US AI company Anthropic claimed on 10 (local time) that China-based research institutes used the capabilities of its Claude models for training without authorization.
The issue at the center of the debate is not merely whether the responses of another model were referenced.
That is because the possibility has also been raised that conversations users believed they were having with another AI service may have been transferred to a third-party model.
3-Line Summary
1. Anthropic alleged that a Chinese company engaged in unauthorized distillation
2. Accounts linked to Alibaba used 1억5100만건 interactions
3. The key issue is the transfer path of user conversations
3500 Accounts and 1억5100만건 Interactions
In a report released on 10, Anthropic said it had detected and blocked unauthorized distillation activities involving Claude by 7 research institutes based in mainland China since February. Here, distillation refers to a technique that uses the output data of a high-performing “teacher model” to train a smaller “student model.” Although the technique itself is used in the AI industry, Anthropic classified activities intended to extract and replicate model capabilities without authorization as “illegal distillation.”
The largest case identified involved Chinese e-commerce company Alibaba. Anthropic claimed that operators linked to Alibaba mobilized more than 3500 fraudulent accounts between May and July 2026 and conducted more than 1억5100만건 interactions with Claude. The maximum daily volume was reportedly about 300만건.
According to Anthropic’s explanation, they sought to convert Claude Opus’s reasoning-related outputs into supervised-learning data and use them to train Alibaba’s Qwen 3.5, 3.6, and 3.7 models. The claim is that core capabilities such as agent functions, tool use, coding, data analysis, and logical reasoning were targeted. Because Alibaba’s direct response or confirmation is not included in the body of this article, this passage should be treated as a finding from Anthropic’s investigation.
The Possibility That Claude Was Involved Even Though Users Used “Kimi”
The more sensitive aspect concerns the processing path of user conversations rather than competition over model performance. Anthropic claimed that Chinese AI company Moonshot AI sent questions from users of its Kimi service to Claude to generate answers. Users believed they were using Kimi, but the explanation is that their actual requests and responses may have passed through Claude.
Anthropic said that, in the case related to Moonshot AI, more than 2300만건 requests were sent to Claude between May and July, and that 5380 fraudulent accounts apparently located in Singapore, Japan, and elsewhere were used. It also said that some of the transferred conversations included potentially sensitive information such as names, email addresses, and corporate information.
Similar allegations were also made regarding Chinese AI company DeepSeek. Anthropic said that DeepSeek routed some customer requests through Claude Opus and that it observed more than 1210만건 DeepSeek-related exchanges during 14 July. This case, too, is an analysis from Anthropic’s report. The extent to which a specific company actually processed user information, and what kinds of information it handled, can be determined only with the companies’ official explanations.
When Proxies Are Involved, the Chain of Responsibility Also Becomes More Complex
Anthropic claimed that third-party proxy networks enabling access to US AI models in regions where access is restricted were used together with fake accounts. A proxy is an intermediary network that forwards requests on behalf of the user between the user and an AI service. If this structure is accurate, users may have difficulty realizing which model and which intermediary service their questions passed through.
What deserves attention in this case is not the technical term “distillation” but where the conversations were sent. Separate from the issue of using model responses for training, whether service users knew that their conversations had passed through another model and through what path sensitive content moved could become issues involving personal information and service terms.
China’s Ministry of Commerce pushed back, saying that distillation is a neutral and conventional technology used throughout the global AI industry and that the United States was politicizing a technological issue to suppress China’s industry. Anthropic said it would strengthen the detection of abnormal accounts and proxy patterns and block suspicious accounts. With the two sides’ positions at odds, the controversy is likely to remain an incident that asks who has control over user conversations, rather than focusing on the scale of technological competition.
References
Tags #China #Anthropic #Claude #AIDistillation #UnauthorizedDistillation #Alibaba #Qwen #MoonshotAI #Kimi #DeepSeek #Proxy #AIPersonalInformation #AI_Security