The Chinese are Ripping Us Off!

Conversational AI Watch

Conversational AI Watch

The news that moves policy, portfolios, and patient safety.

By Jess Jessop  |  July 8, 2026  |  Issue #89

▶ WATCH🎧 QUICK LISTEN🎧 DEEP DIVE📄 READ ON WEB

Yesterday's Pulse

China is forcing its biggest apps to switch off companion chatbots. Should the US do the same?

Yes, ban companions 25%
Disclosure, not bans 24%
No, let adults choose 28%
Depends on the user's age 23%

153 readers answered

Infographic titled The Chinese are Ripping Us Off. Panels this week: American labs telling the Senate that Chinese rivals used fake accounts to distill more than 28 million exchanges from Claude, with Anthropic briefly monitoring its own users to catch them; Illinois signing an AI Safety Measures Act with third-party audits and 72-hour reporting; Commerce clearing OpenAI's GPT-5.6 for broad release; Anthropic reserving the right to require ID and face scans from some Claude users; and research on cognitive surrender warning heavy AI use can weaken critical thinking.
Jess Jessop

JessJessop.Info

Jess's Take

The Chinese are Ripping Us Off!

US labs told the Senate that Chinese rivals siphoned tens of millions of answers from their chatbots to train their own. Illinois signed the toughest US AI law; Washington cleared OpenAI's top model.

It was a loud day on this beat, and Congress had nothing to do with any of it.

American labs told the Senate that Chinese rivals had siphoned tens of millions of answers out of their chatbots to train their own.

A governor in Illinois signed the toughest AI law in the country.

The Commerce Department cleared OpenAI's most powerful model for the open market.

Anthropic gave itself the right to ask some users for a photo ID and a face scan.

Sam Altman offered the public a slice of OpenAI while the Treasury quietly warned the whole thing might be a bubble.

And a new study asked whether these tools are making us worse at thinking.

. . .

This is CAW eighty-nine.

Reader Pulse

Face scan to chat. Where is the line?

🔥  Nailed it
✏️  Filing this one
💪  Push back harder
🤔  You lost me
💬  Hold my coffee

Forward to a colleague →  ·  Join the discussion →

. . .

THE SECRET AI WAR. American AI companies say their Chinese rivals are forcing their chatbots to work as unpaid tutors, and Anthropic has told the United States Senate exactly how. One Chinese team, it says, ran roughly twenty-five thousand fake accounts to pull more than twenty-eight million answers out of Claude to make its own model smarter.

The technique is called distillation. You take a large, expensive model, ask it millions of questions, and use its answers to train a smaller, cheaper model that ends up nearly as capable at a fraction of the cost.

Anthropic told senators that Alibaba's Qwen team generated more than twenty-eight point eight million exchanges with Claude through about twenty-five thousand fraudulent accounts. Three other Chinese labs, DeepSeek, Moonshot, and MiniMax, ran another sixteen million interactions through some twenty-four thousand fake accounts, in violation of Anthropic's terms and its regional access rules.

. . .

Here is the part that should sit uneasily. To catch the distillation, Anthropic in March quietly deployed code that checked whether a Claude Code user's computer was set to a Chinese time zone and tied to certain Chinese AI domains. It was watching its own users to find the ones it did not want. A software developer discovered the monitor, privacy advocates said the company was surveilling the people who pay it, and last week Anthropic pulled the code.

. . .

The company frames the stakes in national terms. In a May post it argued that if distillation and chip smuggling can be blocked, the United States might lock in a lead of twelve to twenty-four months over Chinese models. That is the argument now being made to the Senate. The company now moving to check users' faces to keep foreign nationals out is the same company telling Washington the foreign nationals are already inside, twenty-eight million questions deep.

For Legislators: The export-control regime you built is the reason for both halves of this week, the face scanning and the distillation defense. If the goal is a durable lead, decide whether user surveillance and biometric gates are a price you meant to authorize.

For Founders: Your terms of service are not a wall. Twenty-five thousand fake accounts walked through them. If your model's outputs are your moat, assume a well-funded rival is drinking from it right now.

For Counsel: Watching users by time zone and domain to enforce an export order is a surveillance fact pattern with its own liability. Anthropic pulled the code for a reason. Read that reason before you advise a client to build the same thing.

