Anthropic says Chinese AI labs trained models on millions of Claude exchanges
Anthropic has publicly accused Chinese AI developers, including Moonshot and DeepSeek, of industrial-scale unauthorized distillation of Claude, alleging millions of user queries and model exchanges were harvested through thousands of fake accounts and overseas transfer stations to train competing models. CNBC and the Wall Street Journal relay the firm's claim that labs secretly used Claude outputs at scale, while Bloomberg reports Moonshot routed thousands of user requests through Claude and repackaged responses as its own. In parallel reporting, Reuters says Anthropic disrupted Russian and Chinese campaigns targeting Claude, and the company published a broader threat intelligence report covering cyberattacks, influence operations, surveillance, and biological misuse. The disclosures mark a shift toward active counter-abuse enforcement by frontier labs, though independent verification of training use and campaign scope remains limited in public excerpts.
Anthropic says Chinese AI labs trained models on millions of Claude exchanges
CNBC reports Anthropic says Chinese AI labs secretly used millions of Claude exchanges to train their models. Reuters separately reports Anthropic disrupted Russian and Chinese AI campaigns targeting Claude.
Key takeaway
Closed-source API providers face industrial-scale model extraction, pushing enforcement from terms of service toward active anti-distillation surveillance.
What happened
CNBC reports that Anthropic says Chinese AI labs secretly used millions of Claude exchanges to train their models, framing the activity as a large-scale unauthorized distillation effort that bypassed API terms of service.
Reporting from the Wall Street Journal and Bloomberg adds that firms including DeepSeek and Moonshot used thousands of fake accounts and overseas transfer stations to route queries to Claude, while Reuters separately reports Anthropic disrupted Russian and Chinese AI campaigns targeting its models.
Evidence
Anthropic alleges Chinese AI labs secretly used millions of Claude exchanges to train models
CNBC AI · attributed
Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says CNBC
DeepSeek and Moonshot allegedly used thousands of fake accounts and millions of queries via transfer stations
Techmeme · attributed
Anthropic says DeepSeek and Moonshot used thousands of fake accounts and millions of real user queries in 'distillation' effort to clone its AI capabilities
Moonshot covertly routed thousands of user requests through Claude and passed off responses as its own
Bloomberg Technology · attributed
Anthropic PBC accused China's artificial intelligence champion Moonshot AI of covertly routing thousands of user requests to the US firm's Claude models and passing off the responses as its own in a bid to gain an edge in the AI race.
Anthropic disrupted Russian and Chinese AI campaigns targeting Claude
Reuters AI · attributed
Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models Reuters
Anthropic published a threat intelligence report on disrupted misuse categories including illicit distillation
Techmeme · attributed
Anthropic publishes a threat intelligence report on how it disrupted efforts to misuse Claude for cyberattacks, influence operations, surveillance, and more — Cyber operations Surveillance operations Influence operations Conventional weapons Biological misuse Scams and fraud Illicit distillation
Why it matters
Operators building on frontier APIs must treat exported model outputs as high-value extraction targets and plan technical controls beyond contractual restrictions.
Limits and uncertainties
Public excerpts lack technical specifics on how Anthropic detected the scraping and whether adversarial prompting was involved.
Without independent verification, the training-use allegations remain a unilateral claim by Anthropic.
Reuters and other Google News excerpts provide limited detail on campaign methods, scale, and detection mechanisms.
Practical implications
API operators should assume outputs are actively monitored for distillation signatures and design rate limiting accordingly.
Builders relying on closed-model APIs need anti-extraction controls such as output watermarking and adversarial robustness testing.
Security teams should treat state-level probing of frontier models as an active threat requiring dedicated detection protocols.
What to watch
Whether Anthropic or regulators pursue legal or diplomatic follow-up on the distillation allegations.
Independent confirmation that harvested Claude exchanges were incorporated into rival model training.
Additional technical disclosure on fake-account infrastructure and overseas transfer-station routing.