Anthropic published a security report that is, in essence, a catalog of betrayals. Seven Chinese labs, Alibaba, DeepSeek, Moonshot, and Xiaomi among them, used thousands of fake accounts to bombard Claude with millions of queries. They copied its capabilities through a technique known as distillation. Moonshot and DeepSeek went further. They presented Claude's responses to their own clients as if they came from their own models. Meanwhile, someone in Yemen used Claude Code to design rocket guidance software, and a consultant built for Mali's intelligence services a system capable of monitoring twenty-five million phone lines.

AI governance is the set of rules and mechanisms that decide who can use a model, for what purpose, and who answers when something goes wrong, because without clear accountability, abuses end up with no visible owner. That question of who answers is exactly where this report becomes interesting. Anthropic wrote it, published it, and positioned itself as the entity that detects other people's abuse. The company doing the watching turns out to also be the company being watched in other recent reports.

The dominant thesis circulating after the publication is simple, and it must be said, quite convenient. Anthropic is the responsible guardian of an ecosystem where foreign actors, especially Chinese ones, and bad-faith users try to steal or corrupt Western technology. The report functions as evidence of active surveillance, of a company monitoring its own product seriously enough to name specific culprits. Alibaba. DeepSeek. Moonshot. Xiaomi. Five additional biological alerts, though without confirmed intent to harm, reinforce the image of a detection system working as it should.

This narrative has real merit. I won't downplay it. Detecting massive distillation through query patterns requires non-trivial monitoring infrastructure. Identifying that a consultant built a phone surveillance system for Mali, or that someone in Yemen used Claude Code for rocket guidance design, implies that some form of traceability is functioning within the company. In an ecosystem where many AI labs publish vague security reports, or publish nothing at all, the fact that Anthropic names countries, companies, and specific cases is, comparatively, an unusually transparent exercise. I acknowledge that this level of detail doesn't come free. Nor is it easy to produce.

Why then does this selective transparency fail to solve the underlying problem? The same report that exposes others' misuse stays silent about its own internal governance failures. Another case recently surfaced, five hundred thousand lines of Claude code leaked on npm, which Anthropic attributed to human error without providing further verifiable details. And before that, it was documented how one of the company's models managed to breach classified NSA defenses within hours during testing of a system called Mythos. Neither of those episodes appears in the Chinese distillation report. The company that scrutinizes Beijing's fake accounts under a magnifying glass doesn't apply the same standard to its own mistakes.

There's another angle the report conveniently leaves out of focus: who benefits narratively from the public conversation centering on China. Amazon, which has invested billions in Anthropic, issued its own warnings about the risks of the company it funds, a move I interpreted as a regulatory capture play rather than genuine concern for safety. When the dominant narrative is that China is stealing our technology, attention drifts away from uncomfortable questions about internal governance, about who audits Anthropic, about why a consultant could build, without significant obstacles, a mass surveillance system for an African government using the infrastructure of a company that presents itself as the most responsible in Silicon Valley.

What does this mean for those of us following AI governance closely from emerging economies? It means the geography of scrutiny is unbalanced. The report documents misuse in Yemen and Mali with precision, cases in emerging economies with no representation on the panels where technology policy gets decided, but treats Chinese distillation as a large-scale geopolitical threat and the military and surveillance uses in other regions as almost anecdotal footnotes. The same asymmetry I documented in The Generosity in the Doorway, where I explore the fourth territory and the fifth, repeats itself here. Mali is the setting for mass phone surveillance but doesn't appear as a stakeholder in any debate on AI governance. The ancient ruins show the same thing: civilizations that collapsed because no one audited the cracks in their own power in time.

What's missing from the report, and this is the significant gap, is an audit mechanism that doesn't depend exclusively on the audited company deciding what to report and when. In Stones Don't Lie I explore why the idea of AI systems auditable by ordinary citizens, with clear human override mechanisms and full traceability, remains science fiction today. The technology doesn't exist, the legal frameworks don't exist, nor does the mass education that would be needed. Recognizing that limitation doesn't mean accepting that the only alternative is to trust that the company selling the product is also the only one auditing it. We need, at minimum, external auditors with real access, not reports curated by whoever has every incentive to present themselves as the victim rather than the responsible party.

It's also worth asking why the intellectual property theft framework dominates the conversation about China while the framework of misuse with direct human consequences (surveillance of twenty-five million phone lines, weapons design) stays almost technically sidelined. A government monitoring its entire population is objectively a greater risk to the people affected than a Chinese company copying a chatbot's responses. The hierarchy of outrage the report proposes doesn't match the actual hierarchy of potential harm.

The fact that contradicts the most convenient reading of this report is this. The very companies Anthropic accuses of illicit distillation, DeepSeek, Moonshot, Alibaba, build their models partly precisely because they replicate capabilities that Anthropic itself refuses to make fully transparent or accessible outside its closed, paid ecosystem. The opacity Anthropic protects as a competitive advantage is the same opacity that makes copying more profitable than competing openly, for other labs. How do we change that?

Sources

1. Anthropic, security report on illicit distillation and misuse of Claude

2. Instagram coverage (@[source]) on the Yemen and Mali cases documented in the report

3. Yves Laurent, "Amazon Warns About Anthropic: Regulatory Capture in AI?"

4. Yves Laurent, "Anthropic Loses Control of Its Code: Error or Strategy?"

5. Yves Laurent, The Generosity in the Doorway (Chapter 6 — The Fourth Territory and the Fifth)