AI model distillation: why the model was never the moat

Anthropic accused leading Chinese AI labs of using Claude to train rival models through AI model distillation, with Alibaba's campaign alone hitting 151 million exchanges. Our view: if a model's behaviour copies that easily, the model was never the moat. The defensible asset is your workflow.
TL;DR: If 35 million requests can quietly copy a frontier model's behaviour, then the model was never the moat — your workflow is.

Key takeaway: AI model distillation proves that raw model capability is copyable at scale; the defensible asset is the human-authored workflow around it, not the model itself.

Why it matters: Marketing teams betting their edge on "which model we use" are defending the wrong thing. The orchestration, judgement and process are what competitors can't quietly siphon.

What happened with AI model distillation and Claude

Anthropic published a threat report accusing several Chinese AI labs of using Claude to train their own models through a technique called distillation. According to Business Insider's summary of the report, the labs named include Alibaba, Moonshot, DeepSeek, Zhipu and Xiaomi.

The numbers are large. TechCrunch reported that the campaign attributed to Alibaba alone involved 151 million exchanges between May and July 2026, peaking at nearly three million exchanges a day across roughly 3,500 accounts.

Source: TechCrunch, 2026

The mechanics matter. Distillation means using outputs from a stronger "teacher" model to train a cheaper "student" model until it imitates the original. As one explainer puts it, the expensive part — discovering the capability — was already paid for by the teacher, so the student's cost is essentially generating a dataset plus a comparatively cheap fine-tuning run.

Source: DEV Community, 2026

Most commentary will frame this as IP theft and a US-China arms race

The obvious reading is geopolitical. A frontier lab spends hundreds of millions building a model, a rival quietly harvests its behaviour through fake accounts, and terms of service turn out to be unenforceable across borders. Cue debate about export controls, sovereignty and who's "winning" the AI race.

That framing isn't wrong. But it treats the model as the crown jewel — the thing worth stealing and worth protecting. And that's exactly the assumption we'd push back on.

Our take: the model was never the moat — the workflow is the IP

Here's the uncomfortable bit for anyone selling AI on the strength of its model. If a competitor can approximate your model's most valuable behaviours with a few million API calls, then the model was a temporary lead, not a durable asset. Distillation is just the loudest proof of a trend that was already obvious: capability leaks downhill, and it leaks fast.

In our experience building agents, the part nobody can quietly copy is the workflow. Not the raw intelligence — the scaffolding around it. Which model gets called for which task, what data it's grounded in, where a human signs off, how failures get caught, and how brand rules are enforced before anything ships. That's human-authored process, and AI output on its own isn't copyrightable. The workflow is the layer with a defensible claim.

We think this reframes the whole "which model should we use?" panic. The model is a commodity input that will get cheaper and more replaceable every quarter. Your competitive position lives in the orchestration: the decisions, the sequence, the judgement encoded into how the system runs. A rival can distil Claude. They cannot distil the six months you spent learning exactly how your audience responds and building that into a repeatable process.

This is why we build AI agents for marketing around scoped, inspectable workflows rather than one clever prompt against whichever model is topping the leaderboard this month. If the model underneath changes tomorrow — and it will — the workflow is what survives the swap. That continuity is the asset, and it's yours in a way the model never was.

The honest version of the AI pitch isn't "we have the smartest model." It's "we've done the unglamorous work of turning a capable model into a reliable, on-brand process — and that work doesn't fall out of an API call." Distillation copies answers. It doesn't copy the reasons you chose those questions.

What this means for marketing teams

  • Stop benchmarking on model choice alone. Audit your top three AI-assisted workflows this quarter and document who owns each decision step — that record is your defensible IP.
  • Assume your model provider will change within 12 months. Build so you can swap the underlying model without rebuilding the process around it.
  • Encode brand and compliance rules into the workflow, not into review meetings. Aim for on-brand by construction, checked before publish, not after.
  • Keep a human sign-off on anything that carries legal or reputational weight. Distillation shows how quickly machine output propagates — decide deliberately what ships unreviewed.
  • If you're mapping where your real moat sits, our plans and what each includes lay out how we structure workflow ownership — worth a look before you commit to any stack.

Frequently asked questions

What is AI model distillation?

Distillation trains a smaller model on the outputs of a larger one until it imitates its behaviour. It lets a lab approximate a frontier model's capabilities at a fraction of the original training cost.

Did Chinese AI labs really use Claude to train their models?

Anthropic's 2026 threat report accuses labs including Alibaba, Moonshot, DeepSeek, Zhipu and Xiaomi of large-scale distillation. It reported Alibaba's campaign alone involved 151 million Claude exchanges between May and July 2026.

If models can be copied, what actually protects an AI marketing system?

The human-authored workflow: which model handles which task, how data grounds it, where humans approve, and how brand rules are enforced. Raw AI output isn't copyrightable; the process around it is defensible.

Written by the Anjin team - we build AI marketing systems and remain professionally unimpressed by hype.

Continue reading