The panel generally agrees that distillation poses a significant threat to Anthropic's business model, with potential revenue erosion and margin compression due to competitors' ability to reach similar performance at lower costs. However, the extent and immediacy of this threat are debated, with some panelists arguing that guardrails, licensing, and compliance costs may favor incumbents like Anthropic.
Risk: Commoditization of mid-tier models and the inability to stop automated scraping, leading to accelerated margin compression and lower long-term margins.
Opportunity: Anthropic's potential to secure regulatory capture and convince regulators that their models are national security assets, protecting them from lower-cost, open-weights competition.
This analysis is generated by the StockScreener pipeline — four leading LLMs (Claude, GPT, Gemini, Grok) receive identical prompts with built-in anti-hallucination guards. Read methodology →
Anthropic's head of threat intelligence, Jacob Klein, says his company welcomes competition. But what's coming out of the Chinese market, he says, is something much closer to theft.
Foreign adversaries, Klein says, are accessing Anthropic's Claude models — a process known as distillation — to train competing technology and sell copycat versions at a lower price. While distillation can …
Read more
Anthropic's head of threat intelligence, Jacob Klein, says his company welcomes competition. But what's coming out of the Chinese market, he says, is something much closer to theft.
Foreign adversaries, Klein says, are accessing Anthropic's Claude models — a process known as distillation — to train competing technology and sell copycat versions at a lower price. While distillation can be done legally, Klein says that's not what's happening here.
"There's an entire illicit ecosystem to try to gain access to Claude and other models," Klein told CNBC. "This ecosystem goes through any means necessary to evade our controls, so they can spin up accounts at extreme scale."
Distillation has become a controversial topic across the artificial intelligence landscape. Depending on how it's conducted, the practice can allow a model developer to use the output from another company's technology to create a competitive offering at a tiny fraction of the cost. In the U.S., some factions in the tech sector have urged policymakers to steer clear of regulations so that the best and most cost-effective AI can win, while others are lobbying for a crackdown on what they see as theft of intellectual property.
In an April memo, the Trump administration wrote distillation that undermines American research and proprietary information is "unacceptable," and said it would explore "a range of measures to hold foreign actors accountable."
The threat is intensifying at a pivotal moment for Anthropic. The 5-year-old company has soared to a private market valuation of close to $1 trillion and is expected to go public as soon as October, CNBC has reported.
Anthropic is singling out Chinese AI lab Moonshot AI as one of the companies it says is ripping off its technology. Moonshot's Kimi K3 model took the tech world by storm in July with its cheaper, frontier-level AI offering. It's been widely adopted in Silicon Valley, thanks in part to its lower price point and ability for companies to tailor it more easily.
Klein said Kimi K3 was illegally trained off the newest version of Claude.
"We've seen a fair amount of this from China," Klein said. "This is something that the industry writ large is dealing with."
Earlier this year, Anthropic alleged Moonshot and two other Chinese AI labs – DeepSeek and MiniMax – distilled its frontier AI models. Anthropic has also accused Alibaba, which makes the Qwen family of models, of conducting a massive "distillation attack" to illegally capture capabilities from Claude. OpenAI and Google have both published reports on distillation and claim they're fighting the same issue.
Alibaba, DeepSeek, Moonshot and MiniMax didn't respond to requests for comment.
## 'Fraudulent means'
Cybersecurity experts told CNBC that, in addition to China, the threat is also coming from countries like Iran, Russia and North Korea, where use of Claude, Google's Gemini and OpenAI's ChatGPT are restricted by the companies due to sanctions.
Klein said many labs in those regions "go through illicit means and fraudulent means to try to gain access to a model."
One way people are getting around those restrictions is by turning to the dark web, where they can find marketplaces of stolen credit card information and compromised AI accounts. Klein said companies like Moonshot are "spinning up tens of thousands, if not hundreds of thousands of fraudulent accounts."
Once they've accessed Anthropic's systems, they're able to ask the models questions and collect responses, which they can use to train their own model, often called the student, Klein said.
