In March, artificial intelligence company Anthropic quietly deployed software to spy on China-based customers of its popular coding chatbot Claude Code.

The apparent goal: unmasking the Chinese rivals the company suspected of hijacking its technology to make their own AI tools smarter.

Subscribe to The Post Most newsletter for the most important and interesting stories from The Washington Post.

Anthropic’s tracking code invisibly checked whether a Claude user’s computer was set to Chinese time zones and using a web domain name linked to certain Chinese AI companies.

The American firm backtracked and removed the electronic monitor last week, after a software developer revealed its existence and privacy advocates criticized Anthropic, saying it had surveilled its own users. An Anthropic executive said the tracking was an “experiment” that would be rolled back in favor of better defenses.

But the episode revealed increasingly aggressive measures American firms are taking in a battle with Chinese rivals over who will control the technology’s future.

The geopolitical contest has contributed to recent, rapid-fire moves by the Trump administration to assert greater control of whom Anthropic and its chief U.S. rival, OpenAI, allow to access their technology. (The Washington Post has a content partnership with OpenAI.)

But although the White House has claimed it is helping U.S. firms dominate AI, some Silicon Valley allies of President Donald Trump have said the recent policies risk making it harder for American firms to compete with those from China. The dissatisfaction with U.S. policy and allegations against Chinese firms come as evidence grows that their AI technology is becoming more competitive with that offered by U.S. companies.

“They’re very close,” Srinivas Mukkamala, CEO of cybersecurity company Securin, said of the capabilities of Chinese AI models, “and they cost you nothing.”

For over a year, Chinese AI companies have consistently matched the capabilities of the latest U.S. AI models within months, industry benchmarks show. Among free and open AI models, Chinese options are already more popular than American ones, The Post reported in October. Last week, cybersecurity firm Semgrep said a new, free AI model from Chinese company Zhipu AI was better at finding computer vulnerabilities than Anthropic’s Claude Opus 4.8 model, which was released in May.

Anthropic’s tracking code was designed in part to catch Chinese firms “distilling” its AI models, a technique that involves pressing a large, expensive AI system to serve as a tutor to a smaller, cheaper one. Asking the larger system huge numbers of questions – hundreds of thousands or more – generates responses that can be used to upgrade the power of the smaller one on the cheap.

Distillation isn’t illegal, and it has been used for years in the AI industry. But distillation without permission is against AI companies’ rules, and, used effectively, is giving Chinese AI companies a major leg-up, American AI companies say.

These “attacks pose a serious threat to national security and undermine AI safety standards across the industry. That’s why we continue to speak openly about what we’re seeing and work closely with other labs, government, and partners on shared solutions,” a spokesperson for Anthropic said. Spokespeople for OpenAI did not return requests for comment.

Anthropic and ChatGPT-maker OpenAI have both accused Chinese AI companies of using this technique to build copy-cat AI models of their own.

In a May blog post, Anthropic said that Chinese companies’ use of distillation, along with evading U.S. export controls on high-end computer chips, has allowed them to “trail closely” behind U.S. models. But if these techniques can be blocked, it might be possible for the United States to “lock in a 12-24 month lead” on Chinese capabilities, the company said.

Neither Anthropic nor OpenAI permits access to their models from mainland China or Hong Kong, blocking users with measures that include IP-based location restrictions and government ID checks, though residents frequently find work-arounds to access the tech.

This month, Anthropic said in a letter to U.S. senators that was obtained by The Post that it uncovered a campaign in which Chinese tech giant Alibaba’s Qwen AI team used roughly 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude to improve its own technology.

In February, Anthropic made similar accusations against the Chinese firms Deepseek, Moonshot and MiniMax and said the campaigns were “growing in intensity and sophistication.” Alibaba, Deepseek, Moonshot and MiniMax did not respond to requests for comment.

Anthropic and OpenAI have appealed to the U.S. government, arguing that distillation amounts to intellectual property theft that harms the U.S. in the geopolitical AI contest.

“Anthropic’s framing is that this is a geopolitical contest for basically the future of the world and freedom and democracy.” said Kyle Chan, a fellow at the Washington-based Brookings Institution’s China Center.

