Chinese AI labs used millions of Claude exchanges for training, Anthropic says
Anthropic has escalated accusations that Chinese AI labs, including DeepSeek and Moonshot, conducted large-scale unauthorized distillation of Claude. CNBC reports Anthropic alleges the labs used millions of Claude exchanges to train competing models, routing queries through overseas transfer stations with thousands of fake accounts, according to Wall Street Journal reporting cited by Techmeme. Reuters separately reports Anthropic disrupted Russian and Chinese campaigns targeting Claude, while Anthropic also published a threat intelligence report covering cyber operations, surveillance, influence activity, and illicit distillation. Bloomberg reports Moonshot routed thousands of user requests through Claude and passed off responses as its own. The disclosures signal active counter-extraction at geopolitical scale. Independent verification remains limited, and excerpts lack detection and enforcement specifics.
Chinese AI labs used millions of Claude exchanges for training, Anthropic says
CNBC reports that Anthropic alleges Chinese AI labs secretly used millions of Claude exchanges to train their models. Reuters separately reports Anthropic disrupted Russian and Chinese AI campaigns targeting Claude.
Key takeaway
Industrial-scale Claude distillation via proxy infrastructure shows closed API outputs cannot be protected by terms of service alone.
What happened
CNBC reports that Anthropic alleges Chinese AI labs secretly used millions of Claude exchanges to train their models, framing the activity as large-scale unauthorized distillation that bypassed API terms of service.
Reuters reports Anthropic disrupted Russian and Chinese AI campaigns targeting Claude; Techmeme cites Wall Street Journal reporting that DeepSeek and Moonshot used thousands of fake accounts and millions of queries via overseas transfer stations, and Bloomberg reports Moonshot routed thousands of user requests through Claude and republished the responses.
Evidence
Anthropic alleges Chinese AI labs secretly used millions of Claude exchanges to train their models.
CNBC AI · attributed
CNBC reports that Anthropic alleges Chinese AI labs secretly used millions of Claude exchanges to train their models.
Anthropic disrupted Russian and Chinese AI campaigns targeting its Claude models.
Reuters AI · attributed
Reuters separately reports Anthropic disrupted Russian and Chinese AI campaigns targeting Claude.
DeepSeek and Moonshot used thousands of fake accounts and millions of real user queries routed through overseas transfer stations.
Techmeme · attributed
Anthropic says DeepSeek and Moonshot used thousands of fake accounts and millions of real user queries in 'distillation' effort to clone its AI capabilities
Moonshot covertly routed thousands of user requests to Claude and passed off responses as its own.
Bloomberg Technology · attributed
Anthropic PBC accused China's artificial intelligence champion Moonshot AI of covertly routing thousands of user requests to the US firm's Claude models and passing off the responses as its own in a bid to gain an edge in the AI race.
Anthropic published a threat intelligence report on disrupted misuse of Claude.
Techmeme · attributed
Anthropic publishes a threat intelligence report on how it disrupted efforts to misuse Claude for cyberattacks, influence operations, surveillance, and more
Why it matters
Anthropic's parallel disclosure of campaign disruption and a threat intelligence report marks frontier labs as active defenders against state-linked model misuse, not passive API vendors.
Limits and uncertainties
The excerpt lacks technical specifics on how the scraping was detected, whether it involved adversarial prompting, or if Anthropic can prove the data was actually used in training.
The Reuters excerpt is generic Google News boilerplate, lacking specific details on the campaigns' methods, scale, or Anthropic's detection mechanisms.
Practical implications
Builders and operators must now assume API outputs are a high-value target for extraction, necessitating stronger rate limiting, output watermarking, and adversarial robustness testing.
Builders and researchers must now assume that API usage patterns are actively monitored for distillation signatures, making stealthy capability extraction increasingly risky and detectable.
What to watch
Whether Anthropic pursues legal or diplomatic follow-up after naming DeepSeek and Moonshot
Independent verification of whether alleged Claude exchanges were incorporated into competing model training