Key Points
ใปAccording to Anthropic’s threat intelligence report published on September 10, 2026, seven labs based in China collected Claude outputs at scale through fraudulent accounts and used them in training, and Moonshot AI and DeepSeek relayed some of their own customers’ requests to Claude while showing Claude’s answers as their own.
ใปDistillation itself is an ordinary training method, and the report says so. What is being alleged is two separate things, large-scale collection in breach of the terms of service, and the relaying of customer prompts. The Chinese government has rejected the accusations while the named companies have stayed silent.
ใปThe report adds a question to the way AI services are compared. Alongside capability and price, buyers now have to ask whether they can verify where their input is processed and whose training it feeds, and that question applies to American providers as well.
Anthropic Names Seven Chinese Labs and Says Two Relayed Customer Requests
Anthropic published a threat intelligence report on September 10, 2026 covering activity it disrupted between December 2025 and August 2026, and alleged that seven labs based in China, including Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai) and Xiaomi, obtained Claude outputs at scale through illegitimate means and used them to train their own models.
The company calls this illicit distillation. According to Anthropic’s September 2026 threat report, the activity attributable to Alibaba alone amounted to more than 151 million observed exchanges between May and July 2026, peaking at nearly 3 million exchanges in a single day.
The report also says Moonshot AI and DeepSeek forwarded a portion of the requests arriving at their own chat services to Claude and displayed Claude’s responses as their own model’s answers. Whether users were told or consented has not been independently confirmed, and Anthropic itself says it does not know whether Moonshot notified its customers.
Through that relaying, according to Anthropic, Claude received requests to analyze surveillance footage from a user which Anthropic assesses was likely affiliated with the People’s Liberation Army, internal code and valid credentials belonging to large state-owned enterprises, and valid credentials for a database held by an agency tied to the Russian Ministry of Defense.
Two days before the report, on September 8, 2026, the National Security Agency, CISA and the FBI issued a joint advisory warning that six China-based AI companies were conducting industrial-scale distillation against US AI companies, naming Claude, GPT, Gemini and Grok as targets.
A spokesperson for China’s Ministry of Commerce rejected the allegations on September 9, 2026, calling them groundless and without legal basis, and warned of countermeasures if distillation were used as a pretext to suppress Chinese companies. No comment from any of the named companies had been found as of September 13.
Anthropic chief executive Dario Amodei published a proposal on September 12, 2026 calling for companies to pace the development of AI capabilities together, through embedded third-party evaluators, shared safety standards among firms in democratic countries, and a crackdown on advanced chip sales to China and on unauthorized distillation. OpenAI chief executive Sam Altman agreed and said a stock listing in 2026 would be ill-advised, according to CNBC’s report of September 12, 2026.
Related Articles
What Distillation Moves and Where the Input Actually Went
Model distillation is a training method in which a capable teacher model answers a large volume of prompts and those exchanges are used to train a smaller student model to imitate the teacher’s behavior. Every major lab uses it internally. Anthropic’s September 2026 threat report states plainly that distillation itself is a legitimate training method.
The Two Acts Being Alleged
What the report objects to is narrower than distillation. The first act is collection at scale in breach of the terms of service, using thousands of accounts built on stolen payment cards, disposable email addresses and residential proxy networks. The second is the relaying of a service’s own customers to a competitor’s model without telling them.
These two have different victims. The first is a complaint by an American company about its own product being harvested. The second involves users in China who, if the account is accurate, were drawn into a data transfer they had no way of seeing.
The report does not quantify how much stronger the harvested material made any Chinese model. What it states is a general finding from Anthropic’s own research, that distillation can deliver significant uplift using fewer exchanges than those harvested in these campaigns. How much of Chinese AI performance comes from distillation sits outside the report’s scope.
Why the Numbers Cannot Be Lined Up Side by Side
The report gives an observed volume for each company, but the observation windows differ, so the totals are not directly comparable. The table below is assembled from the figures reported for each lab.
| Lab | Observation window (2026) | Length | Observed exchanges | Fraudulent accounts |
|---|---|---|---|---|
| Alibaba | May to July | About three months | More than 151 million, peaking near 3 million per day | More than 3,500 |
| Moonshot AI | May to July | About three months | More than 23 million | 5,380 used for customer relaying |
| DeepSeek | July | 14 days | More than 12.1 million | Not stated |
| Zhipu (Z.ai) | June to July | 17 days | More than 3.4 million | 273 |
| Xiaomi | March to April | 20 days | More than 400,000 | More than 1,500 |
All figures come from Anthropic’s threat intelligence report of September 10, 2026. Because the windows run from 14 days to three months, a larger total does not by itself mean a higher rate of collection.
