Distillation at industrial scale
Anthropic's report covers misuse it disrupted between December 2025 and August 2026. Its section on distillation, the practice of training one model on another's outputs, accuses seven labs based in China: Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. It attributes to Alibaba the largest distillation attack it had measured, over 151 million exchanges between May and July, and says the transcripts helped train Alibaba's Qwen models. It counts over 23 million exchanges for Moonshot, over 12.1 million in 14 days for DeepSeek and over 3.4 million for Zhipu. [1]
The report goes further than a June letter in which Anthropic had accused Alibaba of 28.8 million exchanges between April and June. The two periods overlap, so the figures should not be added together. [1][3]
Other companies' users, answered by Claude
The most unusual allegation concerns ordinary users. Anthropic says Moonshot, maker of the Kimi models, silently forwarded customer requests to Claude instead of processing them with Kimi, in one ten-day period relaying almost 300,000 requests, most of them to Opus, and then mined the saved exchanges for Claude's reasoning to train its own models. It says DeepSeek, Xiaomi and Moonshot all fed conversations between their users and their own models into Claude, which it calls likely inconsistent with privacy laws and the labs' own terms. [1]
CNBC reported that Alibaba, Moonshot, DeepSeek and Xiaomi did not immediately respond to requests for comment. The same day DeepSeek released V4.1 Flash; the report does not connect the two. [4][1]
A virus, weapons projects and state actors
Outside distillation, Anthropic describes a request its biological safety classifier blocked in May: a grant application for gain-of-function work on chikungunya virus, routed through a reseller that evaded regional blocks, and intended for a military research institute. Anthropic says it does not assert the researchers intended harm and withholds their identities. It also reports six weapons-development cases, three in China, two in Russia and one in Yemen, and Russian espionage it says matches public reporting on Midnight Blizzard. Only one case, a distillation campaign, involved Fable or Mythos-class models. [1]
Atlas interpretation: A company publishing accusations against its competitors is not a neutral source, and the named labs had not answered the specifics when it appeared. What the report offers is checkable detail rather than a general charge: counts, dates, account numbers and mechanisms that the accused could dispute. [1][4]
Sources
- Detecting and countering misuse of AI: September 2026
Anthropic · Sep 10, 2026
- Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek
TechCrunch · Sep 10, 2026
- Anthropic accuses Alibaba of campaign to 'brazenly' and 'illicitly' extract AI capabilities
CNBC · Jun 24, 2026
- Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says
CNBC · Sep 10, 2026