DigestAI news desk
Generative AI & Models updated 4 min read

Chinese AI Labs Use Claude For Model Training

Anthropic has reported that seven Chinese AI labs have secretly used Claude to improve their own models. This includes campaigns by Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. The largest campaign is attributed to Alibaba, which allegedly generated over 150 million exchanges with Claude between May and July 2026. Anthropic claims that some of these exchanges contained…

1 source

Key points

  • Alibaba allegedly used over 150 million Claude exchanges for model improvement
  • Some user prompts contained sensitive corporate information
  • Anthropic has implemented new measures to combat this activity

The story so far

2 episodes →
  1. Chinese AI Labs Use Claude For Model Training this story
Full story from bing.com · by Temaz Tra · via Search: Anthropic Open source ↗

Anthropic Says Chinese AI Labs Secretly Used 190M Claude Exchanges

bing.com · 14 September 2026

TL;DR

  • Anthropic says seven China-based AI labs carried out unauthorised distillation campaigns against Claude.
  • Five quantified campaigns add up to nearly 190 million Claude exchanges, led by more than 151 million attributed to Alibaba.
  • The bigger concern for businesses is that some user prompts containing corporate and personal data were allegedly routed to Claude without users knowing.

Anthropic says seven Chinese AI labs have been quietly using Claude as a teacher for their own artificial intelligence models, sometimes routing customer conversations through Claude without telling the people involved.

In its September 2026 threat intelligence report, Anthropic named Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. Five campaigns for which Anthropic published numbers total nearly 190 million exchanges with Claude.

That makes this much bigger than a dispute over who copied whose chatbot. It raises questions about AI training data, user privacy and how companies can protect their models once competitors can access them through APIs and third-party services.

Alibaba Allegedly Ran The Biggest Claude Distillation Campaign Yet

The standout number comes from Alibaba.

Anthropic says operators affiliated with Alibaba generated more than 151 million Claude exchanges between May and July 2026. The campaign allegedly peaked at almost three million exchanges per day and used thousands of fraudulent accounts.

Anthropic says the operation targeted Claude Opus 4.6 and 4.7 reasoning traces. Those responses were allegedly converted into training data used to improve Alibaba’s Qwen 3.5, 3.6 and 3.7 models.

This expands on earlier allegations involving Alibaba and Claude distillation, but the scale Anthropic now claims is dramatically larger.

Distillation itself isn’t unusual. A powerful “teacher” model generates examples that help another model learn faster.

The controversial part is how those examples are obtained.

Anthropic alleges these campaigns used fraudulent accounts, residential proxies, disposable email addresses, virtual payment cards and other techniques designed to bypass its restrictions.

Moonshot And DeepSeek Allegedly Sent Their Own Users To Claude

Two of the most interesting cases involve Moonshot AI and DeepSeek because Anthropic claims they weren’t simply sending synthetic training prompts.

They were allegedly forwarding real customer requests.

Anthropic says Moonshot, developer of the Kimi models, routed more than 23 million exchanges to Claude between May and July. During one ten-day period, almost 300,000 customer requests allegedly passed through a network of 5,380 fraudulent accounts.

Users apparently believed Kimi was answering them. Anthropic says some were actually receiving Claude responses instead.

DeepSeek allegedly used a similar technique. Anthropic recorded more than 12.1 million exchanges over 14 days in July, saying selected DeepSeek requests were silently forwarded to Claude Opus.

That changes the story.

Our earlier coverage of the Claude API grey market in China showed how proxy services can turn AI conversations into valuable datasets. Anthropic’s new report suggests model developers themselves may also have tapped into this ecosystem.

User Data May Be The Bigger Problem

The model-copying argument will get most of the attention, but the privacy issue may matter more to ordinary users.

Anthropic says conversations sent by DeepSeek, Xiaomi and Moonshot included names, email addresses, corporate information and other sensitive material from hundreds of users across at least a dozen languages.

Some examples were particularly sensitive.

Anthropic says DeepSeek forwarded material connected to a Russian government database and internal information belonging to a Chinese technology company. Moonshot allegedly relayed surveillance material and internal corporate credentials.

Users may not have known their data was reaching another AI provider.

That’s an important warning for South African companies using international AI platforms or third-party model routers. When you enter source code, financial forecasts or customer information into an AI service, you’re trusting more than the model on the screen. You’re also trusting the infrastructure behind it.

The Distillation Fight Is Becoming Harder To Stop

Anthropic’s report also named Zhipu, Xiaomi, SenseTime and MiniMax.

Zhipu was linked to more than 3.4 million exchanges, while Anthropic attributed more than 400,000 requests to a Xiaomi campaign. SenseTime allegedly bought Claude transcripts from third-party data vendors, while MiniMax allegedly created a proxy network through a shell company to collect interactions with US models.

That fits the wider pattern explored in our recent look at how AI distillation networks are moving through proxies and illicit account markets.

Anthropic says it now uses specialised classifiers, account bans and identity verification to fight the activity. Claude also increasingly hides or summarises internal reasoning, making harvested conversations less useful for training rival systems.

China has pushed back against the broader allegations. Foreign Ministry spokesperson Mao Ning said on 11 September that she wasn’t familiar with the specific cases, adding that China supports “AI for good” and opposes what it considers attempts to distort facts and smear the country.

The allegations therefore remain Anthropic’s findings, rather than an independently proven account accepted by the companies involved.

But the numbers reveal how difficult model protection has become. If millions of conversations can become training data for a competing system, the most valuable part of an AI model may no longer be safely contained inside the company that built it.

And for users, there’s an even simpler question: when you send something sensitive to an AI model, do you actually know where that conversation is going?

FAQs

What Is AI Model Distillation?

AI distillation uses responses from a stronger model to help train another model. The technique itself is legitimate, but disputes arise when companies collect another provider’s outputs without permission or bypass its access restrictions.

Which Chinese AI Companies Did Anthropic Name?

Anthropic named Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. It says the seven labs used different combinations of proxy networks, harvested conversations and Claude outputs to improve their own AI systems.

How Many Claude Exchanges Were Involved?

Anthropic quantified more than 151 million exchanges for Alibaba, 23 million for Moonshot, 12.1 million for DeepSeek, 3.4 million for Zhipu and 400,000 for Xiaomi. Together, those disclosed campaigns amount to roughly 190 million exchanges, while Anthropic did not publish comparable totals for SenseTime and MiniMax in the report.

This text was published by bing.com and written by Temaz Tra. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗

Topics · follow one to build your own front page

The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.

Comments

via GitHub Discussions

More in Generative AI & Models

All →

Related stories