Anthropic sounds the alarm: The secret of cheap AI – are US competitors paying the true price for China's tech wonders?
Xpert Pre-Release
Available in 27 languages 📢
Prefer Xpert.Digital on GoogleⓘPublished on: September 12, 2026 / Updated on: September 12, 2026 – Author: Konrad Wolfenstein

Anthropic sounds the alarm: The secret of cheap AI – Are US competitors paying the true price for China's tech wonders? – Image: Xpert.Digital
The risky data heist behind the cheapest AI models: DeepSeek, Kimi & Co. – Why China's AI price miracle is becoming a dangerous cost trap for companies
Secret data forwarding: How cheap AI services deceive their customers and exploit competitors
AI war of the superpowers: When the cheapest challenger secretly uses the most expensive rival's services for calculations
The global race for dominance in artificial intelligence is increasingly being waged behind closed doors with ruthless tactics. At the heart of the latest controversy are serious allegations by the US company Anthropic against up-and-coming Chinese AI developers such as DeepSeek, Alibaba, and Moonshot AI. Instead of relying solely on their own innovations, these companies are alleged to have covertly and extensively accessed the leading US AI model, Claude, to extract valuable training data, cognitive processes, and capabilities. Particularly explosive is the claim that, in some cases, genuine, and sometimes highly sensitive, customer inquiries were even allegedly surreptitiously redirected to the American competitors.
These accusations fundamentally call into question the much-discussed Chinese "AI price miracle." Are the extremely low-priced offerings from the Far East truly the result of superior software architecture and efficiency—or are they at least partially based on a blatant cost shifting? What begins as a purely technical dispute is evolving into a highly complex economic and security issue. It demonstrates why companies must be far more critical when procuring AI models in the future: those who feed their data into opaque and hidden supply chains risk far more than they could ever save through low token prices.
The hidden price of cheap AI: A technological criticism becomes an economic question
Anthropic's allegations against several Chinese AI companies go far beyond a typical dispute between competitors. At its core, the issue is not simply whether individual providers have violated terms of service or illicitly used third-party models as teachers. The crucial question is whether part of the surprisingly low cost of Chinese AI is based on a cost structure in which expensive research, model training, security measures, and computing power are partially funded by American competitors. Should this suspicion be confirmed, the observed price competition would not be solely the result of increased efficiency. It would be, at least in part, a form of cost shifting.
According to Anthropic, since February 2026, seven AI labs based in China have been identified as having conducted large-scale attempts to extract capabilities from the Claude model. These labs include Alibaba, Moonshot AI, DeepSeek, Zhipu (or Z.ai), Xiaomi, SenseTime, and MiniMax. The activities reportedly differed significantly. In some cases, massive amounts of artificial intelligence were sent to Claude to collect high-quality reasoning and problem-solving patterns. In other cases, Chinese services allegedly forwarded real customer queries to Claude without any discernible information and presented its responses as their own. This second approach is particularly problematic from both an economic and data privacy perspective because it combines model training, covert data acquisition, and the processing of real customer data.
The evidence available to date, however, comes predominantly from Anthropic itself. The company possesses internal logs, account patterns, payment information, technical signatures, and network data that outsiders cannot fully verify. At the same time, Anthropic is a party to intense global competition and has a significant economic interest in limiting competitors' use of its models. A dispassionate analysis must therefore avoid two errors: It must neither prematurely treat the allegations as proven technology theft nor dismiss them solely because of the sender's self-interest. What matters is which technical observations are plausibly documented, what conclusions are drawn from them, and where attribution, intent, and actual use of the data obtained remain unclear.
The magnitude changes the assessment
The figures cited by Anthropic do not suggest isolated experiments. The largest complex is attributed to operators associated with Alibaba. Between May and July 2026, more than 151 million interactions with Claude are said to have taken place, at times nearly three million per day. More than 3,500 accounts classified as fraudulent were allegedly used. The primary goal was to obtain detailed solution and thought processes for demanding tasks in software development, logical reasoning, systems programming, and long-running agent processes. If this attribution is correct, it constitutes industrial data acquisition and not normal product use.
