Blog Post
2026-09-14 18:49:05

Anthropic Says Chinese AI Labs Secretly Used Millions of Claude Exchanges to Train Rival Models

AI Labs have continued to invest, time and again, to ensure that its models withhold their intellectual capacities and are able to monitor and identify attempts to deduct its functioning and ideologies and many companies often invest extensive resources to prevent competitors from misusing its models.
Anthropic Says Chinese AI Labs Secretly Used Millions of Claude Exchanges to Train Rival Models

Anthropic over the past week, discovered and claimed something that it was expecting, but could not be totally preventive of. Originating from servers based in China, a claimed pattern of large-scale, deliberately disguised extraction, running into the hundreds of millions of exchanges, focused on estimating and reverse-engineering Claude's most valuable capabilities.

 

Table of Contents

 

1. What Anthropic Actually Claimed

2. The Scale, Lab by Lab

3. What "Distillation" Means, and Why It's Contested

4. The Most Serious Allegation: Silent Rerouting

5. China's Response

6. Why Anthropic Says This Matters Beyond Competition

7. Conclusion

 

What Anthropic Actually Claimed

 

On Thursday, September 10, Anthropic released a threat intelligence report that said it had detected large-scale, unauthorized campaigns from multiple China-based AI companies with attempt focusing on understanding Claude’s capabilities and using its responses to train their own competing models, a practise known within the AI World as “illicit distillation”. The report included such instances from December 2025 to August 2026 and reported names of reputed giants such as Alibaba, Moonshot AI, DeepSeek, Xiaomi, and Zhipu as the parties behind the activity, with a total estimated exchanges in Claude’s model in the 200 million region.

 

"Over the last several months, unauthorized labs have developed increasingly sophisticated methods to circumvent our defenses and harvest the capabilities of US frontier models," the report states, adding that the campaigns specifically targeted Claude’s finest capabilities in the form of agentic mechanisms, coding, data analysis, tool use, and its logical reasoning."

 

The Scale, Lab by Lab

 

The report had documented figures and timeframe for each company, while stating that Alibaba was responsible for conducting the single largest distillation operation that has ever been observed across its models.

 

Company

Reported Activity

Timeframe

Alibaba

151+ million exchanges; up to ~3 million/day; 3,500+ fraudulent accounts

May–July 2026

Moonshot AI (Kimi)

23+ million exchanges; ~300,000 requests silently routed to Claude in one 10-day span via 5,380 fraudulent accounts

May–July 2026

DeepSeek

12.1+ million exchanges; 150,000+ exchanges specifically targeting reasoning capabilities

July 2026 (14-day span)

MiniMax

Built a proxy service via a shell company to harvest exchanges with Claude and OpenAI models

Ongoing

Xiaomi, Zhipu

Named as participants in broader distillation activity

2026

 

Anthropic further stated that Alibaba used the harvested exchanges to help train its Qwen model family, and further used its exchanges to obtain details on AI research, including reinforcement learning and model architecture work.

 

What "Distillation" Means, and Why It's Contested

 

The process of Distillation, in the AI Development interface, focuses on training a smaller or less capable model using the mechanisms and responses from a more capable one, potentially allowing the new model to learn by studying the functioning of the older, stronger model and its approach towards resolving prompts. Within the AI Industry, this is a fairly common and widely used strategy, yet what makes Anthropic’s report serious is the lack of authorization from Anthropic for using its models, which violates Claude’s terms of service and makes the exchanges unethical, especially the use of multiple fraudulent accounts that were used as an attempt to bypass detection and regional access restrictions.

 

The Most Serious Allegation: Silent Rerouting

 

While the report claims multiple allegations, one specific allegations stands out for its severity as compared to any previous allegations: Anthropic claimed that multiple Chinese labs didn’t simply analyze and study Claude’s outputs, but they also rerouted their own paying customers' live requests to Claude in real time, without disclosure. Based on the report, Moonshot "silently forwarded customer requests to Claude, instead of processing them using Kimi," then displayed Claude's responses to users who believed they were interacting with a Kimi model. Claude claims that over 300,000 customers received responses routed through Claude’s Opus model while being under the impression that it was actually Moonshot’s Kimi model.

 

 

Anthropic also reported that based on an analysis of their exchanges, the exchange even included valuable sensitive information of individual users, multinational companies, and state-affiliated organizations, which in itself was a breach of privacy laws, as well as the labs own terms of service, while also murking its allegations with the risk of user consent, data handling and management from the labs part.

 

China's Response

 

Following Anthropic’s report release, Beijing was prompt to refuse the allegations that had been made. The Chinese Foreign Ministry Spokesperson Mao Ning, told reporters that China was committed to advocating AI for Good while also accusing Anthropic for distorting facts. He further added, "We firmly oppose attempts to throw mud at China by distorting facts.". Anthropic’s claims were further disputed by the Chinese Commerce Ministry that went a step ahead and emphasized on distillation being “a widely used and neutral training method,” and in turn also went on to claim that multiple US Companies had also distilled from Chinese models in the past. As on date, none of the five accused companies from Alibaba, Moonshot, DeepSeek, Zhipu, or Xiaomi have issued any formal response or statements with regards to the allegations and also denied comments on the allegations, according to multiple outlets that sought comment from each.

 

Why Anthropic Says This Matters Beyond Competition

 

Anthropic’s report and its accusations extend far beyond normal and acceptable commercial activity. Anthropic has also time and again reiterated that while distillation might help companies match the quality output from the model, they wouldn’t replicate its safety safeguards which would enhance the risk of misuse, and possibly lead to malicious use including applications tied to military, intelligence, or mass surveillance use cases such as offensive cyber operations or disinformation campaigns. Anthropic has used these findings to argue for tighter industry and policy responses, including suggesting stricter limits on advanced chip access as one way to constrain the scale of future distillation efforts. Additionally, it has also shut down accounts tied to the campaign, strengthened its detection systems to identify capability-extraction attempts while also having added extra identity verification requirements for accounts that originate from regions where Claude isn’t officially directly available.

 

Conclusion

 

Take a moment to leave the geopolitics involved in the accusations, and what we are still left with is a genuine novel and technical dispute, An AI System’s output being wrongfully without authorization used for training its competitors, in a volume of hundreds of millions of exchanges. And sometimes, even misguiding the competitors' own customers, as to where the answer they’re receiving is actually originating from. Anthropic has built its report and claims on very specific and detailed figures, and Beijing has rejected it with the notion of using normal industry practices instead of any specific misconduct. As of yet, neither party’s accusation and defense has been put to trial, and the consequences from this dispute is sure to become a benchmark that will shape AI labs rivalry as well US-China AI policy in the foreseeable future.