HomeArticle

Anthropic's "victim" mask

定焦One2026-09-18 12:19
What Anthropic calls "AI safety" is increasingly resembling a business.

On September 10, Anthropic released a threat intelligence report covering AI "misuse" behaviors including cyberattacks and illegal model distillation. The most notable part of the report names 7 Chinese AI companies and accuses them of conducting "industrial-scale distillation" against Claude. This marks the third time the company has publicly made such accusations since the beginning of this year.

The "distillation" at the center of the accusations is by no means a new technology. In 2015, a paper from the Google Brain team established it as a model training method, which has since been used internally by major laboratories around the world. The technology itself is neutral. The industry has debated for years about where its application boundaries lie and whether it constitutes infringement, and no conclusion has been reached to this day.

Why would a leading company make three public accusations against this neutral conventional technology in more than half a year, with each outcry louder than the last? To answer this question, we need to connect the moves Anthropic has made in recent months.

In June this year, Anthropic secretly submitted an IPO application to regulators, sprinting for what could become the largest listing in history; in July, it became the only leading company in Silicon Valley that refused to sign the open source open letter; on September 12, two days after the report was released, founder Dario Amodei published a long article calling on the entire industry to slow down the iteration speed of the most powerful models to make time for safety verification.

Putting these moves together, they present a thought-provoking contrast: on one hand, the company constantly emphasizes AI risks and calls for the industry to slow down, while on the other hand, it pushes forward commercialization and listing at the fastest speed; on one hand, it puts safety at the top of its corporate mission, while on the other hand, it locks the most valuable model capabilities firmly in the closed-source system to capture the most lucrative profits in the industrial chain.

Anthropic is no longer just a model supplier. It is simultaneously acting as an application competitor, risk interpreter and rule advocate, and trying to influence open source policies, define technical boundaries and crack down on potential competitors in the name of "safety".

At the end of the day, Anthropic is not simply safeguarding AI security. What it really wants to defend is its own technical barriers, commercial interests and industry status.

01. Anthropic's "Victim" Mask

In Anthropic's narrative, it is always the attacked party. The accusation against "distillation" is exactly this case.

In 2015, Geoffrey Hinton, who had just joined Google Brain, together with team leader Jeff and researcher Oriol, published a paper that systematized the previously scattered ideas of model compression for the first time and named it "knowledge distillation". Since then, from leading laboratories to the open source community, distillation has been widely used for model compression and post-training.

Its basic logic is not complicated: use a more capable "teacher model" to generate results to improve the smaller-scale "student model". The student model can not only learn the probability distribution of each Token output by the teacher model and the chain of thought, but also directly learn the final answers generated by the teacher model, the so-called "hard distillation".

In the large model industry, distillation is generally regarded as an efficient post-training method. It is a neutral technology in itself, neither a decisive factor of model capability nor a moat that can be formed alone.

Since the beginning of this year, Anthropic's accusations against "distillation" have escalated step by step. In February, it publicly accused three companies, DeepSeek, Moonshot AI and MiniMax, of generating more than 16 million interactions with Claude through about 24,000 fake accounts; in June, it wrote to US congressmen accusing another leading Chinese laboratory of launching "the largest distillation attack in history"; the September 10 report further expanded the scale to nearly 200 million interactions, named 7 Chinese companies, and described the characteristics of the so-called "industrial scale" with monitoring data such as the number of accounts and interaction frequency.

However, at the legal level, "distillation" itself is difficult to be directly characterized. Anthropic's terms of service prohibit users from using Claude's output to train competing models, which means that even if the accusations are established, the most direct basis is the breach of contract at the contractual level. What's more, all the above interaction data come from Anthropic's own monitoring system and have not been verified by any independent third party.

Among the named companies, Alibaba has denied any improper behavior, and many others have not responded publicly.

Faced with the so-called "largest attack in history", Anthropic did not first bring the dispute to court, but chose to write to congressmen and release threat intelligence reports, turning technical disputes into public issues. Because the court requires evidence, while the public opinion field only needs a sufficiently sensational report.

From a deeper technical perspective, distillation cannot be proven, nor can it be falsified. Today no company can prove that it has been distilled by another company, nor can it prove that it has never distilled others.

The US industry's attitude towards the line of "technology is innocent" is even clearer. At the end of July, 25 institutions including NVIDIA, Microsoft, Meta and IBM published a joint letter emphasizing that distillation is widely used for model improvement, evaluation and verification, and should not be confused with illegal extraction. Jensen Huang, CEO of NVIDIA, also publicly stated that distillation and learning from various knowledge sources are the foundation of intelligent development, and what should be held accountable are specific acts that violate privacy and contracts, not the technology itself.