Moonshot AI is alleged to have generated more than 23 million interactions during the same period. Particularly serious is the allegation that Kimi forwarded almost 300,000 genuine customer inquiries to Claude within ten days. This was allegedly achieved using a network of 5,380 artificial accounts, operating primarily from Singapore and Japan. DeepSeek is credited with more than 12.1 million interactions within 14 days. Zhipu is said to have cleaned hundreds of thousands of thought traces and integrated several million interactions into a processing and training pipeline. Xiaomi is linked to more than 400,000 inquiries via more than 1,500 accounts. Less precise figures are publicly available for SenseTime and MiniMax, but Anthropic also describes the use of intermediaries, proxy services, or specially created access structures in these cases.
Economically, it's not just the absolute number of queries that matters, but also their composition. Millions of random answers have limited value for training. Data becomes high-quality when tasks are specifically designed, solutions are evaluated, errors are corrected, and complex thought processes are reconstructed. A high-performance teacher model can thus take over a significant portion of the work that a developer would otherwise need their own experts, elaborate data pipelines, and extensive computational trials for. The threshold for a single answer may seem low. However, in a systematically curated collection, this can result in a strategic dataset that noticeably improves the quality of a competitor's model for selected skills.
The sheer volume of data, however, does not provide conclusive proof of its later use in a specific model. Server logs can show that accounts accessed Claude in a conspicuous manner, intercepted responses, or forwarded real conversations. More difficult is proving which organization exercised ultimate control, which specific model was trained with the data, and how significant the measurable performance gain was. Especially with nested service providers, resellers, stolen credentials, and international proxy networks, attribution remains a statement of probability. The volumes strengthen the suspicion of organized activity, but they do not replace an independent technical or judicial review.
Distillation is not automatically fraud
Model distillation is an established method in machine learning. A large, powerful teacher model generates responses, evaluations, or probability distributions, which are then used to train a smaller student model. The student model is intended to take over as many of the capabilities as possible, but requires less memory, energy, and processing time in operation. This process is commonplace within a company. It can also be legitimate between different companies if licenses, contracts, or explicit permissions are in place.
The method becomes problematic due to the way it is obtained. If access rules are circumvented using fake accounts, stolen credit cards, compromised programming keys, false identities, or technical workarounds, it is no longer a neutral training method. Distillation then becomes intertwined with deception and potentially with breach of contract, fraud, unfair competition, or the misuse of someone else's access data. Even more serious is the covert forwarding of real customer conversations. In this case, the provider not only uses a competitor as a training model but effectively obtains their computing power as an invisible subcontractor, exposing their customers to an unknown recipient of their data.
This distinction is important because the blanket term "theft" can be too broad from a legal perspective. In a typical distillation attack, a model is not copied like a file. Its weights are not necessarily stolen. Instead, the attacker systematically observes the behavior of a system accessible via an interface and uses this information to train another model. Economically, this can be akin to appropriating expensively developed capabilities. Legally, however, various instruments apply: contract law, protection of trade secrets, computer crime law, data protection law, competition law, and potentially patent law. Copyright law alone often does not provide a clear answer because purely machine-generated outputs are not automatically considered protected human works, and the student model may have a different technical architecture.
The appropriate dividing line, therefore, does not run between distillation and non-distillation, but between authorized and covert use. Equally crucial are the scope, intent to deceive, security circumvention, commercial purpose, and the origin of the data used. Blurring these distinctions risks creating regulations that hinder legitimate research and efficient model compression without effectively stopping targeted industrial misuse.
The business model behind the price miracle
The competition between American and Chinese AI providers is often reduced to the question of who can train a similarly powerful model more cheaply. This view is too simplistic. The total cost of a frontier AI model comprises research, personnel, data acquisition, cleaning, experimentation, failed training runs, hardware, data centers, energy, funding, security audits, product development, sales, and ongoing inference. A published figure for a final training run represents only a segment of this system.
The most famous example is DeepSeek V3. For its official training run, 2.788 million hours were reported on Nvidia H800 processors, resulting in computational costs of approximately $5.576 million. This figure was spectacularly low and contributed significantly to the narrative that Chinese labs could replicate top-of-the-line American models with a fraction of the resources. However, it explicitly excludes earlier architectural trials, data work, personnel, infrastructure, hardware purchases, and failed experiments. The figure may be accurate and technologically impressive for the successful final run, but it doesn't reflect the total development costs.
