Storylines / Live · opened Mon 14 Sep · moved this week · 7 items · 1 update

China distillation and export controls

Chinese labs accused of extracting Western models at industrial scale, and the chip, weight-security and espionage rules being built in response.

What would settle it

Do the distillation allegations hold up outside the accusing companies, and do export and espionage controls tighten or loosen? Settled by: a second lab or a government publishing its own counts; a formal US export-control change; or a named company producing records that contradict the figures.

Where this stands as of Monday, 14 September 2026

As of 14 September the allegation is specific and the rebuttal is political. Anthropic attributes 151 million Claude interactions to Alibaba-linked accounts and names seven China-based AI companies behind distillation campaigns; US agencies named six Chinese firms over industrial-scale distillation in the same week. Moonshot AI, one of the named companies, told TechCrunch it targets $2bn annualised revenue by year-end, double its August run rate, and did not address the allegation in that report.

On the controls side, Dario Amodei tied his pacing plan to blocking China chip sales, a distillation crackdown and model weight security; South Korea's expanded espionage law took effect on 13 September, covering leaks of AI and chip technology to any foreign country; and on 14 September Beijing's foreign and commerce ministries and Global Times rejected Amodei's call to keep curbing China's AI. No named company has produced records contradicting the per-campaign figures.

Timeline

Every item filed under this storyline, newest first, with its sources.

Tuesday, 15 September 2026

Tue 15 Sep · Military, defense & geopolitics

China's new exit rules take effect, allowing travel bans on citizens who endanger "technological security" harmful

  • China's new Exit and Entry Administration Provisions took effect on Tuesday 15 September 2026. Free Malaysia Today reports the rules target violations of export controls or technology import and export rules that may endanger "industrial or technological security", and were unveiled in July.
  • The News International reports the regulations were formulated by the State Council alongside multiple ministries and empower border and security authorities to impose exit bans, and says individuals who breach technology import and export rules — "particularly engineers and corporate officials operating in sensitive sectors like artificial intelligence (AI) and advanced manufacturing" — face immediate travel restrictions.
  • Free Malaysia Today reports the rules provide for exit bans of six months to three years on citizens who return to China after committing illegal or criminal acts abroad that harm national security or interests, and that foreign nationals may be denied entry for one to five years for false statements in visa applications.
  • Free Malaysia Today reports Taiwan's Mainland Affairs Council deputy head raised concerns about the new "export control" and "technology import-export management" grounds, particularly for Taiwanese tech workers. Neither report cites a case in which the AI-related grounds have been used.

Monday, 14 September 2026

Mon 14 Sep · Military, defense & geopolitics

Beijing's foreign and commerce ministries and Global Times reject Amodei's call to keep curbing China's AI Update

  • At a regular briefing in Beijing on Monday 14 September, foreign ministry spokesperson Guo Jiakun said: "Fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance which serves no one's interest." The AP reports the commerce ministry separately dismissed US allegations as groundless, said distillation is commonly used by many AI companies, and accused the US of pursuing a "monopoly of the AI industry".
  • The AP reports the response follows Amodei's essay, which warned that a "Chinese lead in AI would pose grave danger for the United States and the world" and called for continuing restrictions on sales of cutting-edge AI chips and chipmaking equipment to China.
  • Reuters reports the state-backed Global Times said the essay's true objective was "to attempt to curb China's AI development through technological barriers and regulatory monopolies", and that "this 'silent AI Cold War' is hypocritical and short-sighted", warning that excluding China would "significantly increase the trial-and-error costs and risks of loss of control in global AI development".
  • This is an update: the essay and its chip and distillation proposals were covered in earlier editions, and the Chinese government reaction is the new element. Neither wire reports any change in Chinese policy, and the AP places the exchange ahead of the Trump-Xi meeting on 24 September.

Sunday, 13 September 2026

Sun 13 Sep · Policy, regulation & law

South Korea's expanded espionage law takes effect, covering leaks of AI and chip technology to any foreign country Single source

  • The revised Criminal Act took effect on Sunday 13 September, broadening espionage offences beyond acts involving North Korea to include all foreign countries. The National Assembly passed the revision on 26 February; it was promulgated on 12 March and took effect after a six-month grace period.
  • The amendment creates a new offence covering espionage for a foreign country or equivalent organisation, carrying a minimum sentence of three years in prison. Existing "enemy state" provisions remain in place.
  • Reuters reports the National Intelligence Service said the amendment would strengthen South Korea's ability to prevent leaks of strategic technologies such as semiconductors, displays, batteries and AI. The report cites the 2025 indictment of five former Samsung Electronics employees accused of transferring DRAM technology to Chinese memory maker CXMT.
  • Asked whether the law targets Beijing, Chinese foreign ministry spokesperson Mao Ning said all countries should safeguard normal investment and business activities of enterprises and provide a fair and non-discriminatory business environment. The report does not say how many cases are expected or how AI technology will be defined in practice.
Sun 13 Sep · Military, defense & geopolitics

Amodei ties his pacing plan to blocking China chip sales, a distillation crackdown and model weight security Company claimSingle source

  • Amodei lists three steps to defend the US lead: "Do not sell powerful AI chips or semiconductor manufacturing equipment to China, and crack down on chip smuggling operations and remote access to data centers outside China"; "Crack down on unauthorized distillation by companies in authoritarian countries"; and "Strengthen security at the AI companies and prevent model weight theft."
  • He writes: "If we execute these measures well, I believe they would slow China's progress enough to widen America's lead significantly over the next 3-5 years — the window when AI becomes geopolitically most important."
  • On international agreements he ranks four levels, calling a "speed limit" on recursive self-improvement "analogous to the SALT treaties" and "difficult but just on the edge of being possible", while a full pacing agreement or pause is "unlikely to actually happen any time soon".
  • This is one company chief executive's policy proposal, published on his personal site. No government has endorsed it, and the 3-5 year estimate is his own with no analysis published alongside it.

