Anthropic Says Chinese Labs Trained Models on Millions of Claude Exchanges
Anthropic has publicly accused Chinese AI laboratories of mounting a large-scale distillation campaign against its Claude models, alleging that firms including DeepSeek and Moonshot used thousands of fake accounts and millions of user queries routed through overseas transfer stations to extract capabilities at industrial scale. CNBC reports the company claims millions of Claude exchanges were repurposed to train competing models, while Bloomberg separately says Moonshot covertly routed thousands of requests and passed off Claude responses as its own. Reuters notes Anthropic has also disrupted Russian and Chinese campaigns targeting Claude as part of a broader threat intelligence release covering cyber misuse, surveillance, and illicit distillation. The disclosures mark a shift toward active counter-intelligence by frontier labs, though published excerpts lack independent verification of training use or detailed detection methods.
Anthropic Says Chinese Labs Trained Models on Millions of Claude Exchanges
CNBC reports that Anthropic alleges Chinese AI labs secretly used millions of Claude exchanges to train competing models. Reuters separately notes Anthropic has disrupted Russian and Chinese AI campaigns targeting its Claude models.
Key takeaway
Closed-source frontier labs are moving from passive API terms to active surveillance against industrial-scale distillation by foreign competitors.
What happened
CNBC reports that Anthropic alleges Chinese AI labs secretly used millions of Claude exchanges to train competing models, framing the activity as a large-scale model extraction effort that bypassed API terms of service. Reporting via the Wall Street Journal, summarized by Techmeme, names DeepSeek and Moonshot and describes queries sent through transfer stations outside China.
Reuters separately reports Anthropic disrupted Russian and Chinese AI campaigns targeting Claude models. Bloomberg says Anthropic accused Moonshot of covertly routing thousands of user requests to Claude and passing off the responses as its own, while Anthropic published a threat intelligence report detailing disrupted misuse spanning cyberattacks, influence operations, surveillance, and illicit distillation.
Evidence
CNBC reports Anthropic alleges Chinese AI labs secretly used millions of Claude exchanges to train competing models.
CNBC AI · attributed
CNBC reports that Anthropic alleges Chinese AI labs secretly used millions of Claude exchanges to train competing models.
Reuters reports Anthropic disrupted Russian and Chinese AI campaigns targeting Claude models.
Reuters AI · attributed
Reuters separately notes Anthropic has disrupted Russian and Chinese AI campaigns targeting its Claude models.
Wall Street Journal reporting, via Techmeme, says DeepSeek and Moonshot used thousands of fake accounts and millions of real user queries in a distillation effort routed through transfer stations outside China.
Techmeme · attributed
Anthropic says DeepSeek and Moonshot used thousands of fake accounts and millions of real user queries in 'distillation' effort to clone its AI capabilities
Bloomberg reports Anthropic accused Moonshot of covertly routing thousands of user requests to Claude and passing off responses as its own.
Bloomberg Technology · attributed
Anthropic PBC accused China's artificial intelligence champion Moonshot AI of covertly routing thousands of user requests to the US firm's Claude models and passing off the responses as its own in a bid to gain an edge in the AI race.
Anthropic published a threat intelligence report on disrupted misuse including cyberattacks, influence operations, surveillance, and illicit distillation.
Techmeme · attributed
Anthropic publishes a threat intelligence report on how it disrupted efforts to misuse Claude for cyberattacks, influence operations, surveillance, and more — Cyber operations Surveillance operations Influence operations Conventional weapons Biological misuse Scams and fraud Illicit distillation
Why it matters
API operators must treat model outputs as high-value extraction targets and assume state-aligned actors are probing frontier systems at scale.
Limits and uncertainties
Published excerpts lack technical specifics on how Anthropic detected the scraping and whether independent parties can verify the alleged data was used in training.
Reuters and several Google News excerpts are generic summaries without detailed campaign methods, scale, or detection mechanisms.
Practical implications
Builders relying on closed-source APIs should plan for rate limiting, output monitoring, and anti-distillation defenses rather than terms-of-service enforcement alone.
Operators should expect frontier providers to publish more threat intelligence and take unilateral enforcement actions against suspected misuse.
What to watch
Whether Anthropic or third parties publish technical proof linking extracted Claude exchanges to specific competitor model training.
Follow-up reporting on legal, diplomatic, or platform enforcement actions against named firms such as DeepSeek and Moonshot.
Additional detail from Anthropic's threat intelligence report on detection methods and scale of disrupted Russian and Chinese campaigns.