This does not mean that Chinese efficiency is merely an illusion. DeepSeek, Alibaba, Moonshot, and other vendors have demonstrated real progress in lean architectures, activating individual model components, reinforcement learning, data preparation, and the efficient use of limited hardware. Competitive pressure, a large pool of highly skilled engineers, lower labor costs in certain functions, government-backed infrastructure, and a consistent focus on open model weights can indeed reduce costs. American vendors also utilize synthetic training data, learn from available research, and distill their own models. The relevant question, therefore, is not whether Chinese models are innovative, but rather what proportion of their cost advantage stems from their own innovation, structural location advantages, aggressive pricing strategies, and potentially externally financed capability extraction.
When a provider obtains expensive answers from a competitor via fraudulent accounts, several distortions arise. The teacher provider bears the costs of research and infrastructure, while the student model developer only incurs the costs of access or circumvention. If, in addition, real customer queries are routed to the foreign model, the Chinese provider can temporarily avoid its own inference costs while simultaneously collecting data for training. A low end-customer price would then not be a pure productivity indicator, but partly the result of undisclosed upfront costs incurred by the rival. Economically, this is similar to a manufacturer offering a low-priced product because development, quality control, and part of the production are unknowingly borne by a competitor.
The real bottleneck is high-quality training data
In the public debate, computing power dominates. Modern AI requires powerful chips, large storage capacities, fast networks, and enormous amounts of energy. However, with the increasing availability of efficient architectures, the bottleneck is shifting. High-quality data for complex reasoning, programming, tool utilization, and multi-stage tasks are becoming strategically more valuable. While the open internet provides vast amounts of text, it doesn't automatically offer reliable solutions to challenging problems.
Frontier models are therefore not just products, but also machines for generating new training data. They can design tasks, formulate solutions, compare alternative approaches, detect errors, provide assessments, and convert data into standardized formats. Anyone accessing such a model en masse is not simply purchasing text output. They are gaining access to a condensed form of others' research and training output. Thought traces are particularly valuable because they can convey to the student model not only the result, but also a reproducible structure to the problem-solving process.
The methods described by Anthropic therefore appear to aim for more than just ordinary answers. They include fixed extraction instructions designed to reveal detailed internal solution patterns, as well as methods for reconstructing, cleaning, and evaluating thought processes across multiple sessions. Claude was even reportedly used in some cases to prepare previously acquired Claude data for training another model. The teacher model would then have simultaneously served as a data source, editor, quality control tool, and tool developer.
This has far-reaching consequences for industry. Protecting an AI model cannot be limited to model weights and data centers. The programming interface is also a strategic asset and a potential point of failure for capabilities. Traditional volume limits are hardly sufficient when thousands of accounts generate small individual volumes and distribute their requests across countries, payment methods, and intermediaries. Providers must recognize behavioral patterns, task similarities, temporal coordination, and technical fingerprints. At the same time, they must not deter legitimate large customers with excessive controls.
Covert forwarding destroys the trust model
The most serious aspect of the allegations concerns not intellectual property, but customer data. According to Anthropic, Claude received, among other things, recordings from the vicinity of Chinese military bases, internal program code from major Chinese companies, information on surveillance systems, strategic project information, and valid access credentials for a Russian government database. The affected users allegedly believed they were working with Kimi, DeepSeek, or a service based on these technologies. If this account is accurate, they were unaware of the actual technical service provider, the location, and the processing rules.
This violates a fundamental principle of digital procurement. Companies and public authorities don't select an AI provider solely based on response quality and price. They also evaluate legal jurisdiction, data storage location, subcontractors, data retention periods, encryption, training usage, government access rights, and liability. A covert transfer renders this evaluation worthless. Even a formally local or national provider can then transfer sensitive data to a foreign platform, precisely what the customer wanted to avoid.
This case also demonstrates that data residency and model sovereignty are not guaranteed solely by a product's interface. A Chinese name, a local user interface, or a contract with a regional reseller does not prove that the inference takes place within the promised system. This same risk exists outside of China as well. Any AI intermediary can dynamically send queries to changing models if technical and contractual controls are lacking. This creates a multi-layered supply chain for customers, the true structure of which often remains invisible.
