My guess is that when you sign up for either Anthropic or OpenAI, the terms of use specify you can't use their model for purpose A, B, C, D. For example, you can't use their model to try to build biological weapons, or to try to extort people, etc. Most likely there is language there that you can't use their models to train other models. It's as simple as that. You agree to those terms of use, or you don't use their models.
How can we prove intent? I’m sure a clever actor can disguise their prompt and simply claim the LLM suggested such and such on its own.
It’s not like Anthropic or OpenAI have the faintest idea how their models actually work.