Three Ways a Cheap Chinese Model Reaches a User
From the screen, a user cannot tell how an AI service is actually running. There are three broad shapes. The developer runs its own model on its own servers, or a published open-weights model is run by another company or by the user directly, or the visible service calls another company’s model behind the interface and returns that answer as its own.
According to Anthropic’s September 2026 report, Moonshot AI and DeepSeek were doing the third for some users. In one instance recorded in Anthropic’s September 2026 report, Moonshot relayed almost 300,000 customer requests to Claude over a ten-day period, the vast majority routed to Opus, and DeepSeek identified requests arriving from third-party coding environments by string matching and forwarded the selected users to Opus. Users believed they were reading answers from Kimi or DeepSeek.
Related article
How Long Do AI Moats Last? What Kimi K3 Tells Us About the Shrinking Head Start
The Order in Which the Accusations Arrived
The Anthropic report was not the opening move. The NSA, CISA and FBI advisory dated September 8, 2026 came first and named six companies, and China’s Ministry of Commerce answered it on September 9. Anthropic published on September 10, and the Amodei essay followed on September 12.
That sequence matters for reading the Chinese response. The Commerce Ministry statement of September 9 was a reply to the US government’s distillation allegation, not to the relaying allegation that had not yet been published. As of September 13, no specific answer on the relaying, on notification or on consent had been found from either the Chinese government or the named companies.
Where the Input Goes, and Who Is in a Position to Check
What leaked was less the model’s capability than the user’s input
If the report is accurate, the people harmed include the customers in China who trusted a domestic AI service with confidential material. Seen from Anthropic, this is a case of a company’s model capability being extracted. Seen from the user, it is a case of text typed into Kimi or DeepSeek arriving on an American company’s servers.
The examples in the report share a pattern. Surveillance camera archives, internal system credentials, the design of a municipal public security case management system. All of them were entered on the assumption that they stayed inside an organization.
If the relaying happened as described, the duty to disclose the transfer and obtain consent sat with the service operators. The people captured on the surveillance footage, and the organizations reachable with the exposed credentials, are affected parties alongside the person who typed the prompt.
How does relayed military and government data change the US China AI contest?
The information listed in the report points to internal organizational work rather than casual chat. Surveillance camera footage covering the surroundings of military facilities, internal code and credentials from state-owned enterprises, the design of a police case management system. If the material is genuine and sufficiently detailed, it could offer clues about who is being watched and how, and about how internal systems are built.
Beyond that point the stages have to be kept apart. An American company receiving the data, the US government obtaining it, and that government using it in diplomacy or operations are three different steps, and the report only supports the first. Nothing is known about how current the information was or whether any of it was new to the American side. There is no basis yet for saying that Chinese military planning has been laid bare.
What can be reasoned from the known facts is how the Chinese side is likely to respond. If the allegations hold up, government agencies and state-owned enterprises in China cannot protect their information simply by avoiding American products in favor of domestic ones, because the question is the actual processing route rather than the nationality of the service. Audits of domestic AI companies’ external connections, restrictions on AI use in sensitive work, and a move to dedicated environments where outbound traffic is controlled are plausible directions, not measures that have been confirmed. One possible outcome is that the same connections get narrowed from both ends, by Washington to stop its models’ capabilities from leaving and by Beijing to stop its information from leaving.
Governments and companies in third countries that use Chinese AI face the same question. If a buyer chose a Chinese service to avoid dependence on American companies and its input was being forwarded to an American company anyway, the intended position and the actual processing route did not match. The report becomes an argument for AI infrastructure a country can manage itself and for services whose processing destination can be audited. Running an open-weight model in a self-managed environment with controlled outbound traffic sits outside this problem.
Why the accusation is hard to verify from outside
The detailed traffic records behind the attribution sit with Anthropic. The company says it grouped scattered accounts into single organizations by shared patterns in account creation and network routing, then acted against them together. The assessment that one user was likely affiliated with the People’s Liberation Army is Anthropic’s own judgment, and no independent third-party verification of the observations or the attribution had been found as of September 13, 2026.