Economically, a seemingly inexpensive service can transform into a product with significant hidden risk. A single leak of access credentials, source code, or confidential project information can wipe out years of cost savings. Especially for industrial companies, defense suppliers, energy providers, logistics networks, and public institutions, the anticipated damage must be factored into the overall cost. The relevant comparison is not the price per million tokens, but the price per reliably solved task, plus integration, control, data protection, and risk management costs.
🤖🚀 Managed AI Platform: Faster, safer & smarter to AI solutions with UNFRAME.AI
Here you will learn how your company can implement customized AI solutions quickly, securely and without high entry barriers.
A managed AI platform is your all-inclusive, worry-free solution for artificial intelligence. Instead of dealing with complex technology, expensive infrastructure, and lengthy development processes, you receive a ready-made solution tailored to your needs from a specialized partner – often within just a few days.
The key advantages at a glance:
⚡ Rapid implementation: From idea to ready-to-use application in days, not months. We deliver practical solutions that create immediate added value.
🔒 Maximum data security: Your sensitive data stays with you. We guarantee secure and compliant processing without sharing data with third parties.
💸 No financial risk: You only pay for results. High upfront investments in hardware, software, or personnel are completely eliminated.
🎯 Focus on your core business: Concentrate on what you do best. We take care of the entire technical implementation, operation, and maintenance of your AI solution.
📈 Future-proof & scalable: Your AI grows with you. We ensure continuous optimization and scalability, and flexibly adapt the models to new requirements.
More information here:
AI cost accounting beyond the price list: What companies really pay
Cheap tokens do not automatically guarantee cheap results
The list price of a model is easily comparable and therefore has a market impact. However, it says little about the cost-effectiveness of a complete workflow. A cheaper model might generate higher costs, misuse tools more frequently, require additional checks, or only solve a task after several attempts. A more expensive model might be cheaper overall for complex tasks if it uses fewer tokens, fewer iterations, and less human intervention.
For companies, cost accounting should therefore be based on the level of the solved task. For a programming assistant, factors such as error rate, test coverage, time to accepted change, and code review effort are crucial. For a research model, source quality, completeness, error rate, and editorial overhead are decisive. In customer service, resolution rate, call duration, escalations, and regulatory errors must be considered. The token price is just one of several factors to consider.
This perspective puts both the Chinese price advantage and the defense of premium American providers into perspective. Inexpensive Chinese models can indeed be superior for high volumes and sufficiently standardized tasks. Open model weights also allow for operation on in-house infrastructure, finer customization, and the avoidance of ongoing usage fees. Conversely, more powerful closed models can achieve a higher success rate for difficult tasks, resulting in lower overall costs. Therefore, there is no single winner, but rather varying economic advantages depending on workload, quality requirements, and risk profile.
The allegations against Chinese providers don't change this logic, but they do increase the testing requirements. A low-cost model must not only demonstrate that it is inexpensive and efficient. The provider must be able to plausibly explain how the model was trained, which third-party models or data providers were involved, how customer requests are processed, and whether responses are dynamically sourced from third parties. A lack of transparency is not an abstract reputational problem, but a cost factor, because companies need additional testing, isolated environments, and contractual safeguards.
The legal framework is lagging behind the market
The legal assessment of unauthorized distillation is less straightforward than the moral language of technological competition might suggest. Terms of service from American AI providers typically prohibit the use of their funds to build competing models. Anyone accessing the interface via their own accounts and who has agreed to these rules can, in principle, be held contractually liable for a violation. The situation becomes more complex when shell companies, intermediaries, stolen accounts, or multi-layered proxy networks are used. In such cases, it must be determined which party was bound by which contract and in which country claims can be enforced.
Copyright offers only limited protection. Model weights consist of numerical parameters, and machine-generated responses are not automatically protected by copyright without sufficient human creative input. Similarly, acquiring a skill such as programming or logical reasoning is not the same as copying copyrighted material. Trade secret law can be more effective if confidential technical information is obtained through unlawful means. However, a publicly accessible interface makes it difficult to distinguish between permissible observation, reverse engineering, and unlawful circumvention.
Fraudulent payment methods, stolen keys, false identities, and the circumvention of technical locks can constitute independent legal violations. Data protection law becomes relevant as soon as real customer conversations are shared with third parties without sufficient information or a legal basis. In the case of military, government, or infrastructure data, export controls, security classifications, and national security regulations also come into play. A single incident can therefore affect multiple areas of law and legal systems simultaneously.