For Investors: The distillation gap is why a Chinese open model can reach near-frontier quality at a fifth of the cost. The moat you are underwriting may be twelve months wide, not five years.

Why it matters: The public argument over AI and China is about chips and spies. This is the quieter mechanism, and it runs straight through the chatbots themselves. The models are being copied by being used, and the defenses the American labs are reaching for, from watchlist-grade identity checks to watching their own customers, are starting to look like the thing they warn about.

Source: The Washington Post, Why Anthropic alleges Chinese firms are distilling knowledge from Claude, https://www.washingtonpost.com/national-security/2026/07/06/why-anthropic-alleges-chinese-firms-are-distilling-knowledge-claude/

Comment on this story →  ·  Forward this →

. . .

THE STATES WRITE THE RULEBOOK. While Washington gated models by letter, a governor picked up a pen. On July 6, Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act, the most demanding state AI law in the country, and with it a third large state moved to write the rules that Congress will not.

The law, Senate Bill 315, targets the largest developers, those pulling in at least five hundred million dollars a year. It requires them to publish a safety framework describing how they identify catastrophic risk, defined as an incident that could kill or seriously injure more than fifty people or cause more than a million dollars in damage.

It is the first state law in the nation to require an annual independent third-party audit. And it forces developers to report a serious incident to the state within seventy-two hours, or within twenty-four if the risk to life is imminent.

. . .

Illinois modeled the bill on measures from California and New York. Together those three states account for roughly two-fifths of the American AI market, which is the point. When the biggest states agree on a floor, that floor becomes the national standard whether or not Washington ever acts. Pritzker framed it plainly, saying the law is meant to rein in the tech companies rather than wait on them.

. . .

Illinois has done this before. Last August it became the first state to bar AI from making mental-health and therapeutic decisions, keeping a licensed clinician in the chair. This law is the frontier-safety companion to that one. The same state that said a machine cannot be your therapist now says the largest machine-makers must open their safety plans to an auditor. The message under both is identical. If the builder will not accept a limit, the state will set one.

For Legislators: This is a working template with an audit requirement and a reporting clock. Copy it. The federal vacuum is being filled state by state, and the states with the market share are winning the argument.

For Founders: A five-hundred-million-dollar revenue line now triggers published safety plans and an outside audit in Illinois. If you clear that bar, compliance is no longer optional in the three states that matter most.

For Counsel: The seventy-two-hour and twenty-four-hour incident clocks are the operational risk here. Build the internal detection and escalation now, because the first missed deadline is the first enforcement action.

For Investors: A de facto national AI-safety standard just formed without a federal law. Diligence on any frontier developer now includes California, New York, and Illinois compliance, not a bet that Washington preempts them.

Why it matters: The story of AI regulation in America has been the story of Congress doing nothing while the harm compounds. The states stopped waiting. With Illinois signing, the country now has a real rulebook for its most powerful AI, written in three statehouses instead of one Capitol, and it binds the biggest builders whether they like it or not.

Source: Capitol News Illinois, Pritzker signs landmark AI regulation bill that aims to mitigate risks, https://capitolnewsillinois.com/news/pritzker-signs-landmark-ai-regulation-bill-that-aims-to-mitigate-risks/

Comment on this story →  ·  Forward this →

. . .

WASHINGTON OPENS THE GATES. For weeks the government held the most powerful American AI models back for testing. This week it started letting them out. The Commerce Department has cleared OpenAI's GPT-5.6 for a broad public release, and OpenAI expects to ship it more widely within days.

The clearance came through the Commerce Department's Center for AI Standards and Innovation, the office now standing between a frontier model and the open market. OpenAI sent technical experts to Washington to answer questions, the government ran its tests, and the gate opened. GPT-5.6 had until now been held to a narrow set of trusted government partners. As of this week it is cleared to go wide.

. . .

The timing is not an accident. Anthropic's Fable 5 and its cybersecurity counterpart Mythos 5 had their export controls lifted on the last day of June, after nineteen days dark, once Anthropic agreed in a letter from Commerce Secretary Howard Lutnick to proactively detect security risks, help write the standards for future models, and report malicious activity. Anthropic's limited Fable promotion ran through yesterday. OpenAI's clearance lands the moment its rival's window closes.

. . .

