Anthropic says Chinese labs used Claude to train AI
US company Anthropic said it had detected and stopped large-scale unauthorized attempts by Chinese artificial intelligence laboratories, including Alibaba, Moonshot AI and DeepSeek, to use responses from its Claude model to train their own systems. This was reported by CNBC Top News, citing Anthropic’s threat analysis report.
Campaign involving Claude
Anthropic described these actions as unauthorized “distillation” — a practice in which the outputs of a more powerful model are used to train another AI model and reproduce some of its capabilities without permission. According to the company, operators linked to Alibaba used Claude’s responses to train Qwen models, as well as for research in reinforcement learning and model architecture.
Anthropic said the Alibaba-linked operation was the largest distillation campaign it had recorded. From May through July, it involved more than 151 million interactions with Claude. Peak activity reached nearly 3 million interactions per day through more than 3,500 accounts that Anthropic described as fraudulent.
Moonshot AI and DeepSeek
According to Anthropic, Beijing-based Moonshot AI discreetly redirected some user requests intended for the Kimi model to Claude and then showed users Claude’s responses. According to the report, users believed they were interacting with the Kimi model.
More current news is available on the UA.News Telegram channel Telegram.
During one ten-day period, Moonshot, according to Anthropic’s estimate, redirected nearly 300,000 requests to Anthropic; the overwhelming majority of them went to Claude Opus models. This allegedly used a network of 5,380 accounts, most of which, according to the company’s assessment, operated from Singapore and Japan. Anthropic also said that Moonshot retained at least some of these interactions and extracted Claude’s reasoning records to train its own models.
From May through July, Anthropic linked more than 23 million interactions with Claude to Moonshot. The company noted that some redirected requests contained sensitive information and said it did not know whether Moonshot had informed its customers that their requests were being sent to Anthropic.
Anthropic also reported a similar practice by DeepSeek. By its estimate, over 14 days in July 2026, it recorded more than 12 million distillation attempts that it attributed to DeepSeek. The report covers cases of abuse of Anthropic’s systems that the company said it stopped between December 2025 and August 2026.