“It’s that this is not just undercutting the U.S. commercially, but undercutting American strategic advantage in the most powerful technology we know today,” he said.

That argument has been echoed by the Trump administration and some Republican lawmakers.

In April, the White House released a memo warning that Chinese firms were running “deliberate, industrial-scale campaigns” to distill U.S. systems, raising concerns that the practice could allow Chinese competitors to build cheaper models stripped of safety mechanisms.

“The United States cannot afford to let China or any other adversary gain a technological edge in artificial intelligence,” said Sen. Tim Scott (R-South Carolina), chairman of the U.S. Senate Committee on Banking, Housing and Urban Affairs, at a hearing last month that addressed distillation concerns. “We have to carefully craft export control policy that is clear and concise,” he said.

That Chinese AI labs are using U.S. models to improve their own technology appears beyond dispute.

In a February 2025 study, researchers from China’s Peking University and the state-funded Chinese Academy of Sciences developed methods to detect signs of distillation in leading large language models. They concluded that, with the exception of ByteDance’s Doubao, most domestic models they tested showed substantial evidence of distillation, mostly drawing from U.S. models.

Among them was one of Chinese e-commerce giant Alibaba’s Qwen AI models. Using tests that compared model outputs and probed for clues about a model’s underlying identity, the researchers found that Qwen repeatedly appeared to mimic Claude – suggesting Anthropic’s model had been used to improve the Chinese system. In one set of intensive tests, a Qwen model misidentified itself as Claude nearly a third of the time, the Chinese researchers found.

U.S. firms have also used distillation to piggyback on AI systems made by others.

In 2024, OpenAI released a tool to make it easier for customers to distill its own models and produce data sets for AI training. SpaceX founder Elon Musk said in court testimony in May that his AI company xAI used distillation to train its models and that the technique is common throughout the industry.

Without knowing the details about how a Chinese model was trained, it can be difficult to distinguish illicit behavior from a terms of service violation, said Irene Solaiman, the chief policy officer for Hugging Face, a repository for open source AI.

But alleging popular Chinese models are somehow “stolen goods” could lead the U.S. to underestimate China’s ability to innovate in AI. Chinese labs have consistently made breakthroughs in efficiency and cost effectiveness, partly out of necessity while facing U.S. export controls, she said.

Silicon Valley startups and cash-strapped academic researchers have flocked to Chinese AI models, which companies such as Alibaba and Deepseek release free versions of for others to use and modify, in addition to charging for apps and services.

Fortune 500 CEOs are beginning to call for cheaper alternatives to the extremely expensive AI sold by leading U.S. companies such as OpenAI and Anthropic. The chief executives of Airbnb, Brian Chesky, and cryptocurrency exchange Coinbase, Brian Armstrong, have spoken publicly about their companies’ use of Chinese AI models.

Any move to prevent Americans from building on Chinese open source models could harm the growing numbers of users, researchers and start-ups depending on them, Solaiman said.

Preventing Chinese companies from distilling U.S. AI models would also be difficult.

In September, Anthropic expanded its restrictions beyond users based in China to include any entity more than 50 percent owned by Chinese interests anywhere in the world. In April, it went further, requiring some users to verify their accounts with a government-issued ID.

Despite that, Chinese users who have faced decades of internet restrictions under the tight controls of the Great Firewall are adept at finding ways around the types of regional registration controls that U.S. AI firms have put on their models. Anthropic said it has banned nearly 700,000 accounts that were using Claude in China.

“There is a whole ecosystem of proxy servers, third-party accounts and even services that allow you to get around the know your customer ID verification,” said Chan of the Brookings Institution.

In recent tests conducted by The Post using Chinese phone numbers and subscriptions purchased on Alibaba-owned Taobao, access to free Claude and OpenAI free accounts was available for about $1 a month. Pro subscriptions that cost more than $100 a month in the U.S. were offered by Chinese re-sellers for as little as $12 monthly.

Anthropic’s February blog post alleging that Chinese companies distilled its AI models suggested that these proxy services can operate at huge scales. “When one account is banned, a new one takes its place. In one case, a single proxy network managed more than 20,000 fraudulent accounts simultaneously,” it said.

Related Content