Stop model copying
Anti-distillation controls. KYC for high-volume API access, hidden reasoning traces, output fingerprinting and rate limits.
What it does
Labs must verify large API customers, hide models' full reasoning, and watch for accounts that copy model outputs to train competing models.
Applies to: Frontier developers offering API access.
- Verify identity for high-volume API customers and enforce terms against training on outputs.
- Do not expose full reasoning traces by default.
- Fingerprint outputs and share attack telemetry across labs and with government.
Where things stand
Anthropic reported over 16 million exchanges through about 24,000 fraudulent accounts in February 2026 and, in September, the largest distillation campaign it had measured, attributed to Alibaba, with over 151 million exchanges. OpenAI told a House committee it observed DeepSeek obtaining outputs through obfuscated third-party routers. A joint NSA, CISA and FBI advisory in September 2026 named six Chinese labs. Labs are already tightening; a mandate standardizes it.
Why it costs almost no lead
It costs U.S. labs a little product polish. The benefit depends entirely on how much China depends on U.S. models: none if it doesn't, about 4 days at "a little."
Biggest unknown: How much of Chinese progress actually came from distilling U.S. outputs, which is the same thing your worldview is about.
Why it lowers p(doom) by ~0.03%
Stops rivals from copying U.S. models by training on their answers.
It keeps capabilities from spreading to labs with weaker safety practices. The effect on overall risk is small.
The strongest case that it costs more
A higher U.S. price: hidden reasoning traces and heavy KYC degrade the product for legitimate developers, and U.S. open-weight releases would need the same treatment or the controls are pointless. A lower China price: DeepSeek V4's model card describes distilling from its own specialist models, and the behavioral evidence of U.S. lineage is suggestive rather than quantified. Nobody has shown how many months distillation bought.
The debate
For
- OpenAI told Congress DeepSeek keeps trying to distill U.S. models and asked for government help, 2026.
- Anthropic named DeepSeek, Moonshot and MiniMax and said no company can solve this alone, 2026.
- House Select Committee on the CCP found it highly likely DeepSeek used unlawful distillation, 2025.
- NSA, CISA and FBI named six Chinese labs and recommended detection and information sharing, 2026.
Against
Sources
- Anthropic, Detecting and preventing distillation attacks (Feb 23, 2026)
- Anthropic Threat Intelligence Report, September 2026: Alibaba campaign: over 151 million exchanges
- NSA/CISA/FBI advisory AA26-251A (Sept 8, 2026)
- OpenAI memo to the House Select Committee on the CCP (Feb 2026)
- Busbridge et al., Distillation Scaling Laws (ICML 2025)
Rough starting points, not precise forecasts. Lead costs assume China doesn't depend on U.S. models, the case least favorable to safety laws, and count 3 years. On the menu you can change every assumption and put in your own numbers. Last priced 2026-09-26.