EN

The AI War: Anthropic’s Hidden Code Tracked China’s “Distillation” Push

Khaled Aziz

1- The Washington Post reported that Anthropic quietly used tracking code to monitor China-based Claude Code users.
2- U.S. AI firms accuse Chinese rivals of using “distillation” to make cheaper models smarter with American systems.
3- The dispute is now bigger than business: it cuts into privacy, export controls and the U.S.-China race for AI power. The latest

Anthropic secretly deployed software in March to identify China-linked users of Claude Code, The Washington Post reported, in an effort to catch Chinese AI companies suspected of using its technology to improve their own models. The company later removed the tracker after a developer exposed it and privacy advocates criticized the move as surveillance of Anthropic’s own users.

Details

The hidden code: The Washington Post said Anthropic’s tracker checked whether a user’s computer was set to Chinese time zones or linked to domains tied to Chinese AI firms.

The rollback: An Anthropic executive described the tracker as an “experiment” and said the company would replace it with better defenses.

The core allegation: Anthropic and OpenAI accuse Chinese companies of using “distillation” to train smaller models on outputs from stronger U.S. systems.

Alibaba claim: Anthropic told U.S. senators that Alibaba’s Qwen team allegedly used about 25,000 fraudulent accounts to generate more than 28.8 million Claude exchanges.

Other targets: Anthropic previously accused DeepSeek, Moonshot and MiniMax of similar campaigns, saying they were becoming more intense and sophisticated.

China’s gains: The Post reported that Chinese models have repeatedly matched new U.S. capabilities within months, with free and open Chinese models gaining strong global use.

Zhipu test: Cybersecurity firm Semgrep said a free Zhipu AI model outperformed Anthropic’s Claude Opus 4.8 in finding software vulnerabilities.

Academic evidence: Researchers from Peking University and the Chinese Academy of Sciences found signs of distillation in several Chinese models, including Alibaba’s Qwen.

Qwen clue: In intensive tests cited by The Post, one Qwen model reportedly misidentified itself as Claude nearly a third of the time.

Washington’s concern: The White House warned that Chinese firms were running industrial-scale distillation campaigns against U.S. AI systems.

Harder controls: Anthropic has blocked mainland China and Hong Kong access, expanded restrictions to Chinese-owned entities abroad and required ID checks for some users.

Workarounds: The company said it has banned nearly 700,000 accounts using Claude in China, while proxy networks and resellers continue to offer access.

Between the lines

The U.S. case is not clean-cut. Distillation is common in AI and not automatically illegal. The fight is over unauthorized use, scale and whether Chinese firms are turning American models into low-cost tutors for competitors that can undercut Silicon Valley.

Background

The fight comes as Chinese AI systems become cheaper, more accessible and increasingly competitive. Some U.S. researchers and startups now rely on open Chinese models, making any American crackdown risky for domestic users as well as Chinese rivals.

What to watch

Watch for tougher U.S. identity checks, new export-control rules, Chinese company responses, and whether Washington moves to restrict American use of Chinese open-source AI models.

What to read next

U.S and Iran Edge Closer to a Wider War After U.S. Troops Killed