Skip to main content
  • Home
  • LLM
  • AI Model Distillation Is Quietly Redrawing the AI Power Map

AI Model Distillation Is Quietly Redrawing the AI Power Map

Picture

Member for

1 year 9 months
Real name
Keith Lee
Bio
Keith Lee is Professor of AI and Finance at the Gordon School of Business, Swiss Institute of Artificial Intelligence (SIAI). His primary research lies in financial mathematics and AI-driven computational science, with a focus on quantitative modeling of complex economic and financial systems. His work integrates machine learning, stochastic modeling, and data-centric methods to study structural transformations in markets and institutions.

His recent work examines the broader socioeconomic consequences of artificial intelligence, including labor markets, public finance, demographic change, institutional adaptation, and the distributional effects of technological progress.

He holds a PhD in Mathematical Finance from Boston University, and previously earned an MSc in Finance and Economics from the London School of Economics. He completed his undergraduate studies in Economics at Seoul National University under the Korea Foundation for Advanced Studies scholarship program.

Modified

Chinese-origin AI models jumped from 4.5% to 63% of enterprise use in one year
No law defines illegal AI distillation, letting extraction pass as ordinary training use
Closing that legal gap, not banning open models, protects both competition and security

Chinese-origin AI models made up roughly 4.5 percent of enterprise token usage on the OpenRouter marketplace in the first half of 2025. By the first week of July 2026, that share had climbed to 63 percent. Fourteen times higher in about a year. Behind that number sits a technique with a plain name and a murky legal status: AI model distillation. It means training a cheaper model to copy the behavior of a more expensive one. Distillation is not new. Anthropic and OpenAI both use it to build budget versions of their own flagship products. What changed in 2026 was scale and method. Rival labs were accused of pulling capability out of American systems through fabricated accounts, not paid use in the normal sense. That line, between training a model and stripping one, is where the real contest over AI leadership now plays out.

The Real Threat Behind AI Model Distillation

The usual way to talk about open-weight AI models treats them as a simple yes or no question. Should the United States restrict them, or let the market sort it out. This framing missed what actually happened between February and August 2026. Anthropic disclosed that DeepSeek, Moonshot and MiniMax had generated more than sixteen million exchanges with its Claude models. They did it through roughly twenty-four thousand fraudulent accounts. The company called it an industrial-scale extraction campaign. Four months later, Anthropic told the Senate Banking Committee something bigger. Operators tied to Alibaba's Qwen lab had run 28.8 million exchanges through nearly twenty-five thousand fake accounts in six weeks. That single episode was larger than the three earlier cases combined. By July, a Chinese open-weight model had outscored Anthropic's own flagship on a widely watched coding leaderboard. In that same stretch, brief export restrictions forced Anthropic to pull two of its newest models from the market entirely.

Figure 1: Four disclosures in eighteen months turned a technical debate into a live policy fight.

None of the accused labs has been found liable for anything, because no case like this has been tested in court yet. Model outputs are not covered by copyright. Copyright requires a human author and a model is not one. So any legal remedy has to come from somewhere else: trade secret law, or federal computer fraud statutes that were not written with this situation in mind. That gap matters more than the underlying technique does. Routine distillation, done through standard paid access, is common practice across the industry. It is not against the law anywhere. What Anthropic describes as an attack is the method of access, not the training step, a distinction clean in theory and hard to enforce in practice. The accounts behind the disclosed campaigns were not researchers running occasional queries. They were coordinated networks. They could manage thousands of identities at once, built to look like everyday traffic while quietly pulling out a narrow, valuable slice of a rival's capability.

Why the Pricing Gap Keeps Widening

Money explains a good part of why this fight matters now. DeepSeek's V4 Flash model reached seventy-nine percent on the SWE-bench Verified coding benchmark in April 2026. That put it within two points of its own larger sibling. Yet it charged roughly a tenth of a cent per thousand output tokens, about one hundred fifty times cheaper than a comparable American closed model. A widely read technology blog ran the numbers on a bigger model too. It found DeepSeek's V4 model priced at $3.48 per million output tokens, against roughly $75 for Anthropic's comparable Opus model. Architecture alone cannot explain a gap that size. Anthropic and OpenAI both remain cash-flow negative as of mid-2026. Every dollar of pricing power lost to a cheaper competitor cuts into the capital available for the next training run.

A congressional advisory body found in March 2026 that roughly 80 percent of American AI startups were already building products on Chinese open-weight models. Some of that shift reflects genuine efficiency gains. Some reflects Chinese state subsidy, which almost certainly lowers compute costs at the margin. Some of it simply reflects a markup that American labs had been charging and are now losing as competition tightens. All three explanations can be true at once. None of them fully accounts for a fourth channel that gets less attention: AI model distillation as a direct transfer of a costly capability from one lab's model into another's, at a fraction of what building it independently would cost. Inside the disclosed February campaign, the extraction was not spread evenly. One firm alone accounted for nearly four-fifths of the exchanges. A single determined actor, not a broad industry pattern, can drive most of the damage in a given episode.

