AI: what is the “adversarial distillation” that ANTHROPIC accuses ALIBABA of using?
To contact us: editorial@fw.media

Artificial intelligence is entering a new phase of its geopolitical confrontation. After the battle over semiconductors, data centres and the latest-generation chips, tensions are now focusing on the exploitation of the models themselves.
According to Bloomberg, Anthropic claims in a letter that Alibaba orchestrated a campaign between April and June 2026 involving nearly 25,000 fraudulent accounts and 28.8 million interactions with Claude. According to the US company, the objective was not to use its conversational assistant, but to systematically extract its capabilities in order to train competing models. In a letter sent to several US senators and the White House, Anthropic described the operation as an industrial-scale “adversarial distillation” campaign.
An established technique becomes a national security issue
Distillation is not inherently illegal. It has been a standard machine-learning technique for several years.
The principle is straightforward. A large model, known as the “teacher”, is used to train a second, more compact model known as the “student”. The latter learns to reproduce the teacher’s behaviour while requiring considerably less memory, computing power and inference expenditure. The technique is used throughout the industry to deploy models on smartphones, embedded devices and lower-cost infrastructure.
In this context, distillation is a perfectly legitimate optimisation tool. “Adversarial distillation” follows a radically different logic.
Instead of using its own system as the teacher, the laboratory seeking to train a model queries a competitor’s model at scale, collects and structures its responses, and then feeds them back into its own training process.
In this case, Claude would unwittingly become the teacher of a competing model.
This distinction is essential. Anthropic is not condemning distillation itself, but its unauthorised use against a proprietary model to reproduce part of its capabilities.
Reproducing years of research at a fraction of the cost
The economics of frontier models explain the strength of Anthropic’s response.
Developing a model such as Claude requires investments running into several billion euros. Laboratories mobilise hundreds of thousands of GPUs, some of the world’s most powerful computing infrastructure and several months of continuous training. These costs are compounded by expenditure on datasets, alignment, safety evaluations and research teams.
Distillation promises to reduce that bill considerably.
By querying an existing model across millions of cases, a company can capture reasoning patterns, problem-solving strategies, alignment preferences and specialised behaviours in fields such as programming or autonomous agents. It does not directly copy the model’s weights, but seeks to reproduce its observable behaviour.
For US laboratories, this approach amounts to capturing part of the value created during training without bearing the same investment. This economic asymmetry is fuelling concerns across the industry.
Why Anthropic describes an industrial operation
The figures cited by Anthropic illustrate the scale of the alleged operation. The company reportedly identified nearly 25,000 fraudulent accounts that generated 28.8 million conversations within three months. According to Anthropic, the requests primarily targeted Claude’s most advanced capabilities, particularly software development and agentic reasoning.
This description goes far beyond the simple misuse of an API. Anthropic depicts an automated infrastructure capable of circumventing account restrictions, distributing requests across large numbers of identities and systematically collecting the model’s responses. Its use of the term “industrial scale” places these practices closer to cyberespionage campaigns or large-scale data-harvesting operations.
Republican Senator Bill Hagerty of Tennessee and Democratic Senator Andy Kim of New Jersey are reportedly preparing to introduce an amendment that would sanction companies engaging in such practices.
Where does learning end and copying begin?
The case nevertheless raises a legal question that remains largely unresolved. Every laboratory evaluates its competitors’ models. Public benchmarks, performance comparisons and response analysis are standard practices in artificial intelligence research.
The difficulty lies in determining when evaluation becomes an attempt at industrial replication. Is it defined by the number of queries, their automation, the intended objective or the dataset created from the responses?
No legal framework currently provides a clear answer to these questions. This grey area explains why Anthropic is seeking to move the debate from contractual law to national security. If distillation is presented as a strategic threat rather than a simple breach of API terms of service, it opens the way to economic sanctions and government intervention.
A new frontier for cybersecurity
The consequences will also be technical. Laboratories will probably never be able to prevent distillation entirely. They will, however, attempt to make it more difficult, more expensive and easier to detect.
This is opening a new field for cybersecurity applied to artificial intelligence.
Behavioural user detection, dynamic rate limiting, response fingerprinting, intelligence sharing between laboratories and watermarking mechanisms are among the approaches already being explored by major US companies.
As models become more valuable, their APIs are also becoming critical infrastructure.



