Listen to this article

Narrated by Charlotte · The Noble House

Compass — Strategic Intelligence

Artificial intelligence competition now reaches beyond research performance into the operational security of model access. In September 2026, Anthropic disclosed what it described as coordinated, industrial-scale distillation campaigns against Claude, attributing the activity to entities affiliated with major Chinese AI laboratories. Anthropic reported nearly 190 million harvested exchanges, including more than 151 million associated with Alibaba’s campaign. [2]cryptobriefing.comAnthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeSupporting coverage from CryptoBriefing: Anthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeOpen source ↗ [7]anthropic.comDetecting and countering misuse of AI: September 2026Anthropic's primary account describes the attributed campaigns, collection methods, observed volumes, and layered defensive response.Open source ↗ If the company’s account is accurate, the central problem is not ordinary competitive learning but systematic extraction of a model’s costly capabilities through an interface intended for legitimate use. That distinction matters because unchecked extraction could weaken incentives to invest in advanced models while accelerating geopolitical competition. AI providers and policymakers should therefore treat high-volume distillation as a combined security, governance, and attribution problem: detect anomalous access, preserve evidence, distinguish permitted research from prohibited extraction, and build enforceable rules without closing APIs to legitimate users.

Anthropic’s disclosure moved the AI arms race from an abstract concern to a specific operational dispute. The company said its proprietary language model had been targeted through massive, coordinated data-exfiltration campaigns conducted by major Chinese AI laboratories. According to Anthropic, those laboratories used industrial-scale distillation to collect high-quality outputs capable of supporting the training of competing systems. By disrupting the campaigns and publicly identifying participants, Anthropic attempted to define a boundary between legitimate model use and illicit appropriation. Its report, Countering misuse of AI: September 2026 / Anthropic, presented model integrity as both a corporate-security concern and a component of national technological security [7]anthropic.comDetecting and countering misuse of AI: September 2026Anthropic's primary account describes the attributed campaigns, collection methods, observed volumes, and layered defensive response.Open source ↗.

The Scale and Scope of the Distillation Campaigns

The reported scale separates this incident from casual scraping or isolated misuse. Anthropic’s internal investigation connected the campaigns to entities affiliated with seven prominent Chinese AI laboratories and named Alibaba, DeepSeek, Moonshot, Zhipu, also known as Z.ai, and MiniMax among them. [7]anthropic.comDetecting and countering misuse of AI: September 2026Anthropic's primary account describes the attributed campaigns, collection methods, observed volumes, and layered defensive response.Open source ↗ The company reported that operators linked to the laboratories harvested nearly 190 million Claude exchanges [2]cryptobriefing.comAnthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeSupporting coverage from CryptoBriefing: Anthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeOpen source ↗. That figure is important because a distillation dataset derives value from repeated access to a capable teacher model: many targeted prompts can expose patterns across reasoning, coding, and writing tasks that a small sample would not capture.

Alibaba reportedly accounted for the largest identified share. Anthropic said Alibaba’s campaign generated more than 151 million exchanges with Claude between May and July 2026 [6]yahoo.comAnthropic accuses Chinese AI labs of illicit distillation attacksSupporting coverage from Yahoo News: Anthropic accuses Chinese AI labs of illicit distillation attacksOpen source ↗. The duration and volume support the narrower conclusion that the activity was sustained and heavily resourced rather than sporadic. They do not, by themselves, establish who inside or outside the company authorized every request. They do show why API abuse at this scale cannot be evaluated as a handful of users violating ordinary service limits.

The participation attributed to DeepSeek, Moonshot, Zhipu, MiniMax, and other laboratories broadens the issue beyond one bilateral corporate dispute. On Anthropic’s account, multiple competitors treated Claude outputs as inputs to their own development processes. The reported pattern therefore suggests an industry-level incentive: querying an advanced model may provide useful training material more quickly and cheaply than independently reproducing every capability. It is an inference, not a demonstrated outcome, that this approach reduced development time for any particular model, because the retained source does not provide comparative training costs or measured capability gains.

