A June 10 letter from Anthropic to the Senate Banking Committee, addressed to chair Tim Scott and ranking member Elizabeth Warren, surfaced via CNBC on Wednesday and is now bouncing through the legislative process at unusual speed. The letter alleges that between April 22 and June 5, operators affiliated with Alibaba and its Qwen AI lab ran approximately 28.8 million queries through Claude using roughly 25,000 fraudulent accounts and proxy services to hide their geographic origin. Anthropic calls it “the largest known distillation attack” the company has logged.
Adversarial distillation is the part of the AI training cycle no lab wants to talk about because every lab does at least some version of it. The mechanic is straightforward. You ask the smart model a lot of questions, you capture its outputs, and you use the output pairs to fine-tune your own smaller model so it imitates the reasoning patterns of the better one. The legal status of doing this against a competitor’s commercial API is roughly “nobody has lost a case yet because nobody has filed one in a way that produces a clean ruling.” The status is therefore “you can do it until somebody complains loud enough that the government does something.” Anthropic has complained loud enough.
The specific complaint is that the Qwen operators were aiming the queries at Claude’s software-engineering and agentic-reasoning capabilities, which are the two workloads where Anthropic’s recent enterprise traction has come from and the two workloads where Qwen has visibly stepped up over the same window. The implication, which Anthropic does not have to spell out because the timing does it, is that Qwen’s recent coding-benchmark improvements happen to look a lot like Claude’s, because Claude wrote a meaningful share of the training set.
The legislative response is moving faster than usual. Senators Bill Hagerty and Andy Kim are introducing an amendment to the National Defense Authorization Act that would blacklist or sanction any foreign entity found running an adversarial distillation campaign against a US frontier-model API. A bipartisan House companion from Bill Huizenga and Sydney Kamlager-Dove is being floated for the same vehicle. NDAA amendments are the vehicle Congress uses when it wants to do a thing without having to negotiate a stand-alone bill, which tells you something about how seriously the staffers are taking this.
Alibaba has not publicly responded. Whether or not they comment, the precedent that gets set here is what matters. If “we accessed your API in a way that broke your terms of service” becomes a sanctionable offense at the federal level, the rest of the Chinese open-weights ecosystem has a new procurement problem. If it does not, “scrape the smart model” remains a free-tier business model. The Senate Banking Committee just turned the question into a vote.