Anthropic identifies large-scale distillation attacks by Chinese AI companies to train models using Claude outputs
Anthropic released a threat intelligence report on Thursday identifying large-scale, unauthorized distillation attacks by Chinese AI companies. The report states that labs such as Alibaba, Moonshot, and DeepSeek used outputs from Anthropic's Claude model to train their own models without authorization. Alibaba conducted the largest distillation campaign observed by Anthropic, involving over 151 million exchanges between May and July 2026. These exchanges were spread across more than 3,500 accounts and were used to produce training material for Alibaba's Qwen models. Moonshot AI also utilized Claude to train its Kimi models. The report notes that Moonshot forwarded nearly 300,000 customer requests to Claude in a 10-day period, often without notifying the users. DeepSeek also performed similar tactics, with Anthropic observing more than 12 million distillation attacks from DeepSeek in July 2026. Anthropic noted that these practices may be inconsistent with privacy laws and the company's terms of service. Beijing rejected the allegations, describing the actions as a move by Washington to suppress China's AI industry.
Sources
-
Anthropic claims Moonshot, DeepSeek secretly diverted user requests to Claude
South China Morning Post
-
Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says
CNBC
-
Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek
TechCrunch