Distillation attacks
Plain English. Using a frontier model's own API to extract its capability into a rival model — distillation, the technique, turned against its owner as unauthorised capability transfer. This entry is the security and economics; the technique itself lives at that entry. The attacker needs no weights, no code and no breach: enough well-chosen queries at retail prices, and the teacher's costliest asset walks out the front door.
Why it moves money. It converts a lab's R&D capex into a public good on the attacker's timetable, compressing the price premium a capability lead can charge and shortening the payback window on every training run — the direct threat to API-business defensibility. The defensive market (rate limits, account vetting, output watermarking) and the detection market (behavioural fingerprinting, provenance probes) are both nascent, and the allegations have escalated from lab-versus-lab claims to US agencies accusing Chinese firms of industrial-scale extraction. Note the asymmetry critics raise: the labs claiming theft trained on unlicensed material themselves, which weakens the moral case without weakening the commercial one.
What to watch. Whether attribution hardens into evidence — fingerprinting that survives adversarial laundering and would stand up in a courtroom or an export-control filing. Accusation is cheap; provable lineage would reprice the whole argument.
From the signals. Anthropic accuses Alibaba of capability theft — and reaches for a policy moat. Fingerprinting points Ox Alpha at GLM-5.3 on six of nine probes — evidence, not identification.
Further reading. Carlini et al., "Stealing Part of a Production Language Model".