Scale alone also does not prove successful replication. A dataset containing millions of responses can be valuable, but its usefulness depends on prompt selection, response quality, filtering, training methods, and the receiving model. Anthropic’s numbers establish the alleged volume of collection, not the exact performance improvement obtained from it. Keeping those claims separate strengthens the case: defenders do not need to prove that every harvested exchange improved a rival model before treating coordinated extraction as a serious threat.

Compass Predictive Analytics

Signal gauge

44%

Evidence Reliability

3 Of 3 Validated Assertions Have Complete Exact Span And Ownership Lineage. · Positive

tracked

Quantifies the conservative evidence floor after exact-span and independent-owner checks.

100%ObservedTraceability43.9%95%Lower Bound
3 evidence references

Signal gauge

97%

Evidence Freshness

Evidence Freshness Is 97 For The Selected Signal. · Positive

tracked

Separates current evidence from aging context using a declared decay window.

97.3%TimeDecayed Fres
3 evidence references
The Scale and Scope of the Distillation Campaigns The reported scale separates this incident from casual scraping or isolated misuse.
The Scale and Scope of the Distillation Campaigns The reported scale separates this incident from casual scraping or isolated misuse.

Technical Mechanisms and Operational Timeline

Distillation is the mechanism that makes model outputs potentially reusable at scale. In a typical teacher-and-student arrangement, a smaller or less capable model is trained to imitate behavior demonstrated by a stronger model. Here, Claude allegedly served as the teacher. According to the source, the operators designed queries to elicit complex responses involving reasoning, coding, and agentic tasks. Those responses could then be incorporated into training material for proprietary systems, including Alibaba’s Qwen series. [7]anthropic.comDetecting and countering misuse of AI: September 2026Anthropic's primary account describes the attributed campaigns, collection methods, observed volumes, and layered defensive response.Open source ↗

The economic attraction of this method follows from what the outputs contain. Training a frontier model from random initialization requires substantial resources, while a teacher model’s responses already express capabilities produced by prior research and training. Collecting those responses does not literally transfer the original model’s parameters, and it cannot reproduce everything hidden inside the teacher. It can nevertheless provide structured examples of desired behavior. Inference: a carefully selected corpus could help a student model approximate some observable capabilities without repeating every step that produced the teacher.

The API was both the access point and the defensive challenge. APIs are designed to let users submit prompts programmatically, which makes them useful for applications, research, and development. The same programmability can support automated extraction when an operator distributes requests, varies prompts, or sustains traffic over time. [7]anthropic.comDetecting and countering misuse of AI: September 2026Anthropic's primary account describes the attributed campaigns, collection methods, observed volumes, and layered defensive response.Open source ↗ This creates an asymmetric problem: each request may resemble an allowed interaction, while the aggregate pattern may reveal an attempt to construct a training corpus.

Anthropic dates Alibaba’s measured campaign to May–July 2026; other campaigns have different observation windows. [7]anthropic.comDetecting and countering misuse of AI: September 2026Anthropic's primary account describes the attributed campaigns, collection methods, observed volumes, and layered defensive response.Open source ↗ The retained source separately reports that requests were routed to Claude at least 35 million times during the summer period [1]businessinsider.comChina AI Labs Routed Requests to Claude 35 Million Times: AnthropicSupporting coverage from Business Insider: China AI Labs Routed Requests to Claude 35 Million Times: AnthropicOpen source ↗. That number should not be casually substituted for the nearly 190 million reported exchanges or Alibaba’s more than 151 million exchanges, because the source does not fully define how “requests,” “exchanges,” campaigns, and time windows overlap. Taken together, however, the figures support the conclusion that the alleged operations were automated and extensive rather than incidental.

The source suggests that automated scripts generated diverse prompts, but it does not provide direct technical evidence about the scripts themselves. That proposed method is plausible because broad prompt coverage would make a harvested dataset more useful across multiple tasks. It remains an inference and should be treated as a hypothesis for detection: defenders can look for repeated semantic patterns, unusual task diversity, coordinated accounts, and collection behavior without claiming certainty about tooling that has not been publicly demonstrated.

