On June 10, 2026, Anthropic CEO Dario Amodei sent a letter to the Senate Banking Committee accusing Alibaba's Qwen AI lab of running the "largest known distillation attack" on its Claude models — roughly 25,000 fake accounts logging 28.8 million exchanges over six weeks. Distillation means querying a powerful AI at scale and training a cheaper competitor on its answers, without paying the original developer's research costs. Alibaba has not responded, and no court has verified Anthropic's evidence. Congress is not waiting: two bills that would sanction Chinese companies over distillation attacks moved from debate to active drafting, Bloomberg reported July 13.
Anthropic and bipartisan lawmakers say China is committing industrial espionage
Twenty-nine million queries, Amodei told the Senate — and a sanctions bill is already moving.
This was espionage, not overuse. Amodei told senators that Alibaba's operation was systematic and precise — not casual querying but a coordinated campaign to extract Claude's agentic reasoning, software engineering, and long-horizon task-completion capabilities. He asked Congress to expand intelligence sharing between AI companies and the government, clarify antitrust rules so AI companies can share threat information with each other, strengthen export controls, close loopholes allowing Chinese firms to access overseas data centers, and impose penalties on companies that run large-scale model extraction campaigns.
The House is already investigating the American companies that use Chinese models. Rep. John Moolenaar (R-MI), who chairs the House Select Committee on the Chinese Communist Party, and Rep. Andrew Garbarino (R-NY), who chairs the House Homeland Security Committee, launched joint investigations into Airbnb and Anysphere, the company behind the coding tool Cursor. Garbarino said reports of Chinese open-weight models matching US frontier systems in cybersecurity tasks are "highly alarming."
The sanctions push is bipartisan. Sens. Bill Hagerty (R-TN) and Andy Kim (D-NJ) are pushing a bipartisan amendment to the National Defense Authorization Act that would blacklist or sanction Chinese companies found to have harvested US model outputs at scale. Kyle Chan, a fellow in the Brookings Institution's John L. Thornton China Center, has described the contest as a "geopolitical" fight over "freedom and democracy."
Tech companies say a ban can't reach open-weight models
The models are already inside American products; a ban would land on the companies using them.
American products already run on Chinese models — carefully, the companies say. Airbnb told Congress it uses Chinese AI tools only through approved US-based providers, with data kept separate and protected. Cursor's parent company, Anysphere, built its Composer 2 model using Kimi, a Chinese open-weight model from Moonshot AI. More than half the Fortune 500 uses Cursor.
AI policy experts say Congress cannot simply ban open-weight Chinese models. Once a company publishes model weights, anyone with sufficient hardware can download and run them locally. No export control or data protection order can reach copies already distributed across thousands of servers globally. Experts call federal procurement bans the most viable option — restricting which AI tools government agencies can buy is something the government can actually enforce. Legal experts have also raised First Amendment concerns about banning publicly available model weights altogether.
Critics say American labs built the same playbook
Musk testified that xAI trained on OpenAI outputs. Distillation is the industry's own standard practice.
American labs run the same playbook on each other. On April 30, 2026, Elon Musk testified in federal court that his company xAI "partly" used OpenAI model outputs while training its Grok model. OpenAI has released distillation tools for its own customers. Distillation has been standard practice in AI research since at least 2015.
And the alleged attacker was a paying customer. Critics have also noted that Anthropic's users — including whoever operated the 25,000 alleged fraudulent accounts — paid for API access before Anthropic classified those interactions as an attack. A Peking University study found that most tested Chinese models showed signs of distillation from US sources. But US companies have also trained on copyrighted content without authorization. Legal scholars note that existing laws around trade secrets and computer fraud are poorly suited to mass API harvesting.
Where This Lands
Congress has two live vehicles. H.R. 8283 — the Deterring American AI Model Theft Act of 2026 — sits before the House Foreign Affairs Committee; it would create a public list of sanctioned AI extraction actors. Hagerty and Kim are still drafting their NDAA amendment separately. No court has ruled on whether mass API querying constitutes trade secret theft — and no court has verified Anthropic's claims against Alibaba.