> I think it is a reasonable term to use in the context of adversarial AI development
Distillation is neither an 'attack', nor 'adversarial' in any reasonable sense.
> Does that mean I am getting paid by the CIA or something
It at the very least means you're uncritically parroting the framing of a company that'd like nothing more than to successfully persuade lawmakers that something should be done about open Chinese models (eliminate choice), preferably so that Anthropic is close to anyone's only option.
It seems like a reasonable person could say that a model being distilled "against the model provider's wishes" is in some sense a cyber attack that is stealing information (eg the lower order bits of the model weights)
I think this is mostly a confusing way to describe it, but I'm not really sure why you say it isn't an attack or adversarial. One side is doing something the other side doesn't want. Seems to be pretty clearly adversarial.