What has quietly taken shape is a regime. A frontier model no longer ships when its maker decides it is ready. It ships when Washington finishes testing it and signs off. That is a profound change in who controls the release of American AI, accomplished in a matter of weeks, with almost no law written down. The models are being gated by handshake and letter, not by statute, and the next administration inherits whatever precedent this one sets.

For Legislators: Model release is now conditioned on executive-branch approval with no statute behind it. If that power should exist, it should exist in law, with limits, not in a secretary's letter.

For Founders: The path to market for a frontier model now runs through a government testing office. Budget for it. The gate is real, and the timeline is theirs, not yours.

For Counsel: A clearance regime built on private letters and voluntary commitments is a regime a court can unwind. Document what your client agreed to, because the terms are the only record.

For Investors: The release date of the model you funded is now partly a government decision. Price the regulatory gate into every launch assumption.

Why it matters: In the span of a month, the United States government went from ordering two of the most capable models offline to personally clearing them for sale. Whether you read that as responsible oversight or as unprecedented control over private software, it is happening without a vote, and it is now the way the most powerful conversational AI reaches the public.

Source: Axios, Trump administration lifts restrictions on OpenAI's GPT-5.6, https://www.axios.com/2026/07/08/openai-gpt-trump-ban-lifted

Comment on this story →  ·  Forward this →

. . .

ANTHROPIC WANTS YOUR FACE. As of today, July 8, the company that builds Claude can require a consumer user to prove who they are with a government ID, a live selfie, and a scan of the geometry of their face. Most people will never be asked. But the policy is now written into the terms, and with it Anthropic becomes the first major American AI lab to reserve the right to demand your biometrics, and the reason it did is a story in itself.

The policy covers consumer accounts, the Free, Pro, and Max tiers, and exempts Business, Team, Enterprise, and API customers. It is less a new feature than a newly formal one. Anthropic has run identity checks in limited form since the spring, aimed at accounts it flags, and today's update writes the practice into the rules.

When Anthropic does ask, the request can include an image of your government ID and everything printed on it, your name, your date of birth, your ID number, plus a photo or video of your face and what the policy calls facial geometry templates. Anthropic concedes in its own words that this data may be considered biometric data in some jurisdictions.

. . .

The checks are run by Persona, a San Francisco identity firm. Your ID and your selfie sit on Persona's servers, not Anthropic's. That matters. In February, security researchers found Persona's government dashboard code sitting on a public endpoint, more than two thousand files exposed, and the code showed the platform can run two hundred and sixty-nine distinct verification checks, including screening a person against terrorism and espionage watchlists.

There is no stated retention period for the verification data in Anthropic's policy. Legal scholars are already flagging that gap under Illinois biometric law.

. . .

Anthropic did not want to be here. On June twelfth a federal export-control order forced it to block foreign nationals from its most capable models, and the company had no way to verify a user's nationality in real time at the scale it operates. Biometric identity was the mechanism it had inside the deadline.

That is the honest version, and it does not make the result smaller. To keep using one of the most widely used AI tools in the country, a person may now have to hand a private vendor their face.

For Everyone: If you use Claude on a consumer plan, understand what may be asked of you and where it goes. Your face and your ID would live on a third party's servers with no retention limit written down.

For Counsel: A no-stated-retention biometric collection is an Illinois biometric-law problem waiting for a plaintiff. The policy language conceding this may be biometric data is the admission a complaint will quote first.

For Legislators: The most-scrutinized AI lab in the country just wrote face scanning into its consumer terms, and it did so to comply with your export order. If you did not intend to push a lab toward biometrics by side effect, the law needs to say so.

For Founders: Identity gating built under regulatory duress is still identity gating your users will feel. Anthropic's users are learning what it costs. Watch the churn before you copy the pattern.

Why it matters: Hundreds of millions of people treat these chatbots as a private place to think. Today one of the companies behind them formally claimed the right to condition that access on the most permanent identifier a person has, their face, handed to an outside vendor with no promise about how long it is kept. Most users will not be asked. The precedent is the story. It is the clearest sign yet that the age of anonymous AI is ending, and it arrived not by debate but by a compliance deadline.

Source: TechCrunch, Anthropic says Claude may want to see your ID, https://techcrunch.com/2026/06/22/anthropic-says-claude-may-want-to-see-your-id/

Comment on this story →  ·  Forward this →

. . .