There is a precedent for the shape of this. In January 2025 the White House AI adviser David Sacks said there was substantial evidence that DeepSeek had distilled OpenAI’s models, and the evidence itself was never published. This report goes further by disclosing volumes and methods, but the accuser, the detector and the interested party are still the same company.
The joint US government advisory two days earlier is part of the same picture. It named six companies and said material had been taken from GPT, Gemini and Grok as well as Claude, so the accusation is not Anthropic’s alone. The rebuttal, meanwhile, has come from the Chinese government and not from the companies.
Does a proposal to slow down also serve an advantage?
Amodei’s September 2026 essay places safety coordination and the preservation of an American lead in one document. The structure has three stages. Embedded evaluators with employee-like access, which Anthropic commits to unilaterally. Shared safety standards and a ceiling on unchecked progress among firms in democratic countries, which the essay says needs US government mediation or a narrow antitrust waiver. Then coordination that includes authoritarian states.
The same document asks governments not to sell advanced chips or semiconductor manufacturing equipment to China, to crack down on unauthorized distillation by companies in authoritarian countries, and to prevent model weight theft. Amodei writes that executing these measures well would widen America’s lead significantly over the next three to five years.
The two halves connect through his own logic. How far democratic countries can slow down is constrained by the size of their lead over authoritarian ones, so a larger lead buys more room to pace. That is also where the distillation report supplies the evidence for one of the policy items.
Critics see a cost. Hosting embedded evaluators and meeting shared standards could weigh heavily on smaller firms depending on scope and who pays, which would tend to entrench the current leaders. David Sacks called Amodei’s approach regulatory capture in August 2026, telling Fortune’s reporting that a licensing body would become a DMV for AI with models queuing for approval. The opposite reading also exists, that the constraints fall hardest on whoever is in front.
Related article
When the Safety Test Becomes the Breach: How OpenAI and Anthropic Agents Reached Real Companies
Who is supposed to do the checking?
Third-party evaluation of safety practice and detection of distillation are different jobs. The evaluators Amodei proposes would sit inside AI companies and verify safety commitments and training processes. Detecting who took how much from where, which is what this report did, is currently done by the company receiving the traffic, and nothing in the proposal puts an independent party on that task.
The essay does include international steps, an agreement banning clearly dangerous uses, pre-release testing through a standards body, and a speed limit on recursive self-improvement for which Amodei invokes the SALT treaties rather than the nuclear non-proliferation framework. What remains unresolved is the authority of any inspector and the treatment of models that are never submitted for testing.
In nuclear non-proliferation, the International Atomic Energy Agency verifies through inspection that fissile material has not been diverted from peaceful use. That works because there is material and there are facilities to measure. In AI it is not settled whether the measurable quantity is compute, capability or training process, and outputs cross borders without any facility at all. This report is a demonstration of that difficulty rather than a solution to it.
What can a buyer outside the United States and China actually check?
For governments and companies procuring AI, the practical question is not which country’s model to pick but how to verify where input is processed. Running open-weights models inside a controlled environment makes the traffic auditable, at the cost of compute, operations and a narrower ceiling on capability for some tasks. Buying a cloud service shifts the question to contract terms, disclosure of processing locations and third-party audit.
The same test applies to American providers. US AI companies also work with governments and defense and intelligence agencies, and Anthropic’s own report says it shared intelligence with authorities and industry partners where appropriate, without specifying what was shared or in which cases.
For Japan specifically, the report contains one detail. Anthropic estimates that most of the accounts used for Moonshot’s relaying were located in Japan and Singapore. Japan appears in this story inside that estimate, and the question it leaves is how procurement contracts and audits can establish where a given prompt is processed.
Related article
Claude Fable 5 Was Pulled. The Real Story Is Who Gets Trusted With Frontier AI
Japanese Reactions to the Anthropic Distillation Report
What follows is the Japanese-language conversation on X in the days after the report, not a measure of Japanese public opinion. No survey has asked about any of this. The pattern is still worth recording, because Japanese posts diverged from the English-language ones. Where English forums argued about whether Anthropic had standing to complain, Japanese accounts mostly summarized what the documents said, and the detail that drew the most surprise was not the distillation but the relaying of user prompts.
The quoted passages are translated excerpts of each post. Posts are embedded above each translation.
The most widely shared post on the relaying came from an account that explains AI and overseas technology news.