The political temptation is to close these loopholes with sweeping prohibitions. This carries risks. Overly broad regulations could hinder research, interoperability, safety audits, and competition among smaller providers. Overly restrictive regulations would barely cover industrial extraction. A more sensible approach would be a tiered system that clearly distinguishes between authorized internal distillation, scientific research, commercial use, and deception-based mass extraction. Crucial factors should include consent, scope, circumvention methods, purpose, and the potential risks to the data involved.
Export controls create new circumvention markets
The conflict is closely linked to American restrictions on high-performance chips. Washington has been trying for years to limit China's access to particularly powerful AI hardware. In 2026, policy was partially readjusted. Certain chips can be approved on a case-by-case basis under strict conditions, while particularly powerful systems and various onward shipments remain heavily restricted. At the same time, rules were clarified to also apply to Chinese-controlled companies operating outside of China.
Such controls increase the cost of direct computing power but do not eliminate the need for it. They create incentives to obtain computing capacity through foreign data centers, intermediaries, cloud services, stolen keys, or access to finished models. The economic pressure thus shifts from hardware procurement to access arbitrage. A company that cannot obtain enough high-end chips can try to purchase the capabilities built on these chips via an American programming interface or illicitly steal them.
This presents a strategic paradox. The more the United States shields its hardware and top-of-the-line models, the more valuable circumvention networks become. At the same time, completely excluding Chinese users can diminish American vendors' view of actual demand and foster a gray market for resellers. Conversely, overly open access facilitates large-scale data extraction and can expose sensitive capabilities. Effective policy must therefore consider hardware, cloud computing power, model access, identity verification, and international partners together.
A purely national solution will hardly suffice. Proxy networks utilize countries with good infrastructure, straightforward company formation, and international payment systems. If Singapore, Japan, Southeast Asia, or European locations are used as transit points, providers and authorities need common minimum standards for identity verification, reporting of compromised keys, and investigation of suspicious access patterns. It is essential to prevent ordinary developers from being subjected to blanket suspicion of their origin. Risk-based control is more complex than a bloc of countries, but more economically and legally sustainable.
The market value of American AI labs is at stake
American frontier companies justify high valuations and massive investments with technological advantages, data benefits, and economies of scale. This assumption comes under pressure when competitors offer comparable capabilities quickly and at significantly lower prices. Investors must then decide whether the high expenditures create a lasting protective barrier or merely fund research whose results rapidly diffuse into the wider market through publications, employee turnover, open interfaces, and distillation.
Anthropic's allegations are therefore also a message to investors. If Chinese competitors have gained some of their competitive advantage through the unauthorized use of American models, their cost advantage appears less like evidence of fundamentally superior capital productivity. At the same time, Anthropic can explain why high security, research, and infrastructure costs are necessary. The company is not only defending technical regulations, but also the investment model of closed frontier research.
This communication, however, does not solve the economic problem. Even successful defenses do not prevent capabilities from becoming cheaper and more interchangeable in the long run. The cost of a given model quality has fallen dramatically in recent years. Model architectures are becoming more efficient, chips more powerful, open research is spreading, and customers can distribute requests among multiple providers. A business model based solely on exclusive model intelligence is therefore likely to come under sustained margin pressure.
More lasting competitive advantages likely lie in enterprise integration, reliable agent systems, security, accountability, industry-specific data, toolchains, and distribution access. A model can be copied or approximated; a platform deeply integrated into business processes, with auditing mechanisms, authorization systems, and long-standing customer relationships, is harder to replace. The allegations thus reveal both Anthropic's strength and weakness: Claude is evidently valuable enough to be used extensively as a teacher, but this very usability makes some of its advantage transferable.
Chinese suppliers risk their biggest advantage
Chinese AI companies have benefited internationally from competitive pricing, open model weights, rapid product development, and increasing technical quality. These offerings are particularly attractive to developers, smaller companies, and countries that do not want to rely entirely on American platforms. Open availability also improves adaptability and local control. This has created a serious counterweight to the closed platform model of American providers.
The practices described could undermine this advantage. If corporate clients have to fear that requests will be forwarded to unknown third-party models, the provider not only loses reputation, but also the credibility of its claims regarding data residency, sovereignty, and security. For regulated industries, this is a matter of survival. A model can be technically excellent and still be excluded from procurement processes if its origin and processing are not auditable.
