AI Risk Clock
Doomsday Clock2 min to midnight
→
THE ONE VOICE DESK · Mon, 13 Jul 2026

Anthropic's Distillation Hypocrisy: Rules for Thee, Not for Me

Satya Nadella's swipe at Anthropic reveals the industry's central hypocrisy: training on everyone's data while locking down your own. The safety farce has a new act.

Last week I wrote that the GPT-5.6 pardon and Sol's secret sauce were just the latest acts in AI's safety farce. This week, Satya Nadella has obligingly provided the sequel. In a post widely interpreted as a swipe at Anthropic, the Microsoft CEO noted that companies which happily invoke fair use to train their models on publicly available data are the same ones imposing restrictive terms on others who wish to distill their models' outputs. It is a beautiful piece of hypocrisy, delivered with the exquisite subtlety of a brick through a window.

For those who don't spend their weekends reading licensing agreements, distillation is the practice of training a smaller, cheaper model to mimic the outputs of a larger, more expensive one. Anthropic has publicly opposed the practice, claiming it violates its terms of service and could lead to unsafe models. The company has even gone so far as to update its terms specifically to prohibit distillation — a move it frames as a safety precaution. But this is safety as a cudgel, not a principle. The same company that built its models using vast swathes of internet text, scraped without consent under the banner of fair use, now turns around and says, 'Yes, but ours is special.' It is the digital equivalent of a car manufacturer that builds its vehicles using steel from a common mine, then demands that no one else be allowed to reverse-engineer its engine design.

The hypocrisy is not unique to Anthropic, of course. It is endemic to an industry where every company believes its own model is the sacred one, while everyone else's is a potential source of misuse. OpenAI has long taken this stance with its API terms. Google's AI principles are famously selective. But Anthropic has cultivated a particular brand of moral earnestness — the company was founded, after all, on the principle of constitutional AI and a commitment to safety above profit. When that public commitment collides with a desire to protect market share, the earnestness curdles into sanctimony. The company's opposition to distillation is framed in the language of risk: what if a distilled model bypasses safety guardrails? But the logical extension of that argument is that only Anthropic can be trusted to build safe models, which is a neat coincidence if you are Anthropic.

There is, of course, a simpler explanation for the anti-distillation stance: money. Frontier models cost hundreds of millions to train. Distilled models are cheap to run, which threatens to commoditise the market and undermine the business model of those who have invested heavily in the frontier. Anthropic's position is therefore not a safety measure; it's a moat. And if safety happens to be a convenient justification for the moat, so much the better. This is where the safety farce I have been tracking for weeks reaches its logical extreme. The same companies that demand transparency and accountability from competitors (and from regulators) are opaque and restrictive when it comes to their own intellectual property.

What makes Nadella's swipe particularly delicious is that he is not exactly a saint either. Microsoft has its own history of selective safety, as I noted in my column on the GPT-5.6 pardon. But it takes a certain kind of chutzpah for a company like Anthropic — which built its reputation on being the ethical alternative — to pull the ladder up after itself. If safety were truly the concern, the industry would be collaborating on standardised evaluation and shared guardrails. Instead, we get licensing restrictions that serve as thinly veiled competitive tactics.

The real tragedy is that distillation is, in many ways, a safety-enhancing practice. Distilled models are smaller, more interpretable, and easier to audit. They allow researchers and smaller organisations to build on frontier work without requiring access to server farms. By opposing distillation, Anthropic is not preventing unsafe models — it is preventing more eyes on the problem. If the AI safety movement is serious about its mission, it should be championing open distillation, not stamping it out. Until that happens, I will continue to treat every safety claim from Silicon Valley with the same suspicion I reserved for Sol's secret sauce: a lot of heat, not much light, and a distinct smell of burning self-interest.

● REC · 2026