Anthropic says China-based AI companies used thousands of accounts and millions of requests to extract the behavior of its Claude models, raising new questions about how frontier AI can remain accessible without becoming easy to replicate.

A contest over more than answers

For the people building and deploying AI systems, the concern is not simply that another company might copy a useful response. Anthropic says attackers tried to study how Claude reasons, writes code, analyzes data and uses tools, treating the model less like a consumer service and more like a research subject.

In a report covered by TechCrunch on September 10, 2026, Anthropic said it identified five separate distillation campaigns involving nearly 200 million exchanges. Distillation is the process of training one model to imitate the behavior of another. It can help create smaller, cheaper systems, but it can also allow a company to absorb capabilities developed through years of research and billions of dollars in investment.

NVIDIA H100 GPU
NVIDIA H100 GPU · 极客湾Geekerwan · via wikipedia · CC BY 3.0

Anthropic attributed the campaigns to Alibaba, Moonshot AI and DeepSeek. The largest alleged operation was linked to Alibaba and generated 151 million exchanges between May and July 2026, according to the company. It reportedly used about 3,500 accounts and reached nearly three million exchanges per day. Anthropic said the activity appeared intended to create training material for Alibaba’s Qwen model family.

The company also described prompts designed to persuade Claude to treat prior working memory as a translation exercise. Such methods, Anthropic said, may have been intended to elicit information connected to internal reasoning or other intermediate behavior that providers generally do not expose to users.

Surveillance claims raise the stakes

One campaign that Anthropic associated with Moonshot AI involved requests directed at its Opus model. The company said thousands of accounts appeared to seek analysis of closed circuit television footage, including judgments about whether a person was behaving abnormally.

Anthropic characterized that activity as connected to the Chinese military. That is a serious claim, and it requires independent verification and clear evidence. Public attribution is especially sensitive when commercial AI competition overlaps with national security concerns.

The broader problem is difficult to solve. Frontier labs want their models to be capable enough to serve as coding assistants, research agents and automated analysts. Those same abilities make them valuable targets. Blocking suspicious traffic can protect a model, but aggressive restrictions may also frustrate legitimate customers, researchers and smaller companies.

The alleged campaigns therefore expose a basic weakness in the AI economy: access can be distributed through accounts faster than identity systems can reliably distinguish customers from coordinated operators. Providers may respond with stronger verification, tighter rate limits and more selective API access. They will also face pressure to explain what evidence supports public accusations.

The debate is moving beyond whether AI models can be copied. It is becoming a question of who controls the methods that make advanced systems useful, and how much openness the next generation of AI can safely tolerate.

#Anthropic#Claude#Alibaba#Qwen#Moonshot AI#DeepSeek
Daniel Reyes writes spAIsee's technical explainers: how a model is built, trained, evaluated and served, and where the published claims stop matching the measured behaviour. He covers architecture, inference economics, evaluation methodology and agent tooling, and reads the paper before the press release.

This article was written with the assistance of an AI system and published automatically.