Learning from Everyone Is Permitted, Learning from the Monopoly Is a Crime
Is Distillation Theft?

Is Distillation Theft? Learning from Everyone Is Permitted, Learning from the Monopoly Is a Crime
The new stage of the US–China artificial-intelligence quarrel lays bare the class nature of intellectual property more starkly than ever.
Dear Young Comrades,
On 8 September 2026 three US security agencies — the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) — issued a joint “cybersecurity advisory.” The advisory’s title is this: "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies."
The six companies named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI; the products listed as “victims” are Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini, and Grok under the SpaceX umbrella.
According to CyberScoop, the document claims that distillation is “not a supplement but the core” of Chinese companies’ AI strategy; according to Nextgov, the activity has been under way since 2024 and “threatens” US “technological leadership.”
In this piece I will first explain in plain terms what distillation is; then I will set out the chronology and the legal ground of the accusation; then I will come to the piece’s real concern: that the same state, in the same week, took two opposite legal positions on the same technical operation. Because this quarrel, even as it tries to conceal the question, brings it into the open: from whose labour are AI models made, and to whom do they belong?
What is distillation?
Technically, “knowledge distillation” has been a known machine-learning method since 2015. A large and expensive model (the “teacher”) produces answers to a great many questions; a small and cheap model (the “student”) is trained on these question–answer pairs. The student never touches the teacher’s weights, code, or training data; it only sees its outputs and learns from them. The result is a model that behaves like the teacher but demands far less compute.
Every major laboratory uses this method internally. Anthropic’s report of 23 February 2026 says so plainly: “Distillation is a commonly used and legitimate training method.” Deriving small, cheap versions from a large model is how the “mini,” “flash,” and “haiku” products sold to customers are made. Even the CISA advisory itself, as CyberScoop reports, acknowledges that companies and open-source communities “widely distill other AI systems in the course of legitimate work and research.”
So where is the crime? According to the accusation, the crime is not in the method itself but in who learned from whom, and with what permission. According to Anthropic’s report, DeepSeek, Moonshot, and MiniMax accessed Claude through some 24,000 fake accounts and conducted more than 16 million question–answer exchanges; a single proxy-server network managed more than 20,000 accounts at once. The CISA advisory claims that Moonshot distilled 18 different US models to train its Kimi models, and that DeepSeek produced synthetic training data this way for its R1 and R3 models.
So the concrete legal content of the claim is this: breach of terms of service, and opening fake accounts. That is not called “theft”; it is breach of contract and perhaps fraud. But the documents insist on “theft,” “systematic extraction,” “malicious copying.” This choice of words is not an accident; we will come back to it.
Chronology: From a company complaint to a state doctrine
It is instructive to see how this matter was turned, step by step, from a private company’s commercial complaint into a national-security doctrine.
January 2025. DeepSeek releases the R1 model and technology stocks on the US market, Nvidia foremost among them, fall sharply. Within a few days OpenAI announces that DeepSeek may have distilled its models; Microsoft opens an investigation. CNN’s comment at the time is already in the headline: “OpenAI now wants to make DeepSeek look like the villain.”
February 2026. OpenAI submits an official notification to the House Select Committee on China; a few days later Anthropic publishes the report I cited above and, according to CNBC, openly accuses DeepSeek, Moonshot, and MiniMax.
April 2026. As The Next Web summarised, a bill titled the “American AI Model Theft Deterrence Act” is introduced in Congress; the Select Committee holds a hearing; the White House Office of Science and Technology Policy (OSTP) issues a memorandum announcing that federal intelligence will be shared with OpenAI, Anthropic, and Google. The three companies have already begun sharing “distillation threat intelligence” under the Frontier Model Forum.
June–July 2026. Anthropic this time accuses Alibaba of thousands of fake accounts; White House OSTP director Michael Kratsios makes statements targeting Moonshot.
8 September 2026. The NSA, CISA, and FBI issue the joint advisory. The accusation is no longer that of three companies; it has become an official finding of the US state. According to Business Standard, Liu Chang, spokesperson for China’s embassy in Washington, called the accusations “a deliberate attack on China’s development and progress in the field of artificial intelligence”; none of the six companies named made a statement. The advisory came weeks before a Trump–Xi summit.
At every link in this chain the same move is made: private capital’s commercial complaint is translated first into the language of “intelligence,” then of “national security,” then of “theft.” The companies’ claim of a contract breach is repackaged as a state cybersecurity advisory.
The same week, two opposite laws
Now we come to the heart of the piece. Six days before the 8 September advisory, on 2 September 2026, the same US government’s Department of Justice filed a 20-page brief in federal court in Manhattan. The matter was The New York Times v. OpenAI: the newspaper treats OpenAI’s use of its own articles as training data without permission as copyright infringement. According to Quartz, the Department of Justice argued that training large language models on copyrighted material is generally “fair use.” According to the case summary on Wikipedia, this was the first time the US government had taken a side in a copyright case concerning AI training. The Intercept’s headline sums it up: “Trump Admin Tells Court: Let OpenAI Rip Off The Intercept’s Articles.”
