AI News Feed
Market watch
World

Anthropic says Chinese AI labs used Claude in 'illicit distillation' to train models

Anthropic says it disrupted unauthorized Claude use by Alibaba, Moonshot and DeepSeek to train AI models, with Alibaba the largest.

Anthropic said the Alibaba operation was the largest distillation campaign it has measured. Operators affiliated with Alibaba used Claude outputs to help train its Qwen models, and the campaign involved more than 151 million exchanges with Claude between May and July. At its peak, the activity reached nearly 3 million exchanges per day from more than 3,500 fraudulent accounts. Anthropic also said Alibaba used Claude for broader AI research, including reinforcement learning and model architecture.

The report also detailed activity involving Moonshot AI, the Beijing-based company behind the Kimi family of AI models. Anthropic said Moonshot routed some Kimi user requests to Claude and then displayed Claude's responses to users who thought they were using a Kimi model. In one 10-day period, Moonshot relayed nearly 300,000 customer requests to Anthropic, the vast majority of which were routed to Claude Opus models. The requests went through a network of 5,380 accounts Anthropic described as fraudulent, most of which appeared to be located in Singapore and Japan.

Anthropic said Moonshot saved at least some of those exchanges and extracted Claude's reasoning transcripts to use as training data for its own models. More than 23 million exchanges were attributed to Moonshot between May and July, according to the report. Some of the customer requests routed to Claude contained sensitive information, and Anthropic said it did not know whether Moonshot had notified customers that their requests were being sent to Anthropic.

DeepSeek, which rose into prominence last year due to its capabilities and cheap costs, also used tactics similar to Moonshot, according to Anthropic. The report said DeepSeek transferred exchanges to Claude without notifying DeepSeek customers. Anthropic said it observed more than 12 million distillation attacks attributable to DeepSeek over 14 days in July 2026.

The report said some of the exchanges involved in the broader distillation activity included sensitive information from individual users, major multinational companies and state-affiliated actors. Anthropic said the practices were likely inconsistent with privacy laws and the labs' own terms of service.

Anthropic said the report named several other major Chinese AI companies and covered activity it disrupted between December 2025 and August 2026 across seven areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation.

CNBC said Alibaba, Moonshot, DeepSeek, Xiaomi and Anthropic did not immediately respond to its requests for comment.