Compass Predictive Analytics

Signal gauge

60%

Independent Source Breadth

Independent Source Breadth Is 60 For The Selected Signal. · Positive

tracked

Shows how many genuinely independent owners support the evidence after syndication collapse.

3IndependentOwners3EffectiveOwners
3 evidence references

Signal gauge

70%

Observed Source Diffusion

56 Observed Sources Resolve To 16.883526 Effective Sources. · Neutral

tracked

Separates broad source participation from concentration in a few high-volume sources.

21%SourceAccess Red5.7%HNFront24.9%Other
3 evidence references
Technical Mechanisms and Operational Timeline Distillation is the mechanism that makes model outputs potentially reusable at scale.
Technical Mechanisms and Operational Timeline Distillation is the mechanism that makes model outputs potentially reusable at scale.

Geopolitical Implications and the AI Arms Race

Anthropic’s allegations acquire geopolitical weight because the named laboratories operate within the broader technological rivalry between the United States and China. Analysts cited in the source characterize the campaigns as evidence of an escalating AI arms race [2]cryptobriefing.comAnthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeSupporting coverage from CryptoBriefing: Anthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeOpen source ↗. Advanced models can affect economic competition and national-security planning, so attempts to reproduce their capabilities are unlikely to be viewed as ordinary product benchmarking. The incident therefore connects commercial API security with state-level concerns about technological advantage.

The strongest opposing view is that distillation is a standard machine-learning technique, model outputs are intentionally provided through paid APIs, and learning from another system can promote competition rather than constitute theft. Under this view, incumbents may use security language to protect market power, while broad restrictions on output reuse could suppress legitimate research, interoperability, and innovation. Attribution also deserves caution: identifying corporate traffic does not automatically prove government direction, and high request volume does not alone establish that a competitive model incorporated the collected material.

That objection correctly demands precise boundaries, but it does not resolve the conduct Anthropic described. The relevant evidence is not the mere use of distillation; it is the alleged coordination, scale, sustained collection, targeted elicitation of high-value outputs, and disruption by the provider. Nearly 190 million exchanges across entities, with more than 151 million attributed to one campaign over three months, describe behavior qualitatively different from limited evaluation or ordinary application use [2]cryptobriefing.comAnthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeSupporting coverage from CryptoBriefing: Anthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeOpen source ↗ [6]yahoo.comAnthropic accuses Chinese AI labs of illicit distillation attacksSupporting coverage from Yahoo News: Anthropic accuses Chinese AI labs of illicit distillation attacksOpen source ↗. The rebuttal should therefore rest on authorization and intent evidenced by behavior, not on declaring every form of distillation illegitimate.

Claims of state involvement require even greater restraint. The involvement of large Chinese laboratories may be consistent with national strategic priorities, but the retained source does not establish explicit or implicit government authorization. Treating that connection as proven would collapse corporate attribution into state attribution without sufficient evidence. The defensible conclusion is narrower: activity attributed to strategically important companies can have geopolitical consequences even when the role of government remains unresolved.

This attribution gap complicates diplomatic and regulatory responses. A government can condemn an alleged campaign, but meaningful enforcement requires clarity about the actors, governing contracts, relevant jurisdictions, retained evidence, and prohibited conduct. The incident exposes weak international norms around cross-border model access and the reuse of generated outputs. Allegations of persistent distillation attacks by China-based AI companies therefore support a call for regulatory clarity, although the form of that regulation remains an open policy question [3]msn.comAnthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeekSupporting coverage from MSN: Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeekOpen source ↗.

Compass Predictive Analytics

Analytic module

3Support0Risk

module

Signal Pressure Matrix

Validated independent claim-owner cells resolve to 3 support and 0 risk pressure.

3 evidence references

Analytic module

3Sources3Exact Spans3Owners

module

Evidence Density

3 source links, 3 exact spans, and 3 independent owners support this signal.

6 evidence references
Geopolitical Implications and the AI Arms Race Anthropic’s allegations acquire geopolitical weight because the named laboratories operate within the broader technological rivalry between the United States and China.
Geopolitical Implications and the AI Arms Race Anthropic’s allegations acquire geopolitical weight because the named laboratories operate within the broader technological rivalry between the United States and China.