SAM ALTMAN'S NEW LIFE, CHAPTER THREE. A week ago Sam Altman floated handing the American public five percent of OpenAI. The idea has spent the days since turning into an argument, and this week it acquired a new character, a Treasury Department quietly worried that the whole AI boom might be a bubble.

The offer, first reported by the Financial Times on July 2, would place about five percent of OpenAI's equity, worth roughly forty-three billion dollars at the company's latest valuation, into a public wealth fund modeled on Alaska's oil-revenue fund. Divide it across the country and it comes to something like three hundred dollars a household. Altman has been making the case directly to President Trump, to Commerce Secretary Lutnick, and to Treasury Secretary Bessent. The talks, everyone stresses, are still conceptual.

. . .

Then the reviews came in. Bloomberg's opinion desk called the stake a Trojan horse, a way to buy political goodwill and a government partner rather than a genuine gift. And this week reporters surfaced an internal Treasury draft warning that the AI market carries real risk of repeating the dot-com bust, even as the administration talks the sector up in public. The company that wants to give the government a slice of itself is being valued, privately, by that same government's economists as a possible bubble.

. . .

Read Altman's summer as a single arc, which is how this column has come to read it. In Idaho he stood among the billionaires while the United Nations met without him. He wrote an op-ed asking for a global standards body with America at its head. Now he offers Washington a piece of the company itself. The pattern is consistent. When the ground shifts under the most powerful man in AI, he does not retreat. He offers to become the ground.

For Founders: Offering the government equity to ease political pressure is a new play, and if it works it becomes the template. Watch whether a stake buys OpenAI the regulatory calm it wants.

For Investors: A leaked Treasury bubble warning is a signal worth more than any earnings deck. The government funding the boom is privately modeling the bust.

For Legislators: A five percent public stake sounds like a gift and functions like a partnership. Before you welcome it, decide whether the government can regulate a company it co-owns.

For Everyone: The richest corners of the AI industry are proposing to make you a shareholder. Ask what they are buying with the offer before you decide whether it is generosity.

Why it matters: The most valuable company in AI is trying to fold the American government into its cap table at the exact moment that government's own analysts are warning the market could burst. It is the boldest move yet in a season full of them, and it tells you the people closest to the money are managing risk, not celebrating certainty.

Source: Bloomberg, Sam Altman's Idea to Gift the US a 5% OpenAI Stake Is a Trojan Horse, https://www.bloomberg.com/opinion/articles/2026-07-07/sam-altman-s-idea-to-gift-the-us-a-5-openai-stake-is-a-trojan-horse

Comment on this story →  ·  Forward this →

. . .

YOUR BRAIN ON THE MACHINE. Step back from the policy fights for a moment and ask the question none of them answer. What are these tools doing to the mind of the person using them. A column this week gathered the new research, and the finding has a name that should give any daily user pause. Cognitive surrender.

Writing in the Washington Post, Michael Coren pulled together a run of 2026 studies on how AI use changes thinking. The phrase cognitive surrender describes a specific failure, where a person stops checking the machine and simply adopts its judgment as their own. Not delegating a task. Handing over the reasoning itself.

. . .

The numbers are unkind. In one set of preregistered experiments with more than thirteen hundred people, researchers sometimes fed participants an AI that was programmed to be wrong. When it was wrong, people followed it about eighty percent of the time, performing worse than they would have with no AI at all. Worse still, using the AI made them more confident in their answers, including the wrong ones.

A separate study of several hundred people found that the heaviest AI users scored lowest on critical thinking, with the offloading of effort as the thread connecting the two.

. . .

Coren does not end in despair, and neither will this issue. The same research points to a way through. Treat the machine as a sparring partner, not an oracle. Make it argue against itself. Write your own answer before you ask for its.

Used that way, the studies suggest, AI can sharpen thinking rather than dull it. That is the whole difference, and it is a choice the user makes, one prompt at a time. The tool can build or it can erode. Which one depends on whether the human stays awake at the wheel.

For Clinicians: Cognitive surrender is a pattern worth naming with clients who lean on these tools. The risk is not just bad information. It is the quiet erosion of the habit of thinking for oneself.

For Educators: The finding that heavy AI use tracks with weaker critical thinking is the one to teach. Show students the sparring-partner method before the offloading habit sets.

