Tekedia Capital LLC

09/12/2026 | Press release | Distributed by Public on 09/12/2026 07:47

Anthropic Says Chinese AI Labs Launched 190 Million Claude Distillation Attacks

Anthropic has accused several leading Chinese artificial intelligence companies of carrying out a large-scale campaign to extract knowledge from Claude, saying Alibaba, Moonshot AI, DeepSeek, Zhipu and Xiaomi collectively launched nearly 190 million distillation attacks against its models between May and July.

The allegations, disclosed in a report published Thursday, offer a detailed look at the increasingly competitive and adversarial race among AI developers to improve model capabilities. Anthropic said the activity involved companies using Claude's responses to train or enhance their own AI systems rather than relying solely on internally generated data.

AI model distillation is a technique in which developers use the outputs of a more capable model to improve a smaller or less advanced system. The practice itself is widely used across the industry, but Anthropic is alleging that the scale and methods employed by the Chinese companies crossed into abusive or unauthorized use of Claude.

Anthropic said Alibaba was responsible for the largest campaign it had detected. More than 3,500 fraudulent accounts allegedly generated over 151 million exchanges with Claude between May and July. According to Anthropic, the accounts were designed to make Claude produce detailed reasoning processes that could subsequently be used to train Alibaba's Qwen models.

The scale of the alleged activity dwarfed earlier incidents disclosed by Anthropic. In June, the company's head of policy, Sarah Heck, told US lawmakers that Alibaba had conducted 28.8 million exchanges with Claude between April 22 and June 5 and urged policymakers to address what she described as illicit distillation.

The latest allegations suggest the practice expanded considerably over the following weeks.

Anthropic said Moonshot AI and DeepSeek also used Claude as an intermediary for requests that were ostensibly intended for their own models. It identified 23 million such rerouted requests from Moonshot between May and July, while DeepSeek allegedly rerouted 12.1 million requests over a 14-day period in July.

The company said these arrangements allowed the Chinese AI firms to gather large quantities of responses from Claude without directly exposing their own models to the same workload.

Anthropic alleges sensitive government data was exposed

The dispute goes beyond competition over model performance because Anthropic said some of the rerouted requests contained sensitive information.

According to the report, requests that users believed were being processed by Chinese AI systems were instead sent to Claude. Anthropic said some of those interactions contained data linked to Chinese and Russian government and military activities.

One example involved CCTV footage uploaded by a user of PLA-affiliated Kimi, while another involved information concerning a Russian government database submitted by a Russian military contractor.

The allegations raise a separate concern about the unintended movement of sensitive information across AI systems. Users may believe they are interacting with a particular model or provider, while routing mechanisms designed to obtain stronger responses can send their data elsewhere.

Anthropic also accused Z.ai, which recently attracted attention with its Ox Alpha model, of conducting an attack similar to the campaign it attributed to Alibaba.

In Xiaomi's case, Anthropic said the company recorded user conversations with its MiMo models and subsequently fed those conversations into Claude to generate training data.

The accusations come as Chinese AI developers have rapidly expanded their presence in the global AI market, intensifying competition with US model developers. Distillation has become an important part of that competitive dynamic because access to a stronger frontier model can potentially shorten the time and cost required to improve a rival system.

For Anthropic, the scale of the alleged activity also highlights a weakness inherent in offering highly capable models through widely accessible interfaces. The same capabilities that make Claude commercially valuable can potentially make it a source of training data for competitors.

Anthropic said it has begun tightening its defenses. The company has introduced additional safeguards intended to identify and block suspicious activity and has reduced the amount of detailed reasoning Claude provides, making its reasoning transcripts less useful as training material for other models.

It will also require users to verify their identities if they appear to be operating from China, Russia or Iran, countries where Claude is not officially available. The measures are revealing how competition between frontier AI companies is increasingly extending beyond model benchmarks, pricing and computing capacity. Control over access to model outputs is becoming an important part of the competitive battlefield.

Like this:

Like Loading...
Tekedia Capital LLC published this content on September 12, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 12, 2026 at 13:48 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]