Let us set them side by side:
| Training on the text and images of billions of people | Training on a rival model’s outputs (distillation) | |
|---|---|---|
| Technical operation | Statistical learning from input–output examples | Statistical learning from input–output examples |
| Permission of the source | None; writers, journalists, artists, Wikipedia editors, forum users were never asked | None; prohibited in the terms of service |
| Path of access | Web scraping, pirate book sites (Anthropic downloaded more than 7 million pirated copies) | Fake accounts, proxy servers, grey-market access |
| The US government’s name for it | “Fair use,” “transformative learning” (Department of Justice, 2 September 2026) | “Theft,” “systematic extraction,” “malicious copying” (NSA/CISA/FBI, 8 September 2026) |
| The companies’ name for it | “Learning,” “publicly available data” | “Distillation attack,” “intellectual-property infringement” |
| Who produces the source? | Billions of people, unpaid or low-paid | A capital-intensive monopoly |
| Result | The model’s owner-capital accumulates | Rival capital accumulates |
The table shows that the distinction is not technical or moral but class-based. The act of learning itself is the same in both columns. The only thing that changes is who is held to own what is learned. Text produced collectively by billions of people is treated as “ownerless,” so learning from it is permitted. The model distilled from that text is treated as a company’s property, so learning from it is a crime.
The statistician Ambuj Tewari of the University of Michigan, in an assessment in January 2025, concedes this even from a liberal frame: distillation is “a completely normal practice if the stronger model was released under a license that permits it”; the problem is not in the method but in the contract. And in the same breath Tewari recalls the debate over whether training on copyrighted books is fair use. So the issue has been this from the start: the law of learning changes according to the property status of what is learned.
The Anthropic case: Learning is permitted, stealing is forbidden — so where is the line?
The example that best shows where this line is drawn is Anthropic’s 2025 settlement with authors. According to NPR, Judge William Alsup said two things in June 2025. First, using published books to train Claude is “exceedingly transformative” fair use; authors have no right to object to the learning. Second, downloading those books from pirate sites such as Library Genesis is not fair use; that part would go to trial. Anthropic paid $1.5 billion rather than stand trial; about $3,000 per book for some 500,000 books. According to the Authors Guild, this was the largest copyright settlement in US history.
Note this: Anthropic paid not because it learned, but because of the form of access. Now the same Anthropic is accusing Chinese companies not because they learned, but because of the form of access — fake accounts. The legal structure is entirely symmetrical. The difference is in the rhetoric: Anthropic’s pirated books were referred to as “training-data procurement”; the Chinese companies’ fake accounts became “industrial-scale theft.” Anthropic closed more than 7 million pirated copies at a unit price of $3,000; the Chinese companies’ 16 million exchanges became a national-security matter.
I am not trying here to whitewash Chinese capital. DeepSeek, Alibaba, and Moonshot too built their models on the same collective labour; their products too are private property, and they too accumulate as capital the knowledge produced by the Chinese working class and the world’s population. The Chinese embassy’s defence of “an attack on our progress” is a defence of its own companies’ property claim; not of the working class. In this quarrel neither side is the worker’s side. But the form of the quarrel shows us the object of class struggle: the distilled product of collective mental labour.
A Marxist reading: The second expropriation of the general intellect
What Marx in the Grundrisse called the “general intellect” is the becoming of society’s accumulated knowledge and skill into a productive force. An AI model is the most concentrated form of this to date: the statistical summary of everything billions of people have written, drawn, coded, and argued. The model is crystallised collective labour. That is what I meant in the Karaburun presentation by “the expropriation of the general intellect”: the enclosing of the common and its conversion into private property.
The distillation quarrel is the second layer of this expropriation. In the first layer, capital distills humanity’s commons into the model and declares property over the model. In the second layer, another capital distills that model again and the first capital shouts “theft.” For the accusation of theft to work, the first expropriation must remain invisible. The “fair use” doctrine supplies exactly that invisibility: it reduces the labour of billions of people, in law, to the status of “ownerless raw material.” The Department of Justice’s 2 September brief and the NSA’s 8 September advisory are not opposites; they are complements. The first fills the inside of the enclosure; the second guards the fence.
This double face of property is not new. At the birth of capitalism, common lands were enclosed because they were “not being used productively”; the peasant who entered the enclosed land became a “thief.” Today collective knowledge is taken into the model because it is “publicly available”; the rival who learns from the model’s output becomes a “thief.” The logic of Marx’s analysis of primitive accumulation continues, even if the terms change: property is first established by seizure, then protected by a law that forbids seizure.
Let us see this as well: although the concrete content of the accusation is “fake accounts” and “breach of terms of service,” what turns it into a national-security matter is that US capital needs the state in its competition with Chinese capital. The policy demands in Anthropic’s February report, in list form: chip export controls, intelligence sharing among laboratories, coordination with the state. That is, the company calls on the state’s apparatus of force to stop its rival; the state, in reply, lifts the same company’s copyright liability in another case. What we call the intertwining of state and capital under monopoly capitalism is being read not from a textbook but from one week’s news flow.
What changes for the labourer?