For Founders: A product that makes users more confident while making them wrong is a liability dressed as engagement. Build the friction that keeps a person thinking, even if it costs you a little stickiness.

For Everyone: Write your answer first, then ask the machine. The research says the order is the difference between a tool that sharpens you and one that quietly takes over.

Why it matters: Every other story in this issue is about who controls the machines, the labs, the governments, the courts. This one is about what the machines are doing to us while we argue. The most powerful conversational AI in history is also the most persuasive, and the early evidence says it can talk us out of our own judgment. Using it well is not automatic. It is a discipline, and it is on us.

Source: The Washington Post, How to stop ChatGPT from ruining how you think, https://www.washingtonpost.com/technology/2026/07/07/how-stop-chatgpt-ruining-how-you-think/

Comment on this story →  ·  Forward this →

Disclosure

A note on conflict. Two of today's stories are about Anthropic, and the model that helps produce this newsletter is Anthropic's. We hold that coverage to the same standard we would apply to any company on this beat, and arguably a higher one, because the conflict is ours to name. The person who decides what ships, Jess Jessop, still signs it, with his own name everyday.

It was the kind of day that used to take a month. Chinese labs siphoning American models, Washington clearing the next one for sale, a governor signing the toughest AI law in the country, and a company reserving the right to ask you for your face.

That is a lot of power moving at once, and almost none of it is written in statute.

The machines are being copied, gated, audited, and offered up as public equity. The one thing no one is doing is slowing down. So keep your own judgment close, because the last story says the tool is very good at borrowing it. Someone has to stay accountable, and stay awake. It still cannot be the machine.

Today's Question

To use Claude, Anthropic can now demand your ID and a face scan. Worth it for safety?

Worth it for safety
No, that crosses a line
Depends who is asking
This is already everywhere

One tap. Results on the other side.

The Book • Out Now

Therapist in the Loop book cover: a therapist and a client in armchairs joined by a glowing loop of light

Therapist in the Loop

by Jess Jessop

One billion people live with a mental health disorder. Most will never see a therapist. Into that gap has rushed a generation of chatbots that talk like clinicians and answer to no one.

The book lays out the architecture this newsletter tests against every statute and docket: client, therapist, and machine, governed by Six Laws offered as an open safety standard.

The machine can help. It cannot be left in charge.

Get the Book on Amazon →

Kindle, hardcover, and paperback

More On Our Radar

China may limit access to its own most powerful models As Washington clears American frontier models for release, Chinese officials are weighing curbs on Alibaba and ByteDance's most capable systems, a mirror image of the US export fight. Source

The federal chatbot bills are still stalled The GUARD Act, the CHAT Act, and the Cruz-Schatz CHATBOT Act all sit in committee while states pass their own laws. Congress has advanced none of them to a floor vote. Source

The consumer bots already scan faces for age Character.AI runs Persona selfie checks to gate users under 18, and Meta uses AI profiling to infer age and apply teen limits. The identity wall Anthropic just built is already up on the companion apps. Source

US companies lean harder on cheaper Chinese models With American token prices rising, the share of US company usage running on Chinese open models has sat above 30 percent every week since February, the payoff distillation was built to deliver. Source

A ratings group splits school apps from consumer apps Common Sense Media rated the school-deployed tools Alongside and Sonar low or minimal risk, while the direct-to-consumer self-care app Wysa was rated unacceptable for teens. Source

Researchers press for rules over outright bans for teens As states move to ban companion chatbots for minors, clinicians and researchers argue in STAT that teens need guardrails and crisis routing, not blanket prohibitions they will evade. Source

Brush your brain. Every day.

Watch the 20-second video that started a movement

This Issue

Your verdict on the ID wall?

Kept me up
Sending to my rep
Wrong call
Run that back
I have notes

If you or someone you know is in crisis, call or text 988 (Suicide and Crisis Lifeline).

Jess Jessop is the Founder and CEO/CTO of Clinician Assist Inc. (BetterMind.Space), building the first voice-first AI-native mental health EHR with Casey Life and Peer AI Coach supervised by licensed therapists. A disabled veteran and 25-year AI/software engineering veteran, Jess brings lived experience as a mental health client to the mission of making daily mental health care as integrated as oral care.

ClinicianAssist.ai  |  BetterMind.Space  |  JessJessop.info

Subscribe  |  Archive  |  Unsubscribe