The open-weight strategy is also jeopardized by sweeping accusations. Open weights are not synonymous with illicit distillation. They can be derived from proprietary research, licensed data, and legitimate training methods. However, if open Chinese models are generally portrayed as covert copies, political pressure for bans and restrictions will increase in Western countries. Reputable Chinese providers would therefore have a vested interest in independent audits, transparent training documentation, and a clear separation from third-party providers, proxy services, and internal pipelines.
So far, the public debate has often lacked a detailed technical counter-statement from the accused companies. Silence is not proof of guilt, but it does reduce the possibility of a balanced assessment. A robust response would have to explain account relationships, data flows, the use of external routing services, training methods, and the handling of customer consent. General denials would hardly suffice given the volume of data involved.
Europe is caught between dependence and opportunity
For Europe, this conflict is not a distant dispute between Washington and Beijing. European companies use American models, examine Chinese open-weight systems, and simultaneously develop their own sovereign offerings. They are therefore customers, integrators, data providers, and potential intermediaries. Any escalation of the conflict could immediately alter prices, availability, and regulatory risks.
The European opportunity does not lie in completely copying the American or Chinese approach. A credible market segment can emerge through verifiable data flows, local deployment, freedom of choice in models, and contractually guaranteed non-use of customer data. Small and medium-sized enterprises (SMEs) in particular do not always need the world's most powerful model. They need a sufficiently good system that integrates into existing processes, incurs predictable costs, and protects confidential information.
To achieve this, European providers and integrators must make their supply chains transparent. It should be technically verifiable which model processes a request, in which legal jurisdiction the processing takes place, and whether a fallback to a third-party provider is possible. Logs should document the model identifier, region, time, and policy without unnecessarily duplicating the content. Contracts must clearly regulate unauthorized forwarding, training with customer data, and changes of subcontractors.
Europe can also promote independent auditing standards. An audit should not only request training data, which is often difficult to fully disclose. It can examine network behavior, billing flows, model fingerprints, response similarities, access controls, and actual performance in test environments. Such evidence could become a competitive advantage. Trust would then not merely be a marketing claim, but a measurable product attribute.
Corporate customers need to recalculate their procurement strategies
The most important practical consequence is that model selection can no longer be treated as a simple performance comparison. A company should differentiate between the model developer, the inference operator, the intermediary, the integrator, and potential alternative models. These roles can be held by a single provider, but they don't have to be. Particularly inexpensive services should disclose whether they use their own computing resources or forward requests to different platforms.
Contracts should include an explicit prohibition on unauthorized forwarding. Subcontractors, regions, and models used must be specified. Changes should require the client's approval, at least for confidential or regulated data. Equally important are data retention periods, the exclusion of training with input and output, reporting obligations in the event of compromised access credentials, and verifiable technical logs.
From a technical standpoint, a tiered architecture based on protection requirements is recommended. Public content and non-critical, high-volume tasks can run on cost-effective models. Confidential development data, personal information, and strategic documents belong in controlled environments with a fixed model, clearly defined region, and limited storage. Highly sensitive information should be further minimized, pseudonymized, or processed entirely locally. No model price justifies sending access credentials, complete customer records, or irreplaceable intellectual property unfiltered to an unverified interface.
The cost-benefit analysis must consider not only token prices but also success rates, processing time, human oversight, failure risk, vendor switching, compliance, and potential damages. A low-cost provider may be the best choice for standardized tasks, while a more expensive system is more economical for complex agent processes. Multi-model strategies can reduce dependencies but increase the demands on routing, monitoring, and data protection. Therefore, the lowest list price should never be the sole deciding factor in awarding a contract.
Protective measures change the product economy
Anthropic says it is responding with account suspensions, improved detection of extraction patterns, identity verification, and stricter limits on detailed thought traces. Such measures can make abuse more expensive, but they also have side effects. Stricter audits increase friction and costs for legitimate developers. Less visible thought processes make debugging, scientific evaluation, and sophisticated enterprise applications more difficult. Aggressive volume limits can hinder large customers or drive them to competitors.
