Anthropic discovered Chinese AI laboratories conducting a large-scale ‘unauthorized distillation’ operation.

Anthropic discovered Chinese AI laboratories conducting a large-scale 'unauthorized distillation' operation.

Anthropic has reported that it intercepted significant unauthorized attempts by various Chinese AI companies, including Alibaba, Moonshot, and DeepSeek, to exploit its Claude model in order to train their own AI systems. This incident marks one of the largest known “illicit distillation” efforts aimed at appropriating Anthropic’s more sophisticated technology.

On Thursday, Anthropic explained that this practice involves utilizing a less advanced AI model, trained on the outputs of a superior system, to replicate its functionalities without permission.

A particularly notable event occurred over a span of ten days this year, during which Moonshot, based in Beijing, redirected 300,000 customer queries to Claude and subsequently presented those answers to its users without disclosure.

According to reports, Moonshot utilized around 5,380 fake accounts located in Singapore and Japan to collect and store this data for training purposes.

This incident is part of a worrying trend where lower-performing Chinese AI firms are attempting to copy more advanced American AI technologies, which is increasingly concerning for US AI leaders who are striving to develop the most sophisticated systems.

Anthropic’s CEO, Dario Amodei, has characterized Alibaba’s actions as the most extensive distillation operation the company has encountered, involving over 151 million interactions with Claude from May to July. Those associated with Alibaba reportedly leveraged responses generated by Claude to enhance their Qwen models.

“Some of these exchanges contained sensitive information from individual users, major multinational corporations, and state-affiliated entities,” Anthropic noted in a threat intelligence summary. “Such practices likely violate privacy regulations and the labs’ own service agreements.”

Anthropic highlighted that the levels of activity rose to nearly 3 million exchanges daily and involved around 3,500 fraudulent accounts. Additionally, Alibaba also utilized Claude for more extensive AI research, including the refinement of its model architecture.

During the Moonshot incident, over 23 million exchanges were attributed to them between May and July. Some prompts sent to Claude from customers included sensitive data, yet Anthropic admitted it was unsure if Moonshot informed its clients that their requests were being relayed to its systems.

DeepSeek, another Chinese AI firm that gained prominence last year with cost-effective models, allegedly employed similar strategies to those of Moonshot, according to Anthropic. They too forwarded exchanges to Claude without notifying users, and Anthropic identified over 12 million distillation attempts from DeepSeek within a two-week period in July.

The report highlighted other significant Chinese AI firms accused of similar attacks that Anthropic said it had seemingly disrupted between December 2025 and August 2026, encompassing cyber operations, surveillance, scams, and more. Notably, Alibaba, Moonshot, DeepSeek, and Xiaomi did not respond to inquiries from The Post regarding these allegations.

Facebook
Twitter
LinkedIn
Reddit
Telegram
WhatsApp

Related News