ไธญๅฝAIใใใใฃใฆใAnthropicใฎๆๆฐใปใญใฅใชใใฃๅ ฑๅใใใชใ่กๆ็ใ
— katsu๐บ๐ฆ (@katsu0575jp2_2) September 12, 2026
ๅใซใClaudeใ่ธ็ใใฆๆง่ฝใใใฏใฃใฆใใใใจใใ่ฉฑใ ใใงใฏใชใใ
Anthropicใซใใใฐใ
โ Kimi๏ผMoonshot AI๏ผใฏใไธ้จใฆใผใถใผใฎ่ณชๅใๆฌไบบใซ็ฅใใใClaudeใธ่ปข้ใใClaudeใฎๅ็ญใKimiใฎๅ็ญใจใใฆ่กจ็คบใใฆใใใ
โกโฆ
Anthropic’s latest security report on Chinese AI is pretty shocking. This is not just a story about “distilling Claude to copy its performance.” According to Anthropic, first, Kimi (Moonshot AI) forwarded some users’ questions to Claude without telling them, and displayed Claude’s answers as Kimi’s own. Second, DeepSeek likewise forwarded some requests to Claude Opus, extracted even Claude’s reasoning process, and used it to train its own AI. Third, as a result, sensitive information that users entered believing it was “processed only inside a Chinese AI” was sent to Anthropic’s side. More than a “copying” problem for AI models, this is a serious information security problem.
katsu, September 12, 2026 (excerpt, translated by Sekahan)
An AI researcher’s account had reached the same detail the day after the report appeared, and by the view counter shown on X on September 13, 2026 that post had drawn more than 270,000 views.
Anthropicใ่ช็คพAIใซ้ขใใ่ ๅจใคใณใใชใธใงใณในใฌใใผใใๅ ฌ้ใใใฎใงใใใใใชใๅใพใใใใจใๆธใใใฆใใพใใ
— ไปไบ็ฟๅคช / Shota Imai (@ImAI_Eruel) September 10, 2026
ๅๅฝใฎ่ปไบๅฉ็จใ่ธ็ใฎไบๅฎใฎใปใใ
ใไธญๅฝใฎAIใตใผใในใใๅฎใฏ่ฃใงClaudeใซไธ้จๅ ฅๅใใซใผใใฃใณใฐใใClaudeใฎๅบๅใใฆใผใถใผใซ่ฆใใๅญฆ็ฟใซใไฝฟใฃใฆใใใ
ใจใใใฎใฏไธญใ … https://t.co/bmD76gmIqk pic.twitter.com/VwglJAMCVu
Anthropic has published a threat intelligence report about its own AI, and what it describes is pretty staggering. Beyond the facts about military use by various countries and distillation, the part where “Chinese AI services were actually routing some inputs to Claude behind the scenes, showing Claude’s output to users, and using it for training as well” is really something.
Shota Imai, September 11, 2026 (translated by Sekahan)
An exaggerated version also spread, in which the Chinese models were described as nothing more than wrappers around Claude and Chinese and Russian military secrets were said to have flowed wholesale to Anthropic. The most-viewed post in the whole Japanese conversation, with more than 580,000 views by the counter shown on X on September 13, 2026, was a correction of that version rather than a discussion of the report. The report does describe customer requests being relayed, so the correction and the report do not agree on every point, and neither has been independently verified.
Coverage by Japanese media concentrated on the pacing proposal rather than the distillation report, and the line about the internet being taken over was the part that traveled.
ใขใณใฝใญใใใฏCEOใAI้็บๆธ้ใธๅ่ชฟ่จดใ ใใใใไนใฃๅใๆใใhttps://t.co/hOQCu3btNq
— ๆฅๆฌ็ตๆธๆฐ่ ้ปๅญ็๏ผๆฅ็ต้ปๅญ็๏ผ (@nikkei) September 12, 2026
Anthropic CEO calls for coordination to slow AI development, citing “fear of an internet takeover.”
Nikkei, September 13, 2026 (headline, translated by Sekahan)
The most widely shared reading of the essay itself, from a veteran executive of Japan’s internet industry, did not treat it as a competitive maneuver.