Financial markets have started pricing this risk directly. Coverage of Alibaba's release of a model that matched or beat Anthropic's own flagship within days used a stark phrase for the resulting market: a death zone. Any provider lacking either frontier capability or rock-bottom pricing risks losing share outright. Anthropic's own accusation against Alibaba was followed by a sell-off in Alibaba's shares. It shows that investors on both sides of the Pacific now treat distillation exposure as a real line item, not a rumor. Between the two disclosed campaigns, the ratio of exchanges to fraudulent accounts nearly doubled, climbing from roughly 688 to about 1,152 exchanges per account. Extraction is getting more efficient, not just larger.

Figure 2: Four forces, not one, are pulling pricing power away from frontier labs at once.

What Counts as Legitimate Training

Supporters of open publication make an argument worth taking seriously and it deserves a serious answer rather than dismissal. More than two hundred seventy companies signed an open letter in July 2026, including Microsoft, Google, Meta and Nvidia. Their claim: openness strengthens security on its own, by exposing systems to wider scrutiny and reducing single points of failure. That claim holds up well in mainstream software security, where more eyes on code tends to catch more bugs. Anthropic's own rebuttal points elsewhere. The logic breaks down, it argues, in domains with a strong offense advantage. Biological weapons design is the sharpest example. A capable model there could shorten the path to serious harm faster than defenders could respond. Neither side has settled that argument with hard evidence yet.

The more immediate policy question is simpler. Can extraction be detected and separated from normal use. Anthropic says the accounts behind its disclosed campaigns ran through what it calls hydra cluster networks. These are coordinated groups that can manage more than twenty thousand accounts at once, routing traffic through third-party cloud platforms to dodge regional access limits. This kind of infrastructure looks nothing like a research team running normal queries. A workable policy response would let an independent body verify these claims, not the accusing company alone. Sanctions should target the fraudulent conduct, not open-weight publication itself, since weights already released cannot be unreleased. A related proposal, sometimes called a nutrition label for the AI supply chain, would require services operating in the United States to disclose which base models they actually run on. A meaningful share of American developers are building on Chinese models without knowing it themselves.

Security at the source matters just as much as detection after the fact. One of Anthropic's most restricted models was reportedly accessed by outside hobbyists on a public forum before its official release. Several hundred fraudulent accounts ran millions of queries against it during that window. That detail complicates the idea that extraction is purely a function of foreign sophistication. A company asking the government to treat its model outputs as strategic assets carries an obligation to secure them first, well before it asks the state to backstop that security through sanctions or trade restrictions.

What Happens If Nobody Draws the Line

A dispute inside the WordPress ecosystem offers an unlikely but useful comparison. In 2024, WordPress co-founder Matt Mullenweg accused the hosting company WP Engine of taking value from the open-source project without giving enough back. He cut off its access to core infrastructure, until a court forced the access restored. The specifics were messy and personal. The underlying claim was not: an open resource, sustained by a small group of contributors, only stays healthy if the businesses profiting from it put something back. AI distillation follows that same pattern in reverse. Frontier labs have spent tens of billions of dollars on training. The labs accused of extracting from them have, by Anthropic's account, spent nothing beyond the cost of running fake accounts.

The likely outcome falls between two extremes. American AI development does not collapse. China does not take over the field either. Frontier labs still hold enterprise and government contracts that are more insulated from consumer price wars than headline subscription numbers suggest. The slower and more consequential shift is different: a frontier that grows more secretive and more expensive to reach, as labs protect what pricing power remains. That means retreating from the openness that helped the field move as fast as it did in the first place. This slow retreat, more than any single accusation or lawsuit, is the real cost of leaving AI model distillation legally undefined.

Fourteen-fold growth in twelve months is not a rounding error. It did not happen because Chinese labs became fourteen times better at building models overnight. It happened because a legal and commercial system with no settled definition of illicit distillation left plenty of room for extraction to pass as ordinary use. Closing that gap does not require banning open-weight models, a step Anthropic itself has declined to ask for. It requires independent verification instead of taking an accuser's word alone. It requires sanctions aimed at fraud rather than at technology. And it requires public investment in domestic open alternatives good enough that developers choose them on the merits. Absent that combination, the frontier will not disappear. It will get smaller, more guarded and more expensive to reach and that is its own kind of loss for the openness that built this industry.


This article is based on an original research article published by The Economy Research. For the original version, please refer to Open Weights, Extracted Capabilities: Reassessing the Distillation Economy and the Contest for American AI Leadership.

This article reflects the analytical judgment of the author and does not constitute policy advice or the official position of any affiliated institution.

Picture

Member for

1 year 9 months
Real name
Keith Lee
Bio
Keith Lee is Professor of AI and Finance at the Gordon School of Business, Swiss Institute of Artificial Intelligence (SIAI). His primary research lies in financial mathematics and AI-driven computational science, with a focus on quantitative modeling of complex economic and financial systems. His work integrates machine learning, stochastic modeling, and data-centric methods to study structural transformations in markets and institutions.

His recent work examines the broader socioeconomic consequences of artificial intelligence, including labor markets, public finance, demographic change, institutional adaptation, and the distributional effects of technological progress.

He holds a PhD in Mathematical Finance from Boston University, and previously earned an MSc in Finance and Economics from the London School of Economics. He completed his undergraduate studies in Economics at Seoul National University under the Korea Foundation for Advanced Studies scholarship program.