(SINGAPORE 2026.9.15) Anthropic, the maverick US safety-focused artificial intelligence company, is now framing Chinese AI companies’ use of its Claude model not simply as a commercial dispute over copyright or model theft, but as an issue of US frontier AI safety and national security.

Beijing, meanwhile, views Anthropic’s calls for tighter controls on China’s access to advanced AI chips and models as another round of US efforts to contain China’s AI development.

Anthropic has barred access to Claude from China, while Chinese authorities have not, announced a specific ban on Claude as of today.

The dispute escalated rapidly over the past week. On September 10, US artificial intelligence company Anthropic released its latest threat intelligence report, saying it had identified operations linked to seven Chinese AI laboratories over the previous eight months that sought to obtain Claude’s capabilities at scale and use them to train their own models through a process known as “distillation” (蒸馏).

The companies named are Alibaba, Moonshot AI (月之暗面), DeepSeek, Zhipu (智谱), Xiaomi, SenseTime (商汤), and MiniMax.

Model distillation involves having a weaker model make large numbers of queries to a more capable model, allowing it to learn from the latter’s responses, reasoning and problem-solving capabilities.

Anthropic said the activity had reached an “industrial scale.” In one case, operators linked to Alibaba made more than 151 million interactions with Claude over a three-month period. Moonshot AI, meanwhile, was accused of using 5,380 fake accounts to route nearly 300,000 user requests through Claude.

Anthropic argues that the issue goes beyond how companies train their models. The company said some of the requests routed through Claude contained what appeared to be internal information belonging to users in the Chinese military, police, and state-owned enterprises, raising concerns among the Chinese that such information could be exposed to a US company without users being fully aware of it.

Anthropic also said some accounts linked to the Chinese government had used Claude to gather and analyze information on religious leaders, dissidents, and overseas Chinese communities.

Anthropic has not treated these incidents simply as cases of commercial infringement, but has placed them within a broader AI safety framework.

Its latest report also regretfully said Claude had been used in cyberattacks, influence operations, surveillance, fraud, and activities involving biological and conventional weapons. The company said AI was making malicious operations that once required large numbers of specialized personnel easier to carry out.

Anthropic chief executive Dario Amodei subsequently broadened the issue further by linking it to the speed of AI development. He has called on AI companies to slow the pace at which they increase model capabilities, giving society more time to address the risks of loss of control and misuse.

He has also urged the US to tighten export controls on advanced AI technologies and restrict Chinese companies from using model distillation to acquire the capabilities of US frontier models.

Amodei’s position has won support from OpenAI chief executive Sam Altman and other technology industry figures, but it has also triggered a sharp reaction from Beijing. China’s Foreign Ministry criticized the US for politicizing AI risks and creating confrontation, saying AI governance should be based on openness, inclusiveness and international cooperation rather than imposition of artificial technological barriers.

China’s state-run Global Times was more direct, describing Amodei’s position as a “Cold War script.” It argued that while the debate was ostensibly about AI safety, the real objective was to constrain China’s AI development and preserve the US technological lead.

Analysts cited by the newspaper said excluding China from discussions on global AI governance could instead increase the risk of AI being inequitably misused or getting out of control.

China’s response does not amount to a rejection of AI safety concerns. On the contrary, the Chinese government has also begun paying greater attention to the national security and social risks posed by advanced AI.

Reuters has reported that China is studying how to address the risks of powerful AI systems potentially escaping human control and is advancing related safety standards. This suggests that the disagreement between Washington and Beijing may be less about whether AI should be regulated than about who should regulate it, how it should be regulated, and whether safety rules could become another instrument of technological competition.

This is not the first time the two sides have clashed over distillation. In February, Anthropic accused three Chinese AI companies of using Claude to acquire capabilities that could improve their own models, while also calling for tighter restrictions on exports of advanced AI chips. In June, Anthropic accused Alibaba of carrying out what the company described at the time as its largest-ever effort to extract model capabilities.

The September report shows that the dispute has now expanded from alleged actions by individual companies into a broader systemic concern. The US worries that Chinese companies could circumvent restrictions on direct access to advanced models by using third-party accounts, API calls and massive numbers of interactions to acquire model capabilities.

China, meanwhile, fears that US companies are conflating commercial competition with national security, ultimately creating a new form of technological containment.

That makes upcoming US-China contacts on AI safety particularly sensitive. Reuters has reported that the two countries plan to discuss AI safety risks in September. Analysts have warned that if the US continues to threaten sanctions against Chinese AI companies, it could make cooperation between the two sides on AI safety even more difficult.

Laurie Chen, a Reuters correspondent covering China, has said mutual distrust over AI development between the US and China is deepening. China does not accept the idea that the US should determine how China develops its AI capabilities, while the US is increasingly viewing the growth of China’s AI capabilities through a strategic and national security lens.

Another complication is that the legal status of model distillation remains far from settled.

Distillation itself is a standard technique in AI development and is not inherently unlawful; the dispute is over whether the way some Chinese companies allegedly obtained and processed Claude’s outputs crossed contractual, privacy or intellectual-property boundaries.

Legal experts note that proving that distillation amounts to “theft” could be difficult under existing laws, particularly when the underlying model’s outputs are not themselves protected in the same way as source code.

This leaves Washington with a policy problem: restrictions based on national security may be easier to impose than winning a conventional intellectual-property case.

At the same time, Anthropic’s push for stronger safeguards is not uniformly shared inside the US government. President Donald Trump has publicly rejected calls to slow AI development, warning that excessive regulation could hand China an advantage.

The result is a complicated policy triangle: US companies are warning about the risks of uncontrolled AI, some US officials are prioritizing technological dominance, and China is challenging the idea that AI safety should become a justification for restricting its access to advanced technology.

LEAVE A REPLY