ใใใชใ้่ฆใAnthropic CEOใฎใใชใชใใๆจๆฅ๏ผ9ๆ12ๆฅ๏ผใใชใ่ธใฟ่พผใใ ่ญฆๅใๅบใใฆใใพใใ
— ๅท้ๅฅๅคช้ (@dennotai) September 13, 2026
ใพใๆฅตใใฆ้่ฆใชใฎใฏใAI่ช่บซใๆฌกไธไปฃใฎAIใไฝใ่ฝๅใๆฅ้ใซ้ซใๅงใใฆใใใใจใใๆๅ ็ซฏAIไผๆฅญใฎใใใ่ช่บซใๆ่จใใใใจใงใใ
ใใชใชใฏใใใ
ใrecursiveโฆ
The most important point is that the head of a frontier AI company has himself stated plainly that AI is rapidly getting better at building the next generation of AI. Dario calls this “recursive self-improvement” and says the movement has visibly accelerated since around this summer. And his warning is not “stop AI development.” It is that the speed of capability gains should be deliberately paced. At the same time, he also says it would be dangerous for the United States, the democracies, alone to slow down and be overtaken by China. So it is neither “AI is dangerous, so stop” nor “it is a race, so go all out.”
Kentaro Kawabe, September 13, 2026 (excerpt, translated by Sekahan)
The argument that dominated English-language forums, that safety rules are a moat built by the leaders, was almost absent in Japanese. So was any defense of the Chinese companies. What Japanese posts did carry, in place of both, was a running irony aimed at the messenger, since the company reporting the abuse of AI is also the company that built the model being abused.
Evaluating Safety and Verifying Where Input Goes Are Two Different Jobs
What the report exposed is that services chosen on capability and price were carrying user input somewhere the user could not see. One mechanism produced two different injuries, the export of prompts for users in China and the extraction of capability for an American company.
The pacing proposal published two days later puts safety coordination and the preservation of an American lead in a single document, and it does set out a concrete idea for third-party verification of safety practice. The authority to run that internationally, and the response when someone breaks the rules, are still unbuilt.
Verifying that a model is safe and verifying where a user’s prompt ends up are not the same mechanism. This report asks the second question, and for anyone buying cheap AI the question that remains is how far a contract and an audit can establish where their own input is processed.
Frequently Asked Questions
What exactly is Anthropic accusing Chinese AI companies of doing?
Two things, according to Anthropic’s threat intelligence report of September 10, 2026. First, collecting Claude outputs at industrial scale through thousands of fraudulent accounts built on stolen payment cards and proxy networks, in breach of the terms of service, and using those outputs in training. Second, in the cases of Moonshot AI and DeepSeek, relaying some of their own customers’ requests to Claude and presenting Claude’s answers as their own. Distillation as a training technique is not the accusation, and the report says so explicitly.
Is model distillation illegal?
Distillation itself is a standard training method used across the industry, and Anthropic’s September 2026 report describes it as legitimate. The conduct alleged here is different in kind, since it involves fraudulent account creation and breach of contract, and separately the forwarding of customer data to a third party. China’s Ministry of Commerce said on September 9, 2026 that distillation is a normal technical and commercial matter in the AI industry and accused the United States of politicizing it.
Has anyone independently verified the report?
Not as of September 13, 2026. The traffic records behind the attribution are held by Anthropic, and no independent third-party verification of the observations or of the attribution to specific companies had been found. The NSA, CISA and FBI made a similar accusation in their joint advisory dated September 8, 2026, so the claim does not rest on one company, but the US government has not published its underlying evidence either.
How did Japanese social media react to the Anthropic report?
Japanese posts leaned toward explanation rather than argument. The detail that spread fastest was that Kimi users had their prompts forwarded to Claude without being told, and the accounts that carried it furthest were technical explainers rather than commentators. An exaggerated version, claiming the Chinese models were simply wrappers around Claude, circulated widely and drew the single most-viewed post in the Japanese conversation, which was a correction of it. The moat argument that dominated English-language forums barely appeared, though irony aimed at Anthropic as both the reporter and the source of the abused model was common.
Sekahan on YouTube
We publish video summaries of articles like this one, along with short clips built around Japanese reactions.
Reference Links
- Threat Intelligence Report: September 2026๏ฝAnthropic
- We Must Pace the Frontier๏ฝDario Amodei
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies (AA26-251A)๏ฝCISA
- China firmly opposes U.S. groundless allegations on Chinese AI firms: commerce ministry๏ฝXinhua
- Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says๏ฝCNBC
- OpenAI rules out IPO this year as Altman, Musk & Amodei warn AI is moving too fast๏ฝCNBC
- Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek๏ฝTechCrunch
- David Sacks says Anthropic’s Dario Amodei wants a ‘DMV for AI’๏ฝFortune