The debate over distillation has largely evolved into a Rashomon situation where each side tells its own version of the story.

A copyright lawsuit that Anthropic itself experienced exposed an awkward fact: the company does not stand on a naturally clean moral high ground.

In the case where writers sued the company, court documents revealed that Anthropic downloaded more than 7 million copies of books from pirated sources to build an internal database, and then selected some of the materials to train the model.

In June 2025, the judge ruled that the model training involved in the case was fair use, but did not extend this conclusion to the act of downloading and retaining pirated books to build a permanent database. The two parties finally reached a $1.5 billion settlement, which was finally approved by the court on July 20, 2026. The settlement does not constitute an admission of liability by Anthropic, nor does it resolve all copyright issues related to AI training, and Anthropic does not admit that it has any fault.

It is somewhat ironic that a company that once fell into a copyright lawsuit due to the way it obtained training materials and finally paid a $1.5 billion settlement cost now stands on the moral high ground and accuses its peers of "distillation".

Anthropic can certainly investigate and hold accountable acts that violate contracts and privacy rules, but it is not qualified to package itself as a moral referee in the AI technology world.

02. When "Safety" Becomes a Commercial Weapon

If the distillation accusation shapes Anthropic's image as a "victim", the game around open source models can better reveal the commercial use of this image.

Around July 24, NVIDIA led 25 AI industry chain related institutions to launch a joint letter titled "Open Weights and US AI Leadership". The signing list expanded rapidly afterwards, including Meta from the open source camp, chip companies NVIDIA and AMD, as well as cloud platforms such as Microsoft and Google, and even OpenAI from the closed source camp finally signed the letter.

Among the leading US AI companies, only Anthropic was absent. Many other industry insiders revealed that the company is lobbying the government to restrict open source models.

Under pressure, Amodei published a long article in response on July 28. He made it clear that Anthropic has never advocated banning open source models. But he also emphasized that once a sufficiently powerful model opens its weights, it cannot be retrieved, and it would be too dangerous if it falls into the hands of bad actors.

Although Amodei did not explicitly say that he wanted to ban open source models, the AI safety he repeatedly emphasized and his repeated accusations of distillation attacks by open source model manufacturers all reflect his "suppression" of open source. This is the brilliance of "safety" as a commercial weapon: Anthropic does not need to publicly shout "ban open source". As long as it continuously associates open source models with security risks, malicious use and national security, the policy environment will naturally become more unfavorable to open source.

The reason for this is that as open source models continue to approach closed source models, Anthropic's profit moat is being eroded.

According to a SemiAnalysis report, Anthropic is expected to achieve its first operating profit of about $559 million in the second quarter, and its earnings before interest and taxes under GAAP caliber in the third quarter is expected to exceed $1 billion; annualized recurring revenue will climb from about $9 billion at the end of 2025 to more than $60 billion.

If channel sharing and model training costs are excluded, Anthropic's gross margin may exceed 80%.

Therefore, suppressing open source and sprinting for IPO are actually part of the same overall plan. On June 1, Anthropic secretly submitted its S-1 draft to the SEC. In this context, if open source models are locked out by policy restrictions, the choice set of enterprise customers will narrow, the certainty of revenue will rise, and policy barriers can be transformed into valuation premiums.

Looking back, Anthropic's "attack" on open source models has almost synchronized with the company's valuation. Shortly after publicly accusing Chinese open source model companies of distillation attacks in February this year, Anthropic's valuation exceeded $1 trillion on the private secondary market platform Forge Global, surpassing OpenAI. The September distillation report coincided with the key preparation period for listing after the submission of documents.

For a model company about to enter the capital market, the fewer competitors it has, the stronger the narrative of its leading model, and the more concentrated its revenue is on itself, the easier it is to push up its valuation. If it can even use the name of "safety" to get regulators to raise the competition threshold for it, it will obtain a moat built by policies.

Moreover, from the perspective of the entire AI industry, closed-source model companies represented by Anthropic are not only harvesting the capital market, but also grabbing a large share of the profits of the entire industrial chain. The high gross profit margin of closed-source manufacturers is also squeezing the profit space of the entire AI industry chain, which will affect both upstream hardware manufacturers and downstream cloud vendors and application vendors. If the open source model route is stifled, Anthropic's profit space will only be larger, which is what other participants in the industry do not want to see.

