September 27, 2026, (Inside AI) — As Chinese President Xi Jinping met with U.S. President Donald Trump in Washington this week, a technical term once confined to machine learning research papers became a diplomatic flashpoint. At the center of the talks: repeated accusations from American AI giants that Chinese companies are stealing their technology through a process called distillation.
The claim, leveled for nearly two years by firms including Anthropic, OpenAI, and Google, has become a key tension in U.S.-China tech relations. But many experts say the narrative is overstated, and the legal and technical realities are far more nuanced than the public debate suggests.
What Distillation Actually Does
Distillation was first developed in the early 2010s as a way to make AI systems more efficient. Researchers would collect data from a large, established model and use it to train a smaller system that could run on cheaper hardware.
"Think of one model as the teacher and the other as a student," Geoffrey Hinton, a former Google researcher who helped develop the technique, recently told The New York Times.
Read: Xi and Trump Launch Formal AI Dialogue in Washington
More recently, the technique has morphed into a way for companies to extract data from competitors. An outside firm sets up multiple accounts on a service like Anthropic's Claude or OpenAI's GPT, assigns those systems tasks like coding or math, and uses the generated outputs to train its own model.
This is not the same as copying source code. The distiller only sees the words and characters the system produces, not the underlying architecture. That distinction matters legally.
Some legal scholars argue distillation could violate the Defend Trade Secrets Act, which allows companies to sue over stolen trade secrets. But U.S. courts have not ruled on the issue. Copyright law is also a poor fit because distillation copies behavior, not text word for word.
Critics of Anthropic and OpenAI point out that both companies have faced similar accusations. Anthropic is fighting multiple lawsuits over its use of copyrighted internet data. Last year, it agreed to pay $1.5 billion to authors and publishers after a judge ruled it had illegally downloaded and stored millions of copyrighted books. That settlement remains the largest payout in U.S. copyright history.
OpenAI and Microsoft face their own suits, including one brought by the Times in 2023. That case contends the companies used millions of Times articles to train chatbots that now compete with the news outlet. OpenAI and Microsoft deny the claims.
China's Models Aren't Just Copies
Chinese firms have most likely distilled proprietary American systems. But the full picture is unclear. After Chinese startup DeepSeek released a powerful and efficient model last year, OpenAI accused it of distillation. As Chinese systems improved over the past nine months, Anthropic made similar claims. In June, Anthropic sent a letter to Sens. Tim Scott, R-S.C., and Elizabeth Warren, D-Mass., accusing Chinese tech giant Alibaba of distilling its technologies. The Chinese companies have not responded publicly.
Yet distillation alone does not explain China's progress. When a company distills a proprietary system, it only gets partial access to the teacher model. It cannot see the underlying code, as it could with an open source system.
"You are not getting access to everything you would use when you are distilling your model in-house," said Rehaan Ahmad, co-founder of Silicon Valley startup alphaXiv, which tracks AI research.
Before using those outputs, a Chinese company must first build a system that is already powerful in its own right. Distillation can then refine that model, but it requires additional work, money, computing power, and talent.
"The narrative that all of the capabilities of the Chinese technologies coming from an Anthropic model is not as true as people say it is," said Charles O'Neill, head of model training at Baseten, a U.S. company that sells access to Chinese technologies.
Can Anthropic and OpenAI stop distillation? They have tried. If they suspect an account is distilling their systems, they may shut it down. But others pop up. And shutting down too many accounts risks barring legitimate users.
"It is basically impossible to stop distillation," said Lino Le Van, another alphaXiv researcher.
As Washington and Beijing navigate an increasingly tense tech rivalry, distillation sits at an awkward intersection. It is a legitimate research technique, a potential trade secret violation, and a geopolitical talking point. The lack of court rulings leaves companies and governments guessing. Meanwhile, Chinese models continue to improve, and American firms continue to accuse. The next chapter may be written not in courtrooms, but in the quiet, persistent work of training the next generation of AI systems.