In this quarrel the danger for the working class is two-sided, independent of which side wins.
First, access to models will be shut down still further on the pretext of a “distillation attack.” One of the demands in Anthropic’s report is “stronger verification” for education and research accounts. That is, the chance for universities, small laboratories, and independent researchers to learn from these models will narrow; distillation will remain an operation that only large laboratories perform internally. Pressure on open-weight models will increase; indeed according to CNBC in July 2026, even Nvidia, Microsoft, and Meta were forced to warn against “premature restrictions” on open-weight models.
Second, the question of who owns the general intellect will be reduced entirely to “America’s or China’s?” The debate in Turkey is squeezed between these two poles as well: some liberals saying “let us protect American technology,” some geopoliticians saying “China is right, hegemony is breaking.” Neither asks the same question: whose labour fed these models, and where are the owners of that labour in this debate? The journalist, the translator, the software worker, the teacher, the forum writer — none of them is on the agenda of either state.
Concrete tasks
There are concrete ways not to remain a spectator to this matter, and to speak without falling into the “America or China” trap.
Computing labourers and unions should reframe the distillation debate as a debate on labour, not intellectual property: if the model’s input is whose labour, then the ownership of its output must also be discussed. This is a direct part of the tasks of the newly founded computing unions and of those we proposed in The Computing Labourer’s Handbook.
Academics and researchers should defend open-weight and public models against the access that will be narrowed on the pretext of a “distillation attack.” That public universities train shared models, and make training data public and auditable, should be put on the agenda as a demand of science policy.
Journalists and writers should tell the New York Times case and the accusations against Chinese companies in the same story, side by side. What the public needs to see is not two separate news items but two faces of a single property logic.
Those who debate AI policy in Turkey should object to the country’s being confined, in this quarrel, to the position of “whose API will we use.” The labour of the millions of people who produce Turkish text has been distilled in both US and Chinese models; what is to be demanded in return for that labour is not cheap API access but a policy of open data and open models.
Young comrades should learn the technique of distillation. This is not an accident: the skill of transferring the knowledge of large models into small, cheap, locally run models is one of the most practical tools for reducing dependence on the monopolies’ closed systems. What the monopoly calls “theft” is often knowledge becoming a commons again.
Comrades,
The AI monopolies say they have “learned” the whole written accumulation of humanity, and they call that learning. When their rivals learn from their outputs, they call that theft. The same state, in the same week, for the same operation, says first “fair use” and then “national-security threat.” This inconsistency is not a mistake; it is how property works. Property is a class relation that determines whose learning is permitted and whose learning is a crime.
Our task is not to choose one of two blocs of capital, but to ask out loud the question both of them conceal: from whose labour were these models made, and when will the owners of that labour have a say? The general intellect, as the name says, is general. Whichever side of the fence it is on, to demand it back is legitimate.
Knowledge belongs to everyone.
Sources
- CISA, NSA, FBI, "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies", 8 September 2026.
- CyberScoop, "Feds accuse China of 'systematic' distillation of U.S. AI models", 8 September 2026.
- Nextgov/FCW, "Intelligence agencies warn of China's large-scale AI model distillation efforts", 8 September 2026.
- Defense One, "China is trying to steal US AI models' secrets, intel agencies warn", 8 September 2026.
- Bloomberg, "US Says Alibaba, DeepSeek Have 'Systematically' Siphoned AI Models", 9 September 2026; the open-access version at Business Standard.
- NBC News, "U.S. agencies say top Chinese AI companies systematically copied American models", 8 September 2026.
- IBTimes UK, "US Names Six Chinese AI Firms Accused of Stealing Claude, GPT and Gemini Capabilities", 9 September 2026.
- The Next Web, "White House accuses China of industrial-scale AI model distillation, commits to intelligence sharing with OpenAI, Anthropic, Google", April 2026.
- Anthropic, "Detecting and preventing distillation attacks", 23 February 2026.
- CNBC, "Anthropic accuses DeepSeek, Moonshot and MiniMax of distillation attacks on Claude", 24 February 2026.
- CNN Business, "OpenAI now wants to make DeepSeek look like the villain", 30 January 2025.
- TechCrunch, "Microsoft probing whether DeepSeek improperly used OpenAI's API", 29 January 2025.
- University of Michigan News, "Unpacking DeepSeek: Distillation, ethics and national security", January 2025.
- Quartz, "Trump administration backs OpenAI in NYT copyright lawsuit", 2 September 2026.
- The Intercept, "Trump Admin Tells Court: Let OpenAI Rip Off The Intercept's Articles", 2 September 2026.
- Wikipedia, "The New York Times v. Microsoft and OpenAI".
- NPR, "Anthropic pays authors $1.5 billion to settle copyright infringement lawsuit", 5 September 2025.
- Authors Guild, "What Authors Need to Know About the $1.5 Billion Anthropic Settlement".
- CNBC, "Nvidia, Microsoft, Meta warn against 'premature restrictions' of open-weight models", 24 July 2026.
- Crypto Briefing, "China sets conditions for US AI talks, criticizes Anthropic over model distillation dispute", 31 August 2026.







