Anthropic, the San Francisco‑based AI firm behind the Claude series, has lodged a formal complaint accusing operators tied to Alibaba and its Qwen lab of running a large‑scale "distillation" operation against its Claude models. The company says the campaign, which ran from April 22 to June 5, 2026, employed almost 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude, effectively extracting model capabilities for downstream use in China[1].

The allegation was detailed in a letter to U.S. senators Tim Scott and Elizabeth Warren, underscoring the strategic risk of illicit model harvesting. Anthropic warned that the extracted data could be used to train rival models at a fraction of the cost of developing them from scratch, eroding the competitive edge of U.S. AI firms.

In a separate February filing, Anthropic identified three additional Chinese AI startups—DeepSeek, Moonshot AI and MiniMax—as having conducted similar extraction campaigns earlier in the year. DeepSeek’s operation involved over 150,000 Claude exchanges, Moonshot AI exceeded 3.4 million, and MiniMax accounted for more than 13 million interactions[2]. The company described the overall activity as "growing in intensity and sophistication" and called for coordinated industry‑government action.

The fallout reached Washington later in June, when the U.S. Commerce Department placed Anthropic’s latest Mythos and Fable models under export‑control restrictions, citing concerns that the models could be leveraged by foreign military intelligence users[3]. Anthropic responded by disabling global access to the affected models, highlighting how quickly policy can impact product availability.

For enterprise leaders, the episode raises immediate practical concerns. Organizations that integrate Claude or similar foundation models must audit usage logs for anomalous account patterns and enforce strict credential hygiene. The cost of a breach extends beyond direct theft; export controls can abruptly remove critical AI capabilities from a company’s stack, forcing costly re‑engineering or migration to alternative providers.

Strategically, the case illustrates a broader shift in AI geopolitics: the line between competitive intelligence and outright theft is blurring, and governments are beginning to treat advanced foundation models as dual‑use technologies. Companies should therefore embed threat‑intelligence sharing into their security operations and consider diversifying model portfolios to mitigate supply‑chain risk.

Sources

  1. Anthropic says Alibaba illicitly extracted Claude AI model capabilities — Reuters (2026‑06‑24) — https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/
  2. Chinese companies used Claude to improve own models, Anthropic says — Reuters (2026‑02‑23) — https://www.reuters.com/world/china/chinese-companies-used-claude-improve-own-models-anthropic-says-2026-02-23/
  3. US blocks foreign access to Anthropic’s most advanced AI models — Reuters (2026‑06‑13) — https://www.reuters.com/technology/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13/