Anthropic names seven Chinese AI companies in report alleging unauthorized model distillation

Anthropic names seven Chinese AI companies in report alleging unauthorized model distillation

N
News Editor
2026-09-11 09:25:03
Anthropic has named Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax in a threat intelligence report released on Sept. 10, alleging unauthorized model distillation tied to Claude. The company said the largest activity it observed involved more than 151 million interactions attributable to Alibaba between May and July this year, which it said were used to extract Claude’s reasoning capabilities. Anthropic also alleged that Moonshot AI and DeepSeek routed some user prompts to Claude and then returned Claude’s answers to users, while other companies were accused of using user conversations to generate training data. The report covers AI abuse that Anthropic said it detected and disrupted between December 2025 and August 2026, spanning cyberattacks, surveillance, influence operations, fraud, biological misuse, conventional weapons development and distillation. As of Sept. 11, 2026, the source article said no verifiable formal response from the seven named companies had been found. Public debate around distillation had already been underway before the September report, including a July 24 open letter released by Microsoft and signed by companies such as Hugging Face, Meta, Mistral and Nvidia, and comments cited by TechCrunch from researchers discussing the technical and regulatory boundaries of distillation.

Anthropic has again placed Chinese AI companies in a threat intelligence report, this time naming seven firms over alleged unauthorized model distillation.

In a report released on Sept. 10, the Claude developer named Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax, alleging that they engaged in unauthorized efforts to distill capabilities from Claude.

The biggest case described in the report involved Alibaba. Anthropic said it observed more than 151 million interactions attributable to Alibaba between May and July this year, and said those interactions were used to extract Claude’s reasoning capabilities.

Another set of allegations centered on user traffic. Anthropic said Moonshot AI and DeepSeek routed some user requests to Claude and then returned Claude’s responses to users. It also accused other companies of using user conversations to generate training data.

Those claims are Anthropic’s published investigative findings.

What the report covers

The report spans AI abuse that Anthropic said it detected and blocked between December 2025 and August 2026. It lists seven categories: cyberattacks, surveillance, influence operations, fraud, biological misuse, conventional weapons development and distillation.

One of the report’s main observations is that attackers are increasingly using AI to directly execute and coordinate tasks. Anthropic gave examples such as automatically advancing network intrusions and operating large numbers of fake dating accounts.

The section directly tied to Chinese AI models is the final chapter on distillation. The source article noted that Anthropic’s figures were gathered across different observation windows, which means they cannot be treated as a same-period ranking of usage volumes.

How Anthropic defines “illicit distillation”

Distillation is commonly understood as training one model by learning from another. A stronger “teacher” model generates answers or reasoning traces, and that material is then used to train a “student” model to perform in a similar way. Anthropic explicitly acknowledged in the report that distillation itself is a standard training method.

What it called “illicit distillation” was narrower: unauthorized, covert and industrial-scale extraction of model capabilities. According to the report, such activity may rely on proxy relay points, fake accounts or stolen credentials to bypass access limits and collect model outputs at scale.

The dispute is focused on reasoning traces rather than final answers alone. A final answer tells a student model what the result is; the reasoning process also provides material on how to analyze and complete a task. Anthropic said the activity it identified mainly targeted capabilities in coding, tool use, data analysis and long-horizon tasks.

That leaves the core dispute tied to provenance and authorization: where the data came from, whether access was authorized, whether restrictions were bypassed and whether users knew what happened to their requests. Using distillation as a technique, by itself, does not determine whether a company’s conduct was unlawful.

Why user data became part of the dispute

According to Anthropic, some users of Moonshot AI and DeepSeek may have believed their prompts were being sent to the model they selected, while those prompts were actually forwarded to Claude.

If that allegation is accurate, the next questions are straightforward: which service providers handled the information, and whether that material was later used in model training.

The report’s wording on user notice was not equally definite in every case. In the Moonshot AI section, for example, Anthropic wrote that it did not know whether the company had notified customers.

Anthropic also raised a safety concern. It said extracted model capabilities may not carry over the original model’s safety constraints. That was one reason it included distillation in a threat report rather than treating it only as a commercial dispute.

The company said its responses included detecting anomalous extraction behavior, banning related accounts, replacing full reasoning content with summaries and strengthening identity verification.

No verifiable formal response identified from the seven companies

As of Sept. 11, 2026, the source article said it had not found a verifiable formal response from the seven named companies to the September report.

Still, public discussion around distillation had already been underway before the report appeared. On July 24, Microsoft released an open letter signed by companies including Hugging Face, Meta, Mistral and Nvidia.

That letter argued that policymakers should distinguish between ordinary model-development techniques and improper appropriation. It said distillation is a widely used method for improving models, and that problems arising from unlawful extraction of value from closed-source models should be handled through targeted legal and commercial rules rather than broad restrictions on the technology itself.

Researchers have disagreed on distillation’s role and limits

There is no single view on the technical side either.

On July 23, TechCrunch, discussing the distillation controversy around Kimi K3, cited AI researcher Nathan Lambert as saying that as models move closer to the frontier and training shifts toward reinforcement learning, supervised fine-tuning style distillation alone cannot easily explain the full improvement in capabilities.

Braden Hancock, a researcher at Laude Institute and co-founder of Snorkel AI, also said U.S. commentary has underestimated the technical strength of Chinese teams.

Those comments addressed distillation’s technical contribution and the boundaries of regulation. They did not independently verify the specific allegations in Anthropic’s September report.

Key questions remain open

For now, the public record is still dominated by Anthropic’s one-sided investigative account. Whether the named companies respond to the specific accounts and data sources involved, whether user prompts were in fact forwarded and how the relevant training data was authorized remain unresolved.

The source article also highlighted several unanswered points: how the 151 million interactions were attributed, whether user requests were forwarded with authorization and which conversations, if any, were used for training.

For ordinary users, the dispute reaches beyond model competition. When code, business materials or private conversations are entered into an AI service, one of the central questions raised here is whether only the on-screen model is handling that information.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.