I skimmed through Anthropic’s distillation report this morning. When I saw Alibaba, the Moon’s Dark Side, and DeepSeek being mentioned, my first reaction wasn’t “here we go again”—it was that API distillation had already been, to some extent, semi-public in that space.

But the phrase “persistent attacks” made me think a bit more: it’s technically quite hard to prevent closed-source models’ outputs being taken to train smaller models. If you rely on output watermarking or behavioral auditing, the engineering effort is large, and it’s also easy to mistakenly flag legitimate users.

The root issue might not be security, but a business model that’s leaking. Model weights have become a new kind of oil, but the pipelines haven’t been designed with valves yet.