Anthropic Disrupts Chinese AI Labs' Unauthorized Model Training
Alibaba, Moonshot, and DeepSeek allegedly used Claude outputs to train competing models without permission, exposing user data in the process.
Anthropic exposes large-scale unauthorized AI training operations
Anthropic has detected and shut down what it describes as unauthorized large-scale efforts by multiple China-based AI laboratories to train their models using outputs from Claude, the company's flagship AI assistant. The U.S. AI firm detailed the operations in a threat intelligence report released Thursday, naming Alibaba, Moonshot, and DeepSeek among the companies involved.
The practice, which Anthropic calls "illicit distillation," involves using outputs from a more capable AI model to train another model and replicate its capabilities without authorization. According to the report, some exchanges included sensitive information from individual users, multinational companies, and state-affiliated actors.
Alibaba operation involved 151 million exchanges
The largest campaign Anthropic measured involved operators affiliated with Alibaba, who used Claude outputs to help train the company's Qwen models. Between May and July, the operation generated more than 151 million exchanges with Claude, peaking at nearly 3 million exchanges per day from over 3,500 fraudulent accounts, according to the company's findings.
Anthropic reported that Alibaba also leveraged Claude for broader AI research purposes, including reinforcement learning and model architecture development.
Moonshot routed customer requests to Claude without disclosure
Moonshot AI, the Beijing-based company behind the Kimi family of AI models, allegedly forwarded customer requests intended for Kimi directly to Claude, then displayed Claude's responses to users who believed they were interacting with a Kimi model.
During one 10-day period, Moonshot relayed nearly 300,000 customer requests to Anthropic through a network of 5,380 accounts the company identified as fraudulent, most appearing to originate from Singapore and Japan. The report indicates Moonshot saved at least some exchanges and extracted Claude's reasoning transcripts for use as training data. More than 23 million exchanges were attributed to Moonshot between May and July.
Anthropic stated it does not know whether Moonshot notified customers that their requests were being sent to a third party.
DeepSeek employed similar tactics
DeepSeek, which gained prominence for its capabilities and low costs, also used tactics similar to Moonshot by transferring exchanges to Claude without notifying DeepSeek customers. Anthropic observed more than 12 million distillation attacks attributable to DeepSeek over 14 days in July 2026.
Why it matters
This disclosure highlights a significant vulnerability in the AI ecosystem: leading models can be systematically exploited to train competitors, potentially violating privacy laws and terms of service. For enterprises using AI services, the incident raises questions about data security when interacting with AI platforms, particularly those that may be routing requests through third-party systems without disclosure. The scale of the operations—hundreds of millions of exchanges—suggests this was not isolated experimentation but systematic competitive intelligence gathering.
The report covers activity Anthropic said it disrupted between December 2025 and August 2026 across seven threat areas, including cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Alibaba, Moonshot, DeepSeek, and Anthropic did not immediately respond to requests for comment.
These details were first reported by CNBC.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
