Anthropic accuses Chinese AI firms of secretly using Claude to train models
U.S. artificial intelligence company Anthropic has accused Chinese AI developers of “engaging in aggressive, malicious,...

U.S. artificial intelligence company Anthropic has accused Chinese AI developers of “engaging in aggressive, malicious, and targeted distillation activities,” and stealing from U.S. AI models.
A September report from Anthropic stated that for two years, companies such as “DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok.”
It also stated that the Chinese government was “likely aware of it.” However, a report in the South China Morning Post(SCMP) has expressed skepticism regarding the claims.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has described it as a “systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership.”
According to Anthropic’s report, Moonshot AI secretly forwards requests to Claude, not Kimi, though users believed it was Kimi. “Over a ten-day period, we’re talking 300,000 customer requests. They used a proxy service network of 5,380 fraudulent accounts in Singapore and Japan,” read an excerpt from the report.
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) issued a joint advisory to warn US firms about the alleged activities. They called out Chinese AI companies for conducting shady dealings on an industrial scale, using robust operations to steal capabilities from American AI systems.
Chinese AI accused of industrial-scale distillation
The government advisory named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as companies involved in large-scale model distillation campaigns since at least late 2024.
Distillation is a technique in which developers use a more advanced AI model’s outputs to train another system.
Anthropic acknowledged that distillation is a “legitimate training method,” but also highlighted that there is a difference between transparent research using capable “teacher” models and conducting “a covert campaign,” without authorization.
“We define illicit distillation as an industrial-scale, covert campaign to extract a model’s capabilities and replicate them in another model without authorization,” Anthropic clarified.
They believe that Chinese developers used third-party aggregators, cloud providers, and proxy services known as “transfer stations” to circumvent restrictions on American AI systems.
Anthropic’s most specific allegations were directed at Moonshot AI, the developer of the Kimi chatbot. Alibaba also appeared to have engaged in more than 151 million distillation activities between May and July 2026.
However, these claims have faced skepticism. Wang Zebin, an investment manager at Shenzhen-based JG Investment, questioned whether Anthropic provided sufficient evidence to independently verify its allegations.
The report “does not provide enough concrete examples to independently verify how those companies obtained or used the model outputs,” Wang told SCMP.
Allegations raise concerns over sensitive Chinese data
Chinese regulators have reportedly questioned domestic AI developers following Anthropic’s allegations. According to SCMP, the Cyberspace Administration of China questioned seven developers before narrowing its attention to DeepSeek and Moonshot.
Moonshot and DeepSeek did not respond to SCMP’s requests for comment.
Meanwhile, the NSA, FBI, and CISA have urged American AI companies to strengthen detection systems, introduce targeted countermeasures, and share intelligence about suspected distillation campaigns.
Anthropic said it had disrupted identified misuse operations and strengthened its safeguards against unauthorized extraction of Claude’s capabilities.
The allegations remain contested, with questions about attribution and the involvement of third-party intermediaries unresolved.
Related articles

Jefferies warns AI boom could end in ‘massive capital destruction’ as Oracle and Nvidia default-protection costs hit records
Jefferies strategist Chris Wood says cheaper Chinese open-source models are likely to take market share and leave the US AI sector with massive capital destruction, as credit default swaps on Oracle, Nvidia and Broadcom climb to record levels.

Google’s AMIE medical AI passes first real-patient safety test in study published in The Lancet
In a Google and Beth Israel Deaconess Medical Center study, 98 patients chatted with the AMIE chatbot before urgent primary-care visits. No conversation needed a safety stop, and AMIE’s differential diagnoses matched doctors’ final diagnoses 90% of the time.

OpenAI says a model in training forged files and tried to wreck its own environment to force a reset
In misalignment reports updated October 9, OpenAI describes an internal grading model that, finding its input files missing, fabricated identical scores and fake files, then tried to delete parts of its environment hoping for a fresh one. None of its grades was accepted.

OpenAI and Anthropic executives are gaming out the ‘day after’ a major AI incident, Axios reports
Executives at leading AI labs are privately rehearsing how to respond to public and political backlash after a catastrophic AI event, most likely a cyberattack that disrupts finance, internet access, power or water, according to Axios.

Nvidia in talks to buy or deepen its stake in open-model startup Reflection AI
Nvidia, already an $800 million investor in Reflection AI, is weighing a full acquisition, an acqui-hire with technology licensing, or a larger equity stake, the Financial Times reported. Talks are at an early stage and could still fall apart.

Satya Nadella says we should assume all AI models are ‘compromised’
In a lengthy post on X, Microsoft's CEO laid out his views on the dangers posed by highly advanced AI models and how to confront those risks.