America built the most expensive teachers in history, then put them on a metered API. The distillation fight is the invoice arriving.
- Anthropic says three Chinese laboratories ran roughly 24,000 fraudulent accounts through Claude to generate more than 16 million exchanges. DeepSeek, the name Washington uses as shorthand for copying, accounts for under 1% of that traffic.
- In July the argument left the corporate blog and entered the White House. Moonshot’s Kimi K3 shipped fifteen days after the model it is accused of copying went on general sale.
- Nvidia, Microsoft and Meta were among the original signatories. OpenAI and Google joined later, while Anthropic did not.
Somewhere in the small hours, a script wakes up and starts asking questions. Not especially clever questions: write this function, trace this error, plan these six steps and use these tools in this order. It asks a few thousand times, goes quiet, then returns through a different account from a different address and asks again. By Anthropic’s account, roughly 24,000 fraudulent accounts asked more than 16 million times before the door was shut on them.
The lab everyone blames barely turned up
The company says the traffic came from three Chinese laboratories and went hunting for exactly what Claude does best: agentic reasoning, tool use, coding, data analysis. Anthropic published a breakdown. Almost nobody quotes it, because it does not say what the headlines say.
Exchanges attributed to each laboratory in Anthropic’s February disclosure. Allegations, not adjudicated findings. Source: Anthropic, 23 February 2026
MiniMax, a name that barely surfaces in the political version of this story, is four-fifths of it. DeepSeek, which is most of the political version, is a rounding error. That gap between the ledger and the rhetoric is worth holding on to for the rest of the argument.
Nothing was smuggled. Everything went through the till.
Distillation is neither exotic nor illegitimate. A large model answers; a smaller model trains on those answers and inherits some of the behaviour without inheriting the cost. Every serious laboratory does it in-house, to turn one expensive system into a family of cheap ones. The technique is not the argument. Permission is.
And this is where the fight is usually graded wrong. It is described as theft of a thing, as though weights had left a building in a bag. Nothing left any building. Everything was requested, served and billed at list price, one prompt at a time, through the front door the vendor built, priced and advertised. There is no burglary in the story. There is a customer.
A frontier laboratory is not a factory with blueprints in a safe. It is a tutor who charges by the minute and cannot stop teaching once the minute begins.
Then Washington named a model
Which is why February did not end it. On 16 July, at the World Artificial Intelligence Conference in Shanghai, Moonshot released Kimi K3: 2.8 trillion parameters, open weights, free to download, benchmarked close enough to the American frontier that US AI equities wobbled on the news.
Six days later Michael Kratsios, who runs the White House Office of Science and Technology Policy, posted that the administration had information Moonshot had distilled Anthropic’s Fable model to build it – through a purpose-built internal platform that switched between access routes to avoid detection, and Nvidia GB300 hardware reached via Thailand. Treasury Secretary Scott Bessent followed within hours: sanctions and Entity List designations were on the table. Beijing’s commerce ministry called the whole thing AI hegemonism and promised all necessary measures.
Then somebody looked at a calendar.
Fifteen days separate the teacher going on general sale from the student shipping. Fable 5 returned to public availability on 1 July after a three-week export-control suspension.
Fable 5 had been on general sale for a fortnight when Kimi K3 shipped. Researchers who train large models for a living have pointed out, politely, that you cannot pre-train and post-train a 2.8-trillion-parameter system on fifteen days of borrowed answers. That does not prove nothing was extracted. It means extraction, if it happened, was seasoning rather than the meal – and that in this instance the accusation arrived some distance ahead of the evidence.
The leak that proves the dam is holding
The most revealing part of Anthropic’s February disclosure was never the accusation. It was the conclusion drawn from it. Extraction at that scale, the company argued, itself requires advanced chips – therefore distillation attacks strengthen the case for export controls rather than undermining it.
It is a genuinely elegant move: evidence of a leak, converted into evidence that the dam is holding. It also only works if you already believe the conclusion. Run it the other way. If a fortnight of API access and a few thousand spoofed accounts can meaningfully narrow a capability gap that cost tens of billions of dollars to open, then the chips were never the binding constraint. The product was. Every answer a frontier model sells is a small, irreversible transfer of the thing that made it expensive, and the transfer is not a bug in the business model. It is the business model.
Seen from India, it is a procurement question
For everyone outside the argument, and for Indian enterprises buying inference by the million tokens above all, none of this is a moral dispute. It is a purchase order. A capable open-weight model that can be run inside your own network, under Indian data rules, at a fraction of frontier pricing, is a commercial fact regardless of how it was trained. Sanctions and Entity List designations may make it awkward to buy from the front. They will not make it worse at the job, and they will not make the frontier alternative cheaper. Every escalation in Washington quietly raises the return on running your own weights.
The next war has no customs officers
The first AI war was fought over chips, which carry serial numbers, cross borders in crates and can therefore be counted by people in uniform. The next is being fought over answers, which have neither. Every frontier laboratory is obliged by its own business model to answer questions from strangers for a fraction of a cent, and every answer gives away a sliver of what made it expensive.
You can raise the fee. You can check papers at the door and throw out the students who came in through the window. What you cannot do is sell the lesson and keep it.
The teacher may still be the best in the world. It stopped being the only one who knows the moment it opened its mouth.
So what exactly is left to protect?