Saturday, 12 September 2026

Sat 12 Sep · Deployment & impact

Moonshot AI targets $2bn annualised revenue by year-end, double its August run rate, as Anthropic alleges distillation Company claim

  • TechCrunch reported on 11 September at 12:35 pm PDT that Moonshot AI is "targeting $2 billion in annualized revenue by the end of the year", a doubling of its August run rate. For scale, TechCrunch puts OpenAI's revenue run rate at $40 billion and Anthropic's annualised revenue at $65 billion.
  • OpenRouter data cited by TechCrunch shows Moonshot's K3 models generating "as many as 300 billion tokens being generated each day" on that platform, with usage down slightly in recent months.
  • The figures matter because Moonshot ships open weights, which carry lower margins than closed models; a $2 billion run rate would be the strongest commercial evidence yet for that business model.
  • In the same week Anthropic accused Moonshot of routing "nearly 300,000 requests from Kimi directly to Claude Opus" and collecting "more than 23 million responses". The revenue figures are Moonshot's own, given to investors, and are not independently verified; Moonshot's response to the distillation allegation is not in the piece.
Sat 12 Sep · Security, misuse & threat intelligence

Anthropic names seven China-based AI companies behind distillation campaigns, with 151 million exchanges attributed to Alibaba harmfulCompany claimUpdate

  • The Hacker News reports the seven named companies as Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai), MiniMax, SenseTime and Xiaomi, with per-campaign figures: GTG-16005 (Alibaba) 151 million exchanges from May to July 2026 across more than 3,500 fraudulent accounts, peaking near 3 million exchanges a day; GTG-16002 (Moonshot) 23 million exchanges across 5,380 fraudulent accounts registered in Singapore and Japan.
  • Also listed: GTG-16001 (DeepSeek) 12.1 million exchanges over 14 days in July 2026 via a proxy relay; GTG-16006 (Zhipu) 3.4 million exchanges across 273 accounts from June to July 2026; GTG-16008 (Xiaomi) 400,000 exchanges over 20 days in March–April 2026; GTG-16012 (SenseTime), which bought transcripts from vendors; and GTG-16003 (MiniMax), via a shell-company proxy network.
  • Anthropic says it responded by banning reseller accounts and accounts from unsupported regions where users fail to verify identity, by updating Claude to summarise its internal reasoning before responding, and by introducing a "preserved thinking" feature — measures aimed squarely at protecting chain-of-thought traces, which the Alibaba campaign is said to have targeted.
  • This extends yesterday's item, which carried only the 151 million figure for Alibaba-linked accounts. Every figure is Anthropic's own account of activity on its own platform; none of the named companies' responses appear in the report, and no independent party has verified the counts.

Friday, 11 September 2026

Fri 11 Sep · Security, misuse & threat intelligence

Anthropic attributes 151 million Claude interactions to Alibaba-linked accounts as US agencies name six Chinese firms over industrial-scale distillation harmful

  • TechCrunch, reporting figures from Anthropic's 10 September threat report, says accounts linked to Alibaba generated 151 million Claude exchanges between May and July 2026 across about 3,500 accounts, and that Moonshot AI accounted for roughly 300,000 requests over ten days across 5,000 accounts — part of around 200 million exchanges across five campaigns. Extraction techniques included framing requests as translation tasks to surface chain-of-thought reasoning.
  • The joint CISA, NSA and FBI bulletin AA26-251A, published 8 September, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as conducting "aggressive, malicious, and targeted distillation activities at an industrial scale" against Claude, GPT, Gemini and Grok since late 2024, extracting "billions of tokens across millions of exchanges/requests."
  • The agencies' recommended countermeasures are unusually specific, and include monitoring subscription-to-usage ratios and enterprise-scale throughput from new accounts, and subtly altering responses to suspected distillation attempts to reduce the payoff to the attacker.
  • The named companies' responses are not documented in the reporting reviewed here. Distillation of a competitor's outputs is a terms-of-service question rather than a settled legal one, and neither document alleges a criminal charge.

Tracked figures

seven
China-based AI companies named by Anthropic Sat 12 Sep The Hacker News
151 million
Claude exchanges attributed to Alibaba-linked accounts, May–July 2026 Thu 10 Sep TechCrunch

Open questions

Why do the US agencies' list of Chinese labs and Anthropic's list not match?

What would settle it
Either party publishing its attribution method, or a reconciled list.
Asked
Mon 14 Sep