Story
September 11, 2026
Anthropic Says Chinese AI Labs Tried to Turn Claude Into Their Training Engine
Anthropic portrays the alleged campaigns as an escalating effort to siphon frontier-model capabilities, while the Chinese companies it named have not publicly offered their side of the story. The dispute underscores how fiercely AI labs are fighting over both model performance and the data used to achieve it.
Anthropic’s warning did not emerge from nowhere. In February, the company had already begun publicly raising alarms about alleged model-distillation efforts, and in June its policy chief told lawmakers that Alibaba had made 28.8 million illicit exchanges with Claude between April 22 and June 5.1
May–July 2026: Anthropic now says the activity surged into something far larger. Its latest report alleges nearly 200 million exchanges tied to five campaigns targeting Claude’s coding, data-analysis, tool-use and reasoning capabilities. The company said attackers found ways to coax out thinking traces that are normally concealed behind summarized explanations — a potentially valuable shortcut for training competing models. “Unauthorized labs have developed increasingly sophisticated methods to circumvent our defenses and harvest the capabilities of US frontier models,” Anthropic said.2
The largest alleged operation was linked to Alibaba: 151 million exchanges over three months, spread across 3,500 accounts and peaking near three million a day, according to Anthropic. It contends the campaign used a shared prompt to extract reasoning for Alibaba’s Qwen models. Anthropic also alleged that Moonshot routed user requests to Claude, including requests it said came from Chinese military-linked users; DeepSeek, Zhipu and Xiaomi were among other companies named.2
September 10: The company broadened the stakes in a separate threat-intelligence report, saying it had disrupted Claude misuse by actors linked to China and Russia, from cyber operations to surveillance and influence work. Anthropic’s message was blunt: it said it had stopped every operation described in the report.
3
Anthropic says it has tightened safeguards, reduced the detail in Claude’s reasoning transcripts and will require identity verification for suspicious users operating from countries where Claude is unavailable. The accused firms had not responded to requests for comment, so the central allegations remain Anthropic’s account — detailed, consequential and publicly unrefuted.1