A point of reference is OpenAI. After Amodei published the long article advocating "slowing down", OpenAI CEO Sam Altman publicly expressed his approval, and confirmed in an interview with the media that OpenAI will not conduct an IPO this year. The two largest closed-source model companies made opposite choices in the same month: one postponed the listing in the name of safety, and the other sprinted for listing amid the outcry for safety.

03. Public Outrage in Silicon Valley, Competitors Are Catching Up

The troubles Anthropic is facing are no longer just doubts from competitors. C-end users are beginning to worry about data privacy, B-end enterprises are beginning to be alert to its unbounded expansion into the application layer, and Chinese open source models are moving from technological catch-up to commercial counterattack.

A company that calls on the entire industry to maintain a high degree of vigilance against AI risks should first maintain the same strict standards for its own data boundaries. However, at the level of user agreements, Anthropic's differentiated arrangements have long sparked discussions. Individual users using Claude Free, Pro and Max do not enjoy the Zero Data Retention (ZDR) agreement, and paid subscriptions do not mean zero retention. ZDR is only provided as a special arrangement to some API customers and approved Claude Code enterprise customers.

In other words, ordinary users' conversation data may be used for model training by default. In January this year, an overseas developer found when checking the proxy logs that the Claude Code backend sent requests to a website every few seconds, with a frequency close to real-time monitoring. His inquiry on GitHub did not get a substantive response.

Anthropic's accusation against distillation this time also demonstrates its detailed mastery of user interaction data. In the report, it accurately describes the conversation content of specific users. Anthropic explained that the monitoring is done by a classifier running automatically in the background, not by manually reading conversations.

In addition to C-end users' concerns about Anthropic's privacy protection, B-end enterprises are also resisting Anthropic's unbridled expansion.

According to foreign media reports on July 29, a wave of resistance against Anthropic is accumulating in Silicon Valley, rooted in the fact that its products compete with existing software providers and its advocacy of a closed AI ecosystem. One of the triggers was Claude Design released in April, a product considered to directly target Figma, a design software company that is its partner.

In addition, according to media reports, NVIDIA, Palantir and Booz Allen Hamilton have begun to restrict the internal use of Anthropic's AI models. These companies are worried that after employees input sensitive information such as internal codes and intellectual property into external AI models, the model providers may access or even learn from these data.

A more practical pressure than public opinion resistance comes from the catch-up of the accused. The Stanford University 2026 AI Index Report shows that the score gap between the top models of China and the United States has narrowed to about 2.7%, and the models of the two countries have taken the top spot alternately many times since the beginning of 2025. The report also pointed out that China's advantages lie precisely in open source exploration, application implementation and basic research transformation.

Apart from the approaching capabilities, Chinese open source models are entering Anthropic's hinterland commercially. Kimi K3, which became the world's largest open source model with 2.8 trillion parameters after being open sourced in July this year. According to foreign media reports, Moonshot AI is negotiating with Microsoft, Amazon and Google, the three major cloud vendors, to get Kimi K3 deployed on the three platforms and obtain up to 30% revenue sharing. If reached, it will be one of the first important sharing agreements between Chinese AI companies and US cloud giants.

On September 16, Zhipu AI stated at an investor conference call that it has signed revenue sharing agreements with many leading cloud service providers at home and abroad, and the GLM series open source models will be provided as hosted APIs on overseas cloud platforms, and relevant revenue will be recognized starting in October. A week earlier, the company had just completed a $5 billion financing round.

From spending money to buy overseas computing power to exporting models to overseas cloud platforms and participating in revenue sharing, the roles of Chinese open source companies and the global cloud computing industry are being reversed. This also actually explains why Anthropic's suppression has had limited effect. When the technology gap narrows to single-digit percentage points and open source models move into overseas cloud platforms in a revenue-sharing mode, the blocked are becoming business partners of the blockers' allies.

At the IPO node, the AI security, open source threats and distillation attacks claimed by Anthropic have been deeply intertwined with its own commercial interests.

In 1959, American inventor Thomas Carter began to sell a device called the Carterfone, which allowed walkie-talkie users to talk over the telephone network. Telecom giant AT&T banned users from accessing it, on the grounds that the company was responsible for maintaining the network and must control the access equipment. In 1968, the US Federal Communications Commission ruled that the Carterfone did not harm the telephone system, and the blanket ban on external device access was unreasonable and discriminatory.

A leader in an industry can participate in formulating technical standards and put forward initiatives for the future development direction of the industry, but "safety" should not become a weapon to crack down on competitors, let alone a bargaining chip for leading enterprises to seek competitive barriers from regulators.

What the AI industry really needs to be alert to is not only the out-of-control of models, but also the situation where "safety" is commercialized and becomes a tool for a