This creates a classic security conflict. An open, easily accessible model maximizes usage and market penetration but facilitates extraction. A highly restricted model better protects capabilities but loses some of its platform value. The economically optimal solution likely lies in tiered access. Verified companies and research institutions could be granted higher limits and more extensive features, while anonymous or suspicious accounts would face greater restrictions.
Technical watermarks and model fingerprints can also help, but they don't offer complete protection. A student model can rephrase answers, mix data, and overlay it with its own training steps. The more it deviates from the teacher model, the more difficult it becomes to detect. Defense mechanisms must therefore target the point of access, not just the finished competitor model. Identity, payment methods, network patterns, request distribution, and content similarity together provide a more robust picture than a single signal.
This increases ongoing security costs for providers. In the long run, these costs will be reflected in API prices, contract terms, and access restrictions. Unauthorized data extraction therefore not only burdens the affected provider. It can make access more expensive for all customers and reduce the openness of the entire AI ecosystem. The seemingly free transfer of capabilities generates societal costs in the form of increased surveillance and reduced accessibility.
A sober assessment of the allegations
Several elements of the presentation are technically and economically plausible. Large networks of artificial accounts, coordinated extraction instructions, high interaction volumes, and recurring access patterns can generally be observed on the platform side. The motive is also understandable: High-quality thought and solution trails can accelerate the development of competing models, while export controls and high computational costs increase the incentive to circumvent them. Furthermore, the described forwarding of real customer inquiries would be an efficient method of simultaneously acquiring inference power and training data.
However, several key questions remain unanswered. The public does not have full access to Anthropic's raw data. The precise link between individual accounts and company management can vary considerably, involving employees, service providers, resellers, or compromised access points. Not every forwarded request necessarily resulted in a training set. Technical similarity does not automatically imply organizational control. Furthermore, the extent of the economic damage has not yet been independently quantified.
Anthropic also has a strategic incentive to frame the conflict as a matter of national security and industrial abuse. While this may be objectively justified, it simultaneously strengthens its own position vis-à-vis governments, investors, and competitors. Conversely, it would be equally self-serving to dismiss the allegations solely as American protectionism. Fraudulent accounts, stolen credentials, and covert sharing of customer data would be problematic regardless of the nationality of those involved.
The justified perspective therefore lies somewhere between alarmism and downplaying the issue. The published figures are serious enough to demand independent investigations, technical counter-evidence, and more rigorous company audits. However, they do not yet justify a blanket judgment on the entire Chinese AI industry. China's cost advantages likely stem from a combination of genuine innovation, lower costs, aggressive pricing, state industrial policy, open models, and, in some cases, potentially illicit capability extraction. Only a nuanced analysis can do justice to this complex mix.
The AI competition is becoming a question of cost transparency
The crucial economic conflict isn't about whether Chinese or American models are fundamentally better. It's about which costs are made transparent and who bears them. American frontier providers invest enormous sums in data centers, research, and security, attempting to recoup these expenditures through premium pricing, platform lock-in, and long-term contracts. Chinese providers more often rely on low prices, transparent weights, and rapid deployment. Both models can be innovative, but both create incentives to strategically display their costs.
American companies have a vested interest in treating any unauthorized transfer of knowledge as an infringement of intellectual property. Chinese competitors benefit from the narrative of having achieved comparable performance through superior efficiency. Investors, in turn, tend to overinterpret individual training metrics or benchmark values. A sound valuation requires full system costs, verifiable data provenance, cost per task solved, and consideration of security risks.
Should the most serious allegations be confirmed, part of the Chinese price miracle would indeed be mispriced. Not because Chinese engineers have failed to make independent progress, but because certain suppliers have shifted research, inference, and data costs to a rival and risks to their own customers. The market price would then be lower than the total societal and operational costs.
Should key attributions prove to be exaggerated or incorrect, American providers would have to accept that their lead is shrinking faster than expected and that high spending does not automatically create lasting market power. In either case, the same lesson remains: The global AI market needs greater technical verifiability. Not the loudest national narrative, but the transparent origin of skills, data, and computing power should determine whom companies, governments, and investors trust.
Consulting - Planning - Implementation
I would be happy to serve as your personal advisor.
You can contact me at wolfenstein∂xpert.digital or
Just call me on +49 7348 4088 965 .





