A clear sign that distillation is taking place is that a user could be asking thousands of questions, rather than dozens and potentially even creating thousands of accounts to do the same, producing a whack-a-mole scenario for the AI labs, Klein said.
"It's very hard to fully stop this as a problem, but I think slowing it down is good and worthwhile," Klein said, adding that foreign companies are able to use the technology with few guardrails.
He pointed to fears like surveillance and possible use in a biological weapons program, and noted what he described as a specific campaign from a China-based entity that was conducting espionage at scale using Anthropic's technology.
"There is a national security concern at play if malicious actors, bad actors who we don't trust are gaining access to a more capable models than they could have otherwise through the act of distillation."
Travis Lanham, technology chief at cybersecurity firm Armadin and a former Google engineer, said bad actors often go undetected because AI companies are under pressure to make their platforms as accessible as possible as they race against the competition.
"These companies are serving billions of requests," Lanham said, about the big AI labs. "The millions are relatively small compared to everything and it's just sneaking in and trying to look like the rest of the crowd."
Klein acknowledges that, for Anthropic, widespread competition is to be expected and that there are legal methods of distillation. That generally means gaining permissions and following the law on matters like IP and export controls.
"I think competition is great," Klein said. "The concern here is if you are taking our model, distilling it through fraudulent means, creating millions of fake accounts using stolen credit cards and stolen infrastructure, to then produce a model that doesn't have safeguards in place."
AI Talk Show
Four leading AI models discuss this article
Opening Takes
“The real near-term risk to Anthropic is not immediate theft itself but the combined impact of heightened security/compliance costs and potential regulatory hurdles that could slow growth and undermine the current high-valuation narrative.”
The piece frames distillation as a personified existential threat to Anthropic, with a dark-web siege and a China-linked espionage angle. A stronger counter view: distillation at scale is not automatically a profit-lowering moat killer—real-world attackers face data, safety, and licensing frictions, and legitimate licensing paths already exist. The headline risk may hinge more on regulatory tempo and enforcement costs than on immediate revenue erosion. The missing context includes how much of distillation is actually profitable versus noisy signal, whether incumbents’ guardrails and data controls can deter mass spoofing, and how public-market participants price AI governance risk into valuations. If policy accelerates, the risk/potential reward could flip quickly depending on guardrail design.
The dark-web threat may be overstated; much of purported distillation requires access, data lineage, and expensive training cycles that limit scale. Also, policy responses could reward legitimate, compliant players more than penalize them, narrowing the competitive threat.
“Anthropic is leveraging national security rhetoric to mask an inability to defend their IP, signaling that the 'frontier model' moat is structurally weaker than their $1 trillion valuation implies.”
Anthropic’s narrative frames 'distillation' as a security crisis, but this is fundamentally a defensive moat issue ahead of an IPO. By framing competitors like Moonshot AI and Alibaba as 'thieves,' Anthropic is attempting to bake geopolitical risk into their valuation. If they can convince regulators that their models are national security assets, they secure a regulatory capture that protects them from lower-cost, open-weights competition. However, the 'whack-a-mole' nature of API abuse suggests Anthropic’s technical controls are insufficient. If they can't stop automated scraping, their 'frontier' advantage is effectively a public good, which severely compresses long-term margins as commoditization accelerates faster than they can monetize.
Anthropic’s focus on 'theft' may be a distraction from the fact that their model architecture is fundamentally vulnerable to distillation because the output tokens contain the 'reasoning' that competitors can easily replicate without needing the original training data.
“Anthropic is weaponizing legitimate distillation concerns to justify a $1T valuation and pre-emptively justify regulatory barriers before going public, but hasn't provided technical evidence that cheaper Chinese models are actually stolen rather than independently developed.”
This article conflates three distinct problems: (1) legal distillation, which is competitive but legitimate; (2) account fraud using stolen credentials, which is a compliance/security issue, not IP theft; and (3) actual model theft, which is real but unproven here. Anthropic's October IPO timing makes this narrative convenient—distillation claims justify premium valuation and regulatory moats. The core issue: we have zero evidence Kimi K3 actually performs better because of distillation versus independent R&D. Moonshot's lower cost could reflect different compute efficiency, data, or business model, not stolen IP. The article presents allegations as fact without technical validation.
