Skip to main content
LLMgram · AI News · 2026-09-11

Anthropic alleges Chinese labs trained models on millions of Claude exchanges

Anthropic alleges Chinese labs trained models on millions of Claude exchanges

Anthropic has accused Chinese AI laboratories of covertly harvesting millions of Claude exchanges to train competing models, framing the effort as industrial-scale illicit distillation. Reporting tied to the company's threat intelligence release describes firms including DeepSeek and Moonshot routing queries through overseas transfer stations, using thousands of fake accounts, and passing Claude outputs off as their own. Reuters says Anthropic disrupted Russian and Chinese campaigns targeting Claude, while Bloomberg reports Moonshot covertly routed thousands of requests through the U.S. provider. The disclosures position frontier labs as active defenders against geopolitical model extraction, but published excerpts offer limited technical detail on detection methods or independent verification, leaving scale and impact dependent largely on Anthropic's own accounting.

Sources

Anthropic alleges Chinese labs trained models on millions of Claude exchanges

Anthropic alleges Chinese labs trained models on millions of Claude exchanges

CNBC reports Anthropic says Chinese AI labs secretly used millions of Claude exchanges to train their models. Reuters reports Anthropic disrupted Russian and Chinese AI campaigns targeting its Claude models.

Key takeaway

Frontier API providers must treat high-volume output access as an extraction target and shift from terms-of-service trust to active anti-distillation enforcement.

What happened

CNBC reports Anthropic says Chinese AI labs secretly used millions of Claude exchanges to train their models, alleging large-scale unauthorized distillation that bypassed API terms of service.

Reuters reports Anthropic disrupted Russian and Chinese AI campaigns targeting Claude. Techmeme excerpts cite Wall Street Journal reporting that DeepSeek and Moonshot used thousands of fake accounts and millions of real user queries routed through overseas transfer stations, while Bloomberg says Moonshot covertly routed thousands of user requests through Claude and passed off the responses as its own.

Evidence

  • CNBC reports Anthropic says Chinese AI labs secretly used millions of Claude exchanges to train their models.

    CNBC AI · attributed

    CNBC reports Anthropic says Chinese AI labs secretly used millions of Claude exchanges to train their models.

  • Reuters reports Anthropic disrupted Russian and Chinese AI campaigns targeting its Claude models.

    Reuters AI · attributed

    Reuters reports Anthropic disrupted Russian and Chinese AI campaigns targeting its Claude models.

  • Anthropic says DeepSeek and Moonshot used thousands of fake accounts and millions of real user queries in a distillation effort to clone its AI capabilities.

    Techmeme · attributed

    Anthropic says DeepSeek and Moonshot used thousands of fake accounts and millions of real user queries in 'distillation' effort to clone its AI capabilities

  • Bloomberg reports Anthropic accused Moonshot AI of covertly routing thousands of user requests to Claude and passing off the responses as its own.

    Bloomberg Technology · attributed

    Anthropic PBC accused China's artificial intelligence champion Moonshot AI of covertly routing thousands of user requests to the US firm's Claude models and passing off the responses as its own in a bid to gain an edge in the AI race.

  • Anthropic published a threat intelligence report on disrupted misuse of Claude including illicit distillation.

    Techmeme · attributed

    Anthropic publishes a threat intelligence report on how it disrupted efforts to misuse Claude for cyberattacks, influence operations, surveillance, and more — Cyber operations Surveillance operations Influence operations Conventional weapons Biological misuse Scams and fraud Illicit distillation

Why it matters

The episode shows state-adjacent AI rivals can allegedly industrialize capability cloning at million-exchange scale while U.S. labs respond with public counter-campaign disclosures.

Limits and uncertainties

Published excerpts lack technical specifics on how Anthropic detected the scraping, whether adversarial prompting was involved, or if independent parties can verify the data was used in training.

Reuters and CNBC Google News excerpts are brief boilerplate summaries without detailed campaign methods, scale beyond headlines, or Anthropic detection mechanisms.

Practical implications

Builders and operators should assume API outputs are a high-value extraction target and plan for rate limiting, output monitoring, and anti-distillation defenses rather than relying on terms of service alone.

Teams routing third-party model calls through proxy or transfer-station infrastructure should expect frontier providers to monitor usage patterns for distillation signatures.

What to watch

Whether Wall Street Journal, Bloomberg, or Anthropic release further technical detail on detection methods, named firms beyond Moonshot and DeepSeek, or enforcement and legal follow-up.

Independent verification of whether harvested Claude exchanges were incorporated into rival model training.

Sources

LLMgram editorial selection and synthesis · @llmgram. LLMgram is not the original publisher of this information.
Continue on LLMgram: Open in AI Signal →
Original reporting: Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says - CNBC