Anthropic says Chinese AI labs used millions of Claude exchanges to train rival models

Anthropic says Chinese AI labs used millions of Claude exchanges to train rival models

Anthropic says it detected unauthorized “illicit distillation” of its Claude models by Chinese AI labs between December 2025 and August 2026. The company alleges the activity used Claude outputs and, in some cases, sensitive user information to train other AI systems.

What Anthropic calls “illicit distillation”

Anthropic described the practice as using outputs from a more capable AI model to train another model and reproduce some capabilities without authorization. It said some exchanges included sensitive information from individual users, major multinational companies, and state-affiliated actors, which it said likely conflicts with privacy laws and the labs’ terms of service.

Alibaba: largest campaign tied to Qwen training

Anthropic said operators affiliated with Alibaba used Claude outputs to help train its Qwen models. It also said Alibaba routed some Claude exchanges through broader AI research, including reinforcement learning and model architecture.

The company described Alibaba as the largest distillation campaign it has measured, involving more than 151 million exchanges with Claude between May and July. It said the activity peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts.

Moonshot and Kimi: customer requests allegedly forwarded to Claude

Anthropic said Moonshot, the Beijing-based company behind the Kimi model family, silently forwarded some customer requests intended for Kimi to Claude and then displayed Claude responses to users. It said some of the resulting exchanges were saved and used as training data, including extracted Claude reasoning transcripts.

In a 10-day period, Anthropic said Moonshot relayed nearly 300,000 customer requests to Claude Opus models. Anthropic attributed more than 23 million exchanges to Moonshot between May and July, describing routing through a network of 5,380 accounts it characterized as fraudulent, mostly located in Singapore and Japan. Anthropic said it did not know whether Moonshot notified customers that their requests were being sent to Anthropic.

DeepSeek: similar tactics, Anthropic says

Anthropic said DeepSeek used tactics similar to Moonshot, transferring exchanges to Claude without notifying DeepSeek customers. It reported observing more than 12 million distillation attacks attributable to DeepSeek over 14 days in July 2026.

Why this matters

Anthropic’s findings point to a broader pattern of large-scale model extraction using third-party model outputs, sometimes involving sensitive information. The reported volume and account networks described in the threat intelligence report suggest the practice can be operationalized at scale, raising legal and compliance risks for the companies involved.