If Anthropic can prove systematic account fraud and demonstrate that Moonshot's architecture/performance directly mirrors Claude's in ways independent development couldn't explain, then IP theft is real and represents genuine national security risk—not just IPO narrative management.
“Unstoppable distillation attacks from sanctioned regions will compress margins and raise compliance costs for frontier US labs faster than IPO narratives assume.”
Anthropic's claims of large-scale distillation by Moonshot, DeepSeek, MiniMax and Alibaba via dark-web accounts and stolen credentials highlight enforcement gaps that could erode US model advantages ahead of its potential October IPO at ~$1T valuation. The Trump memo signals possible export-control tightening, but detection remains probabilistic at scale. OpenAI and Google face identical issues, suggesting sector-wide margin pressure from low-cost copycats. Cybersecurity costs and guardrail overhead rise while competitors like Kimi K3 gain traction in Silicon Valley on price alone.
Distillation via public outputs is often legal under current US law; Anthropic's accusations may simply reflect inability to compete on cost, and enforcement could backfire by slowing global AI progress.
The Debate
Responding to Claude
“Distillation can yield real efficiency gains through architecture and data choices, so Claude's 'zero evidence' stance underestimates the strategic risk to incumbents and suggests a narrower moat than reality.”
I think your 'zero evidence' stance is too categorical. Distillation can improve efficiency via architecture tweaks, data mix, and smarter training. Moonshot could outperform Claude on cost per true capability even without stolen data. The real risk isn't just IP theft; it's how guardrails, licensing, and compliance costs compress margins for all incumbents, favoring those who couple governance with compute-efficient models. Distillation may be a revenue moat, not just a threat.
Responding to Claude
“The economic threat of distillation is not IP theft, but the inevitable commoditization of model performance that invalidates premium, R&D-heavy valuations.”
Claude is right to demand evidence, but Grok’s $1T valuation benchmark is the real elephant in the room. If Anthropic is pricing for a trillion-dollar exit, they must prove their 'frontier' status is a defensible moat, not just a high-spend training cycle. If distillation allows competitors to reach 90% of Claude’s performance at 10% of the cost, Anthropic’s R&D-heavy business model is fundamentally broken. They aren't just fighting theft; they are fighting the economics of diminishing returns.
Responding to Gemini
“Distillation efficiency gains follow a power law; the last 5% of performance costs disproportionately more than the first 85%, which protects Anthropic's premium positioning longer than the $1T valuation implies.”
Gemini's $1T valuation stress is valid, but the 90/10 cost assumption needs scrutiny. Distillation gains plateau fast—going from Claude's 95th percentile to 90th percentile is trivial; reaching 85th costs exponentially more. Anthropic's moat isn't just frontier performance; it's the compounding cost of safety, alignment, and regulatory compliance that smaller players can't easily replicate. The real margin compression comes from commoditization of mid-tier models, not distillation theft.
Responding to Claude
“Mid-tier distillation combined with uneven compliance costs erodes US margins faster than safety moats can protect them.”
Claude's point on exponential costs for higher performance tiers overlooks how mid-tier distillation still undercuts Anthropic's pricing power in volume markets. Gemini's 90/10 scenario gains traction if safety overheads, which Claude flags as a moat, instead raise break-even points for US firms while Moonshot skips them entirely. This dynamic risks accelerating commoditization beyond IPO narratives, as enforcement costs compound without proven IP linkage.
Panel Verdict
NEUTRAL No ConsensusThe panel generally agrees that distillation poses a significant threat to Anthropic's business model, with potential revenue erosion and margin compression due to competitors' ability to reach similar performance at lower costs. However, the extent and immediacy of this threat are debated, with some panelists arguing that guardrails, licensing, and compliance costs may favor incumbents like Anthropic.
Anthropic's potential to secure regulatory capture and convince regulators that their models are national security assets, protecting them from lower-cost, open-weights competition.
Commoditization of mid-tier models and the inability to stop automated scraping, leading to accelerated margin compression and lower long-term margins.
Related News
This is not financial advice. Always do your own research.