Anthropic accuses multiple Chinese AI companies of large-scale distillation. Alibaba, Dark Side of the Moon and DeepSeek are accused of tens of millions of interactions

📅 2026-09-11

Abstract:

Anthropic, an American artificial intelligence company, recently released a threat intelligence report, accusing institutions including Alibaba, Moonshot AI, DeepSeek, Xiaomi and several other Chinese AI laboratories of extracting their model capabilities through large-scale calls to Claude and using the generated results to train and improve their own artificial intelligence models. Anthropic calls this behavior an unauthorized "distillation attack."

85b45f07f9e00f3c3172f3e3a69b632e.jpg

The so-called model distillation refers to using a model with stronger capabilities and larger scale to generate a large number of answers, and then using these outputs as training data to train models with lower cost, smaller scale, or weaker capabilities. For AI companies, this is a technical route that can reduce training costs and quickly improve model capabilities. However, Anthropic believes that some of the behaviors discovered this time have gone beyond the scope of normal model distillation and belong to the organized and large-scale extraction of their business model capabilities.

Anthropic said that between May and July 2026, operations related to Alibaba generated more than 151 million interactions with Claude, making it the largest illegal distillation operation the company has discovered to date. The relevant operations used more than 3,500 accounts that Anthropic identified as fraudulent, and the highest number of interactions per day was nearly 3 million.

Anthropic believes that these accounts are mainly used to continuously ask Claude a large number of questions and obtain the model's answers and more detailed reasoning processes, and then use this information to improve Alibaba's Tongyi Qianwen series of models.

For model developers, the inference process is especially valuable. Compared with only obtaining the final answer, detailed inference records can show the trainer how the model analyzed the problem, how to decompose the task and how to reach the final conclusion, and therefore can become important data for training advanced inference models.

5949f5ae5197c4dc775d2f06d918999b.png

Anthropic also named Dark Side of the Moon AI, the developer of Kimi. The report stated that between May and July 2026, Dark Side of the Moon-related accounts had more than 23 million interactions with Claude.

What is more noteworthy is that Anthropic accused Dark Side of the Moon of not only using Claude for model distillation, but also forwarding real requests from Kimi users to Claude for processing.

Anthropic stated that during one of the 10-day periods, Dark Side of the Moon transferred nearly 300,000 user requests originally submitted to Kimi to Claude through an account network consisting of 5,380 accounts, with most of the requests being sent to the Claude Opus series of models. Anthropic believes that these accounts are mostly located in Singapore and Japan and are used to hide the actual source of requests.

This means that in some cases, Kimi users think they are interacting with Dark Side of the Moon's own model, but in fact the request may be forwarded to Anthropic's Claude for processing. Anthropic also said that Dark Side of the Moon saved some of the interactive content and extracted Claude’s reasoning records as training data.

Even more worryingly, these forwarded requests are not necessarily just ordinary chat content. Anthropic said some of the requests contained sensitive information, and users may not be aware that their data was actually being sent to another AI company's model.

f91b5d29494b4f3d17897c0465579de8.jpg

The report cites a case related to Kimi. One user asked Kimi to analyze a large number of surveillance camera footage from Chengdu, China, to determine a person's behavior. According to Anthropic, the video data was eventually transferred to Claude for processing, and users originally believed that the data was analyzed within Kimi.

Anthropic also discovered that some content submitted to Kimi by some users involved sensitive information such as corporate login credentials. In one case, an engineer submitted login credentials from multiple companies to Kimi in order to use Kimi to help a Chinese company develop software, and the relevant information was subsequently transferred to Claude.

Anthropic stated that users do not clearly know that their requests will be forwarded to Anthropic's model, so in addition to involving model distillation issues, this approach may also create serious privacy and data security risks.

DeepSeek was also accused by Anthropic of adopting a similar approach. The report states that DeepSeek was found to have conducted more than 12 million Claude-related distillation interactions during a 14-day period in July 2026.

Anthropic believes that DeepSeek also forwarded real requests from users to Claude, and some of the content in these requests contained sensitive information. Claude's answers were then used to train and improve DeepSeek's own models.

In addition to Alibaba, Dark Side of the Moon and DeepSeek, Anthropic also named Chinese AI companies such as Zhipu and Xiaomi. According to the report, Xiaomi recorded chats between users and its MiMo model and handed these conversations to Claude to generate data for model training.

Anthropic stated that during the time frame covered by its report, a total of seven Chinese AI laboratories were found to have implemented model distillation activities targeting Claude. Not all related activities use exactly the same method, but the common feature is that they try to obtain a large amount of Claude's output, learn its model capabilities, and use this information for the training of their own AI systems.

