The Nexus Uplink Dispatch
On September 8, US federal agencies alleged that Chinese AI firms are carrying out “industrial-scale” theft of American AI trade secrets, naming six companies in an intelligence advisory that Beijing rejected within the day. The same news cycle carried a Google Threat Intelligence Group report describing enterprise AI assets, from model weights to cloud compute quotas, as high-value targets for espionage, extortion, and resource theft.
Two days later, Anthropic published its fourth threat intelligence report, an account of misuse it says it detected and disrupted between December 2025 and August 2026, sorted into seven harm areas. Six of those areas got the headlines. Kamikaze drone swarms and virus grant proposals will do that. The discussion that belongs in this newsletter is the seventh, illicit distillation.
Distillation trains a smaller model on the outputs of a larger one. The student learning from the teacher’s answers rather than from the raw corpus the teacher learned on. The technique is a decade old, named in a 2015 paper by Geoffrey Hinton and colleagues, and it is legitimate to the point of being ordinary industry practice. Every lab distills its own frontier models into the small fast ones it actually sells.
The economics explain the temptation. A frontier model costs hundreds of millions of dollars to train, and its behavior can be sampled for the price of API calls. In early 2025, OpenAI said it had evidence that DeepSeek had distilled its models, defining the moment the practice crossed from technique to accusation.
The legal footing is thinner than the outrage suggests. Provider terms forbid training competitors on outputs, so unauthorized distillation is at minimum a contract breach. Whether it is also theft is a question. Trade-secret law was written for documents that leave buildings, and courts have not settled what it means for a capability extracted through a public interface, one authorized for a query at a time. The September 8 advisory calls it theft outright. Anthropic’s report is more careful, reserving the word illicit for covert harvesting at industrial scale, done without permission.
The report says Anthropic has disrupted distillation campaigns from seven China-based labs since February, all aimed at its generally available models. The largest, tracked as GTG-16005 and attributed to Alibaba, ran chain-of-thought distillation against Opus 4.6 and 4.7 at a peak of nearly three million exchanges per day from more than 3,500 fraudulent accounts. Anthropic counts over 151 million exchanges between May and July and says the harvested transcripts went into training three successive Qwen releases.
The supporting cases are stranger. One lab’s pipeline reportedly included Claude transcripts purchased from third-party data vendors, which means the stolen output had already developed a resale market before anyone upstream noticed. Another built its proxy access through a shell company whose product list offered only Anthropic and OpenAI models, a storefront that existed only in name.
The practitioner question is the usual one. Which security control failed? The control catalog, NIST SP 800-53, adopted in Canada as ITSP.10.033, has always known how to protect a trade secret that lives in a file. Media protection governs where the weights sit (MP-4) and how they are destroyed (MP-6). Protection of information at rest (SC-28) encrypts them. Personnel security screens the people near them (PS-3) and recovers access when they leave (PS-4). January’s conviction of a former Google engineer, the first for AI economic espionage, was a failure and then a vindication of exactly this family. Two thousand pages copied to a personal cloud account over a year is a burglary. The catalog has a shape for burglaries.
Distillation touches none of those controls. No file leaves the building. No badge is misused and no repository is breached. The extraction runs through the authorized interface, one completion at a time, paid for at list price or under it. Every individual exchange is a legitimate API call. The theft exists only in the aggregate, which is precisely where per-request security controls do not work.
The catalog does contain a control that could help. AC-23, Data Mining Protection, asks organizations to detect and protect against unauthorized mining of data stores while still permitting authorized use. It was written with databases in mind and it is scoped out of nearly every baseline as an exotic. It stops reading as exotic the moment you accept that a frontier model is a data store, that a query is a lookup, and that 151 million lookups from 3,500 manufactured identities is a mining operation.
The countermeasures Anthropic describes are AC-23 by other names. Extraction classifiers watch the aggregate behavior of accounts rather than the compliance of single requests. Metadata attribution unpicks the proxy networks that launder where the queries come from. The interesting move is conceptual. The provider stopped asking whether each call was allowed and started asking what the caller was building.
Four practices follow for anyone operating a model worth copying, and for anyone whose vendor operates one.
Classify extraction at the interface. Rate limits cap volume per account. They say nothing about a thousand accounts each staying politely under the cap. Detection has to run on the aggregate, across accounts, sessions, and time.
Treat account genesis as security telemetry. The 3,500 accounts were the campaign’s actual infrastructure. Signup patterns, payment fingerprints, and proxy overlap are audit records, and they belong in the same review pipeline as any other log source.
Put provenance clauses on data vendors. If model transcripts can be bought wholesale, then transcript acquisition belongs in vendor due diligence on both sides of the trade. Ask your data suppliers where the corpus came from. Ask your own terms of service what happens when the answer is you.
Publish the ledger. A threat awareness program (PM-16) is usually an inbox that receives feeds. Anthropic’s report is the other direction, a provider publishing its own abuse record with actor designators and counts. The September 8 advisory names the actors. The September 10 ledger shows the mechanism. An allegation of industrial-scale theft is a policy document. A count of 151 million exchanges is evidence, and evidence is what a control assessment runs on.
Readers of the Mobius Nexus Cycle will recognize this geometry. In the books, the Uplink is the only channel to the Venn homeworld, and the Fragments Operation turned on a fact the characters learn slowly and the channel operator knew from the start. Whoever runs the channel holds the record of everything that ever crossed it. The API provider is the channel operator. Nothing in this month’s reporting suggests the record was wrong. The open question, there and here, is what the operator does with it, and how long the counting ran before anyone was told.
The weights never left the building. The capability did.
RECORD RETAINED / SOURCE INTEGRITY UNCONFIRMED


