OpenAI and Microsoft probed DeepSeek-linked accounts in 2025, and Anthropic named seven China-based labs for distillation in 2026
Distillation means training a model on another model's outputs. On 2025-01-29 Bloomberg reported a probe by Microsoft and OpenAI into DeepSeek-linked developer accounts allegedly pulling large…
- Date
- 29 January 2025
- Who
- OpenAI, Microsoft, Anthropic, DeepSeek, Moonshot, MiniMax, Alibaba, Zhipu, Xiaomi, SenseTime
- Confidence
- Medium (accusations by competitors; accused labs mostly silent)
- Deep dive
- Reasoning II, from o1 and o3 to DeepSeek-R1 and the labs that replicated them
Tier: Supporting · Significance: 4/5 · Org(s): OpenAI, Microsoft, Anthropic, DeepSeek, Moonshot, MiniMax, Alibaba, Zhipu, Xiaomi, SenseTime · Confidence: Medium (accusations by competitors; accused labs mostly silent) Distillation means training a model on another model's outputs. On 2025-01-29 Bloomberg reported a probe by Microsoft and OpenAI into DeepSeek-linked developer accounts allegedly pulling large volumes of data from the OpenAI API in late 2024. OpenAI said it was reviewing indications DeepSeek "may have inappropriately distilled" its models, and White House AI adviser David Sacks claimed "substantial evidence" (TechCrunch; the Bloomberg original not fetched). DeepSeek's R1 paper concedes web-crawled pre-training data contains OpenAI-generated text, denies deliberately including it, and Huan Sun, commenting on the Nature review, called that rebuttal convincing (paper App. A.1, Scientific American). No court finding or published evidence settled it in 2025.
In 2026 the accusations escalated. OpenAI's memo to the House China committee (reported 2026-02-12) alleged DeepSeek-linked accounts used obfuscated third-party routers to evade access limits (Taipei Times); Anthropic (2026-02-23) reported about 24,000 fraudulent accounts and over 16 million exchanges attributed to DeepSeek (150,000+), Moonshot (3.4M) and MiniMax (13M), targeting agentic reasoning, coding and tool use (Anthropic); and in its threat report of 2026-09-10 (Anthropic, which has an "illicit distillation" section; the part I could read is only the contents line, so the details below are from coverage) Anthropic named seven China-based labs, with harvesting reasoning as the headline charge, and listed Alibaba (151 million exchanges over May-July 2026 across 3,500+ accounts, extracting chain-of-thought transcripts with a fixed prompt), Moonshot (23 million exchanges, including about 300,000 live customer requests silently relayed to Claude over ten days via 5,380 accounts), DeepSeek (12.1 million+ exchanges in 14 days of July 2026, by relaying live requests and extracting reasoning transcripts), Zhipu/Z.ai (3.4 million+, replaying Claude reasoning traces), Xiaomi (400,000+), SenseTime (bought transcripts from third-party vendors) and MiniMax (a proxy network); TechCrunch gives a headline total of nearly 200 million exchanges across five campaigns (The Hacker News, TechCrunch, reported). The Information (relayed by The Next Web, 2026-09-22) reported that China's Cyberspace Administration summoned all seven but focused on DeepSeek and Moonshot, over Chinese user data flowing to Anthropic rather than over distillation itself.
On the defensive side, Claude Fable 5 (2026-06-09) added a "reasoning_extraction" refusal category for blocked attempts to duplicate its outputs (release notes), and an August 2026 paper showed that encrypted reasoning blocks could be replayed to extract plaintext CoT (B08-49b). Hiding raw reasoning (o1) was partly an anti-distillation measure, and the accusations show that the replication lag depends partly on API access. See also B20.