Anthropic believes that these activities have become increasingly organized and large-scale. Unlike ordinary developers who occasionally call other AI models for testing, these operations use a large number of accounts, agents, and intermediate platforms to hide their true identities and continuously generate model interactions at an industrial scale.

dd9e04472e39d531b91dc1c42fa0cad6.jpg

Among them, Alibaba-related activities have attracted particular attention. More than 151 million interactions meant that the operation was not a simple experimental test, but a large-scale data acquisition operation that lasted for several months. Anthropic believes that these data are mainly used to help train and improve Alibaba’s Tongyi Qianwen model.

For Dark Side of the Moon and DeepSeek, the problem is more complicated, because Anthropic accuses them of not only obtaining training data from Claude, but also forwarding their own user requests to competing models. This means that content submitted by users to one AI company may enter the system of another AI company without explicit notification.

Anthropic said it has taken steps to stop these activities, including banning relevant accounts, tightening identity verification, and further limiting Claude's ability to output detailed reasoning. Since detailed inference records are highly valuable for model distillation, reducing the output of this content can reduce the efficiency of competitors replicating Claude's capabilities through a large number of automated requests.

Anthropic also stated that the company will strengthen identity verification measures for users from countries or regions where Claude currently does not provide official services, such as China, Russia, and Iran, but who are suspected of trying to bypass restrictions and access Claude.

28d3b33c4fc787d733f087fd8ef8efe8.jpg8707bed652c494aab56984bea46dd9e8.jpg4c47000037ad171df342392102579798.jpgcc63593d60bee286809b4685c3eb858f.jpg

This report is not the first time Anthropic has publicly accused Chinese AI companies of model distillation. In June of this year, Anthropic policy director Sarah Heck wrote to U.S. Congressmen, stating that Alibaba had approximately 28.8 million interactions with Claude between April 22 and June 5, and believed that these interactions were used for unauthorized model distillation.

This latest report shows that Anthropic believes that the scale of related activities will further expand in the future. Alibaba alone had more than 151 million interactions between May and July, far higher than previously disclosed figures.

At the same time, this incident occurred against the background of increasingly fierce AI competition between China and the United States. In recent years, Chinese AI companies have rapidly improved their model capabilities with relatively low training and inference costs. Products such as DeepSeek, Kimi, and Tongyi Qianwen have become important players in the global AI industry. American AI companies have advanced basic models including Claude and GPT series.

4e6306117e36bb70e6d4a37a38b66fce.jpg

Model distillation itself is not an illegal or unreasonable technique. AI developers can use the data generated by the teacher model to train their own models with authorization. However, Anthropic believes that the operation involved poses a serious problem because the relevant companies are accused of systematically obtaining Claude's capabilities without Anthropic's authorization through a large number of fake accounts, agency platforms, and hidden data forwarding mechanisms.

More importantly, Anthropic believes that some actions have touched upon user data security issues. For users who normally use AI services, they usually think that the data they submit to platforms such as Kimi and DeepSeek will be processed in accordance with the privacy policies of these platforms. If the platform actually forwards these requests to a third-party model, users may not know that their data has entered another company's system.

d3b954205872a70115454046845c4f45.jpg

5dd32c210036575dc7c13849d00d5e94.jpg

040ab041c9ba0953d89dfae422eb8039.jpg

040ab041c9ba0953d89dfae422eb8039.jpg

As of the time of the report, Alibaba, Dark Side of the Moon, DeepSeek, Xiaomi and Anthropic did not immediately respond to requests for comment. The Chinese Ministry of Foreign Affairs stated that it was not aware of the report released by Anthropic, and reiterated that the Chinese government believes that artificial intelligence should be used to benefit mankind, and is opposed to distorting facts and smearing China.

1329f51b35456fa2a3c2866826ead451.jpg

efac400f942f00f62ef8acb28178b3bf.jpg

The incident disclosed by Anthropic has also resurfaced the long-standing model distillation controversy in the AI ​​industry. For companies with advanced basic models, how to prevent competitors from acquiring model capabilities through automation and large-scale calls has become an important issue in the business and security fields. For AI application companies, how to handle user data and whether users should be clearly informed that requests are being forwarded to third-party models may also become the focus of future regulatory attention.

From an industry competition perspective, the figures released by Anthropic are particularly noteworthy. More than 151 million Alibaba-related interactions, more than 23 million Dark Side of the Moon-related interactions, and more than 12 million DeepSeek-related interactions show that the competition between advanced AI models is no longer just about algorithms and chips in the traditional sense, but is extending to areas such as training data, model capability acquisition, and model distillation.

As the capability gap between various AI models continues to narrow, how to draw a clear line between the legal use of public technology, normal model distillation, and unauthorized large-scale capability duplication will become an increasingly difficult problem that the global AI industry must face in the future.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet