ThinkPatternGet the app
Perspective
TECHNOLOGY · JUL 28, 2026

The Distillation War Has No Good Defenses

The shift from chips to models has created a trap the chip war never had: the only way to stop distillation is to close the commercial product that makes your model dominant, and both sides are now building the exact restrictions they accuse the other of violating.

While the US government threatens sanctions against Chinese firms for distilling American AI models, Microsoft is selling access to those same models — OpenAI's, via Azure — to the very companies accused of doing the distilling. ByteDance alone pays over $1 billion annually for the access; Tencent, Ant Group, and Meituan are also customers. [1] This is not a scandal waiting to be exposed. It is the structural condition that now defines the US-China AI conflict, and it explains why six months of escalating accusations have produced no resolution — only a tightening knot. The knot is this: the attack vector is the commercial product itself. Distillation — extracting a rival model's capabilities by querying it at scale through its own API — works because frontier models are accessible to paying customers. Shut down that access and you stop the extraction, but you also kill the commercial reach that makes a model globally dominant in the first place. Both sides are now living inside this contradiction. In April, Anthropic began blocking third-party API tools like OpenClaw that enabled high-volume automated access through flat-rate subscriptions — a defensive move that also reduced the legitimate user base for Claude. [2] China, meanwhile, is considering restricting overseas downloads of its own advanced model weights, consulting Alibaba, ByteDance, and Zhipu on national security laws that would limit the very open-source distribution that made Qwen and Kimi dominant globally. [3] Beijing is demanding open access to US models even as it builds the same walls around its own. [4] The speed at which distillation became a state-to-state dispute is itself the evidence that the old framework cannot contain it. In February, Anthropic reported what it called the first industrial-scale distillation campaign: roughly 24,000 fraudulent accounts generating 16 million exchanges to extract Claude's agentic reasoning, coding, and tool-use capabilities, with the Chinese firm MiniMax alone running 13 million interactions. [5] By April, the White House had issued a formal memorandum and the House Foreign Affairs Committee unanimously passed a bill to sanction foreign entities engaged in model extraction — the first legislative response to distillation as a threat category. [6] In June, Anthropic accused Alibaba's Qwen of an even larger operation: 25,000 fake accounts, 28.8 million exchanges. [7] And last week, Treasury Secretary Bessent threatened sanctions against Chinese firms, naming Moonshot AI specifically, while China's Ministry of Commerce fired back that US firms also distill Chinese models and called the accusations "AI hegemonism." [8] The asymmetry in the evidence is hard to miss. The US accusations carry specific, checkable figures — account counts, query volumes, named companies. China's counter-accusation, so far, carries no documented instances. [8][5][7] That does not settle the question of who is right, but it does clarify who has built a case and who is responding with a diplomatic posture. The US response is not a united front. It is split along the same fault line that ran through the chip war — between the companies that build models and the companies that sell the infrastructure to run them. The AI labs, led by Anthropic and OpenAI, are demanding government bans on Chinese open-source models. Anthropic told senators in June that "distillation attacks turn hundreds of billions of dollars in American investment and R&D into a massive subsidy for our geopolitical competitors." [7] Nvidia's Jensen Huang, whose chips run those models, has called the Chinese systems "excellent" and advocated for open-source accessibility. [9] Microsoft's Satya Nadella has taken the same position. [9] Microsoft also sells OpenAI model access to ByteDance, Tencent, Ant Group, and Meituan through Azure. [1] The fracture runs inside the government, too. David Sacks, the White House's own AI adviser, has called the labs' push for restrictions "regulatory capture."

the leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open-source competition. — David Sacks

The leading closed labs, Sacks argues, already control the bulk of AI model revenue and want the government to eliminate their open-source competition. [10] That is not a fringe view from a think tank. It is the position of the official charged with advising the president on AI policy. This is what makes the model war fundamentally different from the chip war. Chips were a one-directional chokehold: the US controlled the advanced manufacturing, so it could impose export restrictions unilaterally and the flow stopped. Model access is reciprocal. Every defensive measure is also self-harm — close the API and you lose the market; keep it open and you feed the competitor. That is why both sides are now building the exact controls they accuse the other of violating. The US-China Economic and Security Review Commission acknowledged the mismatch in March. [11]

US export controls primarily target the digital loop, restricting access to advanced chips used for frontier model training — but are not well suited to addressing the physical loop of deployment-driven data creation and accumulation across China’s manufacturing base. — U.S.-China Economic and Security Review Commission

Roughly 80% of US AI startups now use Chinese open-source base models, the Commission found. [11] The architecture of containment changed. The strategy has not.


Sources
  1. 1. Microsoft Sells OpenAI Models to Chinese Firms via Azure
  2. 2. Anthropic Blocks Claude Subscription Access for OpenClaw and Third-Party Tools
  3. 3. China Considers Stricter Export Controls on AI and Chips
  4. 4. US and China Escalate AI Conflict Over Security and Exports
  5. 5. Anthropic Accuses Chinese AI Firms of Industrial-Scale IP Theft
  6. 6. U.S. Accuses Chinese AI Firms of Industrial-Scale Model Theft
  7. 7. Anthropic Accuses Alibaba of Massive AI Distillation Attack
  8. 8. US and China Trade Accusations Over AI Model Distillation
  9. 9. US Weighs Sanctions Over Chinese AI Intellectual Property Theft
  10. 10. Trump Administration Considers Restrictions on Chinese AI Models
  11. 11. US Commission Warns China's Open-Source AI Threatens US Leadership

Keep reading in the app

The full perspective, free in the app.

Download on the App StoreComing soonGoogle Play