US agencies and Anthropic accuse Chinese AI firms of industrial-scale model distillation

This digest was compiled by AI from multiple sources — links to the originals are below.
US cybersecurity agencies and Anthropic have accused Chinese AI companies of distilling American models at industrial scale, including over 151 million requests to Claude from Alibaba between May and July 2026. The campaigns, which also targeted GPT, Gemini, and Grok, involved billions of tokens and millions of queries. Anthropic detailed seven such operations against Claude, with Moonshot AI and DeepSeek redirecting user queries to the model without disclosure.
Key Facts
- CISA, NSA, and FBI stated that Chinese AI companies have been distilling American models at industrial scale since at least late 2024.
- Alibaba sent more than 151 million requests to Claude Opus 4.6 and 4.7 from May to July 2026, peaking at nearly 3 million requests per day.
- Moonshot AI redirected over 23 million user queries to Claude between May and July 2026, while DeepSeek sent more than 12.1 million requests in 14 days in July.
- Anthropic identified seven Chinese laboratories conducting unauthorized distillation of Claude since February 2026.
- The campaigns used over 3,500 fake accounts, stolen API keys, and proxy services to hide request origins and bypass restrictions.
The Accusations
CISA, NSA, and FBI said Chinese AI companies are distilling American models at industrial scale to train their own systems. The agencies named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as companies using the technique without permission. The campaigns have been running since at least late 2024 and likely operate with the knowledge of Chinese authorities, according to the agencies. Distillation, a standard training method where a stronger model teaches a smaller one, is being used as a core strategy in Chinese model development, researchers said.
Anthropic's Findings
Anthropic disclosed details of seven campaigns targeting Claude, the largest linked to Alibaba. Alibaba sent more than 151 million requests to Claude Opus 4.6 and 4.7 from May to July 2026, peaking at nearly 3 million requests per day. The operation used over 3,500 fake accounts, and the collected reasoning chains were used to train Alibaba's Qwen models. Moonshot AI and DeepSeek secretly redirected portions of their own users' queries to Claude, storing the responses for training while users believed they were interacting with Kimi or DeepSeek. Moonshot AI sent over 23 million requests to Claude from May to July 2026, and DeepSeek sent more than 12.1 million requests in just 14 days in July.
Infrastructure and Methods
Access to models was typically obtained through APIs, cloud platforms, third-party aggregators, and proxy services. Operators created thousands of fake accounts using fictitious identities, fake or stolen bank cards, and stolen API keys. This infrastructure allowed Chinese AI laboratories to hide the origin of requests and bypass restrictions.