Corporate Responsibility and Future Security Measures

Anthropic’s public disclosure changed the defensive posture from private mitigation to collective warning. Security incidents involving proprietary models might otherwise remain inside legal, fraud, or trust-and-safety channels. By publishing the allegations and naming laboratories, Anthropic alerted other providers and regulators to the claimed scale of extraction. [7]anthropic.comDetecting and countering misuse of AI: September 2026Anthropic's primary account describes the attributed campaigns, collection methods, observed volumes, and layered defensive response.Open source ↗ Public attribution also creates reputational pressure, although its deterrent effect cannot be assumed without evidence of changed behavior.

Providers bear responsibility for securing the interfaces through which they commercialize model access. The reported campaigns indicate that authentication and ordinary rate limits may be insufficient when activity is distributed or designed to resemble legitimate demand. [7]anthropic.comDetecting and countering misuse of AI: September 2026Anthropic's primary account describes the attributed campaigns, collection methods, observed volumes, and layered defensive response.Open source ↗ More sophisticated behavioral analysis could examine patterns across accounts, prompts, timing, and response collection. Such controls should identify aggregate behavior while avoiding the unsupported assumption that any heavy user is conducting model theft.

Rate limiting is one possible control, but it carries a direct tradeoff. Restrictive limits may slow extraction while also constraining legitimate high-volume customers and researchers. A stronger approach would connect limits to risk signals and provide review or escalation paths for unusual but authorized workloads. The objective is not simply to reduce traffic; it is to distinguish productive use from coordinated attempts to turn the service into an unapproved training-data generator.

Output watermarking or related tracing mechanisms may also help investigators connect leaked training material to a source model. Watermarking is an analytical proposal here, not a defense that this report establishes as effective. Its usefulness would depend on durability, detectability, and the ability to survive transformation during dataset preparation or training. Providers should therefore treat tracing as one layer of evidence rather than a substitute for access controls, monitoring, and contractual enforcement.

The incident raises a deeper question about the API business model. If a model’s commercially valuable behavior can be extracted through repeated interactions, then wider access expands both revenue opportunities and the attack surface. That does not mean the model’s entire value is “easily” transferable; the source does not prove complete replication. It does mean providers must price, monitor, and govern access with the understanding that outputs may be aggregated into assets whose purpose differs from the individual requests that produced them.

Anthropic’s reported disruption demonstrates at least some capacity to identify and block suspicious campaigns. It does not establish that every campaign was detected, that the defensive measures will generalize, or that future operators cannot adapt. The likely continuation of attacker-defender adaptation is an inference grounded in the exposed incentives, not a measured outcome. The immediate defensive action nevertheless shows that providers are not limited to passive acceptance when they identify coordinated extraction [4]msn.comAnthropic caught Chinese AI labs carrying out massive 'distillation attack' to rip off its technologySupporting coverage from MSN: Anthropic caught Chinese AI labs carrying out massive 'distillation attack' to rip off its technologyOpen source ↗.

Compass Predictive Analytics

Analytic module

Support 100% · Risk 0%

module

Cross Pressure

Support and risk pressure differ by 100 points.

3 evidence references

Analytic module

35.5%CurrentShare36.5%Prior28D Median

module

Statistical Surprise

The current share has a modified-Z score of -0.330765 and is classified within reference range.

3 evidence references
Corporate Responsibility and Future Security Measures Anthropic’s public disclosure changed the defensive posture from private mitigation to collective warning.
Corporate Responsibility and Future Security Measures Anthropic’s public disclosure changed the defensive posture from private mitigation to collective warning.

Conclusion

The September 2026 disclosure is best understood as a test of whether AI governance can distinguish open access from industrial extraction without confusing either with ordinary competition. Anthropic alleged that entities affiliated with major Chinese laboratories harvested nearly 190 million Claude exchanges, including more than 151 million connected to Alibaba between May and July [2]cryptobriefing.comAnthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeSupporting coverage from CryptoBriefing: Anthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeOpen source ↗ [6]yahoo.comAnthropic accuses Chinese AI labs of illicit distillation attacksSupporting coverage from Yahoo News: Anthropic accuses Chinese AI labs of illicit distillation attacksOpen source ↗. Chinese AI laboratories secretly used millions of Claude exchanges as training material, according to the retained account, changing the practical conditions of competition even though the resulting capability gains are not quantified [5]msn.comChinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic saysSupporting coverage from MSN: Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic saysOpen source ↗.

The appropriate response is evidence-led protection rather than reflexive closure. Providers should detect coordinated behavior, preserve attribution evidence, enforce authorized-use boundaries, and disclose significant campaigns with careful separation between established facts and inference. Policymakers should clarify how contracts, intellectual-property rules, cross-border access, and national-security concerns apply to industrial-scale model extraction. Researchers and customers should retain legitimate paths to use APIs, because an indiscriminate restriction would sacrifice much of the openness that makes the interfaces valuable.

Anthropic’s disruption may set a precedent for future enforcement, but its lasting significance will depend on whether the precedent becomes technically credible and legally intelligible [2]cryptobriefing.comAnthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeSupporting coverage from CryptoBriefing: Anthropic disrupts massive distillation attack from Chinese AI labs targeting ClaudeOpen source ↗. The reported routing of at least 35 million requests to Claude remains an important record of the escalation, while also requiring careful interpretation alongside the larger exchange totals [1]businessinsider.comChina AI Labs Routed Requests to Claude 35 Million Times: AnthropicSupporting coverage from Business Insider: China AI Labs Routed Requests to Claude 35 Million Times: AnthropicOpen source ↗. The durable lesson is that model capability must now be defended at the interface where it is delivered. Security teams should monitor and disrupt extraction; companies should define enforceable permissions; regulators should establish clear norms; and all parties should avoid converting unresolved attribution into certainty. That combination protects innovation more effectively than either unrestricted harvesting or a retreat from useful access.

Compass Predictive Analytics

Analytic module

21%SourceAccess Red5.7%HNFront24.9%Other

module

Observed Source Diffusion

56 sources produce 16.883526 effective-source breadth with HHI 0.103868.

3 evidence references

Bibliography

  1. [1] Bharade, Aditi. 'China AI Labs Routed Requests to Claude 35 Million Times: Anthropic.' Business Insider, September 11, 2026. https://www.businessinsider.com/china-ai-labs-millions-distillation-attacks-anthropic-claude-2026-9. Business Insider
  2. [2] CryptoBriefing. 'Anthropic disrupts massive distillation attack from Chinese AI labs targeting Claude.' September 2026. https://cryptobriefing.com/anthropic-disrupts-chinese-ai-distillation-claude/. CryptoBriefing
  3. [3] MSN. 'Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek.' September 2026. https://www.msn.com/en-us/technology/artificial-intelligence/anthropic-details-distillation-campaigns-from-alibaba-moonshot-ai-and-deepseek/ar-AA2bYoeP. MSN
  4. [4] MSN. 'Anthropic caught Chinese AI labs carrying out massive distillation attack to rip off its technology.' September 2026. https://www.msn.com/en-us/news/other/anthropic-caught-chinese-ai-labs-carrying-out-massive-distillation-attack-to-rip-off-its-technology/ar-AA2c2d2n. MSN
  5. [5] MSN. 'Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says.' September 2026. https://www.msn.com/en-us/money/markets/chinese-ai-labs-secretly-used-millions-of-claude-exchanges-to-train-their-models-anthropic-says/ar-AA2bYO5g. MSN
  6. [6] Yahoo News. 'Anthropic accuses Chinese AI labs of illicit distillation attacks.' September 2026. https://www.yahoo.com/news/us/articles/anthropic-accuses-chinese-ai-labs-122255005.html. Yahoo News
  7. [7] Anthropic. "Detecting and countering misuse of AI: September 2026." September 2026. https://www.anthropic.com/threat-intelligence-report-september-2026. Anthropic