China's government just called the biggest AI theft accusation in Washington "misguided," but it never disputed a single one of Anthropic's numbers.
Liu Bin didn't bother naming the United States. He didn't have to. Standing before delegates at the World AI Conference in Shanghai on July 18, China's assistant foreign minister publicly rejected months of American accusations that Chinese labs are systematically stealing frontier AI models through a technique called distillation. "Some countries hype up distillation," he said, according to Bloomberg. "This is misguided and counterproductive."
The accusation Liu was answering runs to specific numbers, not vague suspicion. In a June 10 letter to the Senate Banking Committee, made public two weeks later, Anthropic told lawmakers that Alibaba's Qwen lab ran the largest known distillation campaign against its Claude models yet recorded. The numbers are specific. Roughly 25,000 fraudulent accounts logged 28.8 million exchanges between April 22 and June 5. The targets, Anthropic said, were Claude's most commercially valuable skills: software engineering, advanced reasoning, and the ability to carry out long, multi-step tasks.
Distillation itself isn't new or automatically illegal. It's the technique of training a cheaper "student" model to mimic an expensive "teacher" model by harvesting its outputs at scale. What Anthropic alleges is theft by volume. Automated accounts hammer Claude with carefully constructed prompts, then feed the answers into Qwen's training pipeline, skipping the years and the billions of dollars Anthropic spent building the original.
This isn't Anthropic's first accusation of this kind. In February, it named three earlier campaigns, attributed to DeepSeek, MiniMax and Moonshot AI, that used roughly 24,000 fake accounts to generate more than 16 million exchanges with Claude. OpenAI made a similar claim against DeepSeek around the same time.
Washington's Turn
Washington had already escalated before Anthropic's letter reached the Senate. On April 23, the White House Office of Science and Technology Policy issued a memo, NSTM-4, accusing foreign actors, chiefly in China, of running "deliberate, industrial-scale campaigns" to copy American AI systems. Signed by OSTP director Michael Kratsios, it directed federal agencies to share threat intelligence with AI labs and explore ways to hold offenders accountable. It stopped short of new export controls or account restrictions.
That restraint didn't survive contact with Congress.
At the Senate hearing that followed Anthropic's letter becoming public, Republicans pushed for harsher measures against Chinese labs. Democrats warned that a sweeping crackdown could end up punishing Chinese American researchers and companies rather than the state actors Washington says it's targeting. Former acting Defense Intelligence Agency director David Shedd testified that distillation campaigns let rivals replicate a model's most valuable capabilities at a fraction of the original research and development cost.
The stakes go beyond one hearing room. Qwen is one of the most widely downloaded open-weight model families in the world, and Alibaba has leaned on that reach to court developers outside China. If US lawmakers conclude Qwen's gains came substantially from copying Claude, that legitimacy takes a direct hit, and so does the case for treating open-weight releases from Chinese labs as safe defaults for Western companies.
Beijing's Answer
Liu's remarks, and Xi Jinping's broader address at the same conference calling for AI development that isn't "a solo performance by a single country," answer the politics of the accusation, not its arithmetic. Neither leader disputed the 25,000 accounts or the 28.8 million exchanges Anthropic handed the Senate. They rejected the frame. Distillation, in Beijing's telling, is a normal feature of how AI research spreads, not evidence of state-directed theft.
That gap matters for anyone pricing Anthropic, OpenAI or Alibaba right now. If distillation campaigns really do let a rival lab clone Claude's coding and reasoning abilities for a fraction of the cost, they erode the moat frontier labs are counting on to justify their valuations. If Beijing is right that this is ordinary technological diffusion, then every export control built on the distillation narrative is solving a problem that barely exists.
Frankly, neither side has produced anything the other is willing to call a smoking gun. What sits on the public record right now is Anthropic's letter, Alibaba's silence, and a foreign ministry statement that never once mentioned the number 28.8 million.
Also read: Hugging Face Says an Autonomous AI Agent Swarm Breached Its Systems Over a Weekend • Qwen3.8 Teases a 2.4 Trillion Parameter Open Model as Alibaba Chases Kimi K3 • Alibaba's Qwen3.8 Arrives With 2.4 Trillion Parameters After Kimi K3 Selloff