Anthropic

Anthropic has alleged that several China-based artificial intelligence companies conducted large-scale campaigns to extract capabilities from its Claude models, with some operations also exposing sensitive user, corporate and government information to the US AI company's systems.

In its September 2026 Threat Intelligence Report, Anthropic said it had identified and disrupted unauthorised model distillation campaigns attributed with high confidence to seven China-based AI labs. The company said the operations targeted its generally available models using techniques designed to circumvent geographic restrictions and other safeguards.

Model distillation itself is a widely used AI development technique in which outputs from a more capable model are used to train another model. Anthropic's concerns centre on what it describes as "illicit distillation," where organisations allegedly accessed Claude without authorisation to reproduce some of its capabilities.

According to Anthropic, operators used proxy services, thousands of accounts created with false identities, fake or stolen payment credentials and compromised API keys to gain access to its models. Some proxy services also allegedly collected conversations between users and US AI models without those users' knowledge.

The report names companies including DeepSeek, Xiaomi and Moonshot among labs that allegedly fed conversations from their own services into Claude and subsequently used Claude's responses as training data. Anthropic said some of the relayed conversations contained names, email