Distillation becomes a geopolitical fight
OpenAI took its complaint about DeepSeek to Congress and Anthropic named three Chinese labs it says ran distillation campaigns against Claude. The mechanics and the policy story deserve to be separated.
What happened this month
On February 12 OpenAI sent a memo to the House Select Committee on China alleging that DeepSeek is engaged in what the memo calls ongoing efforts to free-ride on capabilities developed by OpenAI and other US frontier labs. The memo says OpenAI detected new, obfuscated methods designed to evade its safeguards, including access through third-party routers to mask the source, programmatic collection of outputs, and unauthorized reseller networks.
On February 23 Anthropic published its own account, naming DeepSeek, Moonshot AI and MiniMax. The numbers are large. Anthropic says the three labs created roughly 24,000 fraudulent accounts and generated over 16 million exchanges with Claude. By its count DeepSeek accounted for more than 150,000 exchanges, Moonshot more than 3.4 million, and MiniMax more than 13 million. The targets, in Anthropic's words, were agentic reasoning, tool use and coding, with Moonshot also working on computer-use agents and MiniMax on agentic coding and tool orchestration.
Detection, according to the post, came from IP correlation, request metadata, infrastructure indicators, and behavioural patterns such as prompt volume and repetitiveness across coordinated accounts. Anthropic specifically mentions detecting chain-of-thought elicitation used to build reasoning training data. TechCrunch asked all three companies for comment and reported no response at publication.
What distillation is
Distillation is a training technique older than any of these companies' models. You take outputs from a strong model, the teacher, and finetune a weaker or smaller model, the student, to reproduce them. It has been standard practice in the open for years, and the companies now complaining about it have used it themselves. Every frontier lab trains its smaller tiers on the outputs of its larger ones.
The clearest public demonstration of how much it can transfer is DeepSeek's own R1 paper from January 2025. The team took about 800k samples generated by R1 and finetuned Qwen and Llama checkpoints on them. The 32B distilled model scored 72.6% on AIME 2024, and the paper reports that distillation beat running reinforcement learning directly on the small model. That is a striking amount of reasoning capability moved with supervised finetuning alone, with the teacher's weights never leaving the building.
That is also the reason the accusations are technically plausible. If 800k samples from your own model can lift a 32B student to that level, then millions of exchanges with someone else's model are a meaningful training resource, particularly when the prompts are designed to elicit long reasoning traces and tool-use trajectories.
What distillation cannot do
It cannot transfer what the teacher does not emit. A student sees the final text, and possibly a visible reasoning trace, and nothing else. It does not see the teacher's weights, its training data, its reward models, or its internal representations. OpenAI's decision in September 2024 to hide o1's chain of thought was explicitly motivated by not wanting other models to train on it, and that decision now looks like the first move in this dispute.
It cannot make the student bigger than it is. The R1 paper's small distilled models are strong for their size and still far behind the teacher on hard problems. A student learns to imitate the surface of the teacher's behaviour on the distribution of prompts it was shown. Off that distribution the gap reopens. Distillation is a way to close part of a capability gap cheaply, not a way to close all of it.
And it cannot substitute for a base model. Every distilled checkpoint in this story started from a pretrained model someone had already paid for. Anthropic's post argues that distilled models lack the safeguards of the originals, which may be true, but the harder question of whether a lab could reach the frontier by distillation alone has an obvious answer in the paper record. Nobody has.
Separating the two arguments
There are two claims tangled together in this month's statements. One is a terms-of-service claim, which says that accounts were created fraudulently, rate limits and access controls were circumvented, and outputs were used in a way the provider prohibits. That claim is about conduct and it is checkable by the provider, which holds the logs. Anthropic's detail about detection methods suggests it is confident on this point.
The other is a policy claim: that distillation is a national security problem and a reason for export controls on chips. TechCrunch notes the timing, with the accusations landing as Washington debates whether to allow H200 exports to China, and quotes Anthropic saying distillation attacks reinforce the rationale for export controls. OpenAI's memo makes the same connection. This claim does not follow from the first one. Distillation reduces the compute a follower needs, which is an argument that chip controls matter less, not more, unless the goal is to raise the cost of everything at once.
We do not have a view on the export control question that belongs in a research blog. We do have a view on the framing. Calling a finetuning technique an attack makes it harder to discuss the actual research questions, which are how much capability transfers through outputs alone, how to detect when a model has been trained on another model's outputs, and whether there are ways to serve a model that limit what its outputs teach.
What researchers can do here
The detection problem is a good open science project and it does not require anyone's logs. Given a student model and a suspected teacher, can you tell from behaviour alone whether the student was trained on the teacher's outputs? There is prior work on fingerprinting and watermarking model outputs. There is very little on doing this after the fact, at the scale of a full model, with the teacher's cooperation but without the training data.
The transfer question is also measurable in the open. Take an open teacher, distill students of several sizes on prompts of several kinds, and measure which capabilities move and which stay behind. The R1 paper did one version of this for math and code. Nobody has done it carefully for agentic tool use, which is exactly the capability Anthropic says was targeted. If the answer is that tool use transfers well through traces, that is important for everyone building agents, on every side of this dispute.
Sources
From the foundation