Industry News Details
Anthropic Accuses Alibaba, Moonshot AI and DeepSeek of Distilling Claude Posted on : Sep 11 - 2026
Anthropic has reported a series of increasingly sophisticated AI distillation attacks by China-based AI companies, saying the campaigns have intensified in recent months as competition in the AI industry grows.
According to Anthropic, unauthorized AI labs have developed new techniques to bypass its safeguards and extract capabilities from U.S. frontier models. The campaigns targeted some of Claude’s most valuable abilities, including agentic workflows and tool use, coding, data analysis, and logical reasoning.
Anthropic identified nearly 200 million exchanges across five separate campaigns, describing the activity as significantly larger and more aggressive than the distillation attempts it previously reported. OpenAI has also raised concerns about similar activity, including efforts it attributed specifically to DeepSeek.
AI distillation involves using the outputs of a more capable model to train another, often smaller, model. Attackers can send large numbers of carefully designed queries to extract useful reasoning patterns and other capabilities, which can then be incorporated into the development of competing models.
Anthropic says its models generally do not expose their full internal chain of thought to users. Instead, Claude provides summarized thinking. However, researchers found that attackers developed techniques to persuade the model to reveal more detailed reasoning traces. In one example, an attacker disguised the request as a translation task, asking Claude to translate its previous working memory into Japanese katakana.
The largest campaign was attributed to Alibaba. Anthropic said it observed approximately 151 million exchanges between May and July 2026, peaking at nearly 3 million exchanges per day. The activity involved around 3,500 accounts and used a common prompt designed to extract Claude's reasoning. Anthropic believes the effort was aimed at generating training data for Alibaba's Qwen family of models.
A separate campaign was attributed to Moonshot AI, the company behind Kimi. Anthropic said the activity appeared to involve requests connected to the Chinese military. In one example, Claude was asked to analyze surveillance footage and determine whether a person was behaving abnormally. Over a 10-day period, nearly 300,000 requests were reportedly routed through about 5,000 accounts, with most targeting Claude's Opus model.
Anthropic's findings highlight a growing concern in the AI industry: as frontier models become increasingly capable, competitors may attempt to reproduce those capabilities through large-scale extraction of model outputs rather than developing them entirely from scratch.