Anthropic Reports China-Based AI Labs Used Claude Outputs for Unauthorized Model Training
Quick Look
Anthropic disclosed that China-based AI labs including Alibaba, Moonshot, and DeepSeek conducted large-scale unauthorized distillation of Claude model outputs to train their own systems, involving over 151 million exchanges and sensitive user data, which the company said it disrupted between December 2025 and August 2026.
AI-generated summary
Why It Matters
Anthropic released a threat intelligence report detailing unauthorized use of its Claude AI model by China-based companies to train competing models through a process called distillation, which involves using outputs from a more capable model to improve another without authorization.
Anthropic said it detected and disrupted unauthorized large-scale efforts by China-based AI labs including Alibaba , Moonshot and DeepSeek to train their models using Claude.
The U.S. AI company said in a threat intelligence report released Thursday that the firms were involved in what it described as "illicit distillation," a process in which outputs from a more capable AI model are used to train another model and replicate some of its capabilities without authorization.
"Some of these exchanges included sensitive information, including from individual users, major multinational companies, and state-affiliated actors ... These practices are likely inconsistent with privacy laws and the labs' own terms of service," according to the report.
Anthropic said operators affiliated with Alibaba used Claude outputs to help train its Qwen models, while Moonshot routed some Kimi user requests to Claude and used some of the resulting exchanges to train its own models.
The Alibaba operation was the largest distillation campaign Anthropic said it has measured, involving more than 151 million exchanges with Claude between May and July.
The activity peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts, according to the report. The company said Alibaba also used Claude for broader AI research, including reinforcement learning and model architecture.
Moonshot and DeepSeek
Anthropic also detailed activity involving Moonshot AI, the Beijing-based company behind the Kimi family of AI models.
Moonshot silently forwarded some customer requests intended for Kimi to Claude and then displayed Claude's responses to users, who thought they were using a Kimi model, according to the report.
In one 10-day period, Moonshot relayed nearly 300,000 customer requests to Anthropic, the vast majority of which were routed to Claude Opus models. The requests were routed through a network of 5,380 accounts that Anthropic described as fraudulent, most of which appeared to be located in Singapore and Japan.
The report said Moonshot saved at least some of those exchanges and extracted Claude's reasoning transcripts to use as training data for its own models.
More than 23 million exchanges were attributed to Moonshot between May and July, according to the report.
Some of the customer requests routed to Claude contained sensitive information. The company said it did not know whether Moonshot had notified customers that their requests were being sent to Anthropic.
The company said DeepSeek — which rose into prominence last year due to its capabilities and cheap costs — also used tactics similar to Moonshot, transferring exchanges to Claude without notifying DeepSeek customers. Anthropic said it observed more than 12 million distillation attacks attributable to DeepSeek over 14 days in July 2026.
The report, which named several other major Chinese AI companies, report covers activity the company said it disrupted between December 2025 and August 2026 across seven areas, including cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation.
Alibaba, Moonshot, DeepSeek, Xiaomi and Anthropic did not immediately respond to CNBC's requests for comment.
What to Watch
AI outlook — possibilities, not facts
Anthropic will implement stronger technical safeguards to prevent unauthorized access to its model outputs
Likely · Within weeks
Regulatory scrutiny of AI model distillation practices will increase in the U.S. and internationally
Possible · Within months
Open Questions
- What specific actions will Anthropic take beyond disruption to prevent future incidents?
- Did the affected companies notify users whose data was involved in the unauthorized exchanges?
- Are there legal or regulatory consequences for the companies involved in the distillation activities?




