Government pressure on alleged AI model theft
In July, Treasury Secretary Scott Bessent told Fox Business that the White House was weighing a crackdown on China’s alleged “IP theft” of AI models in the United States. He said sanctions could be applied if overseas models are stealing from U.S. companies.
Why it matters
Industrial-scale model extraction changes the enforcement problem for AI providers. If safeguards do not transfer and stolen access credentials enable rapid replication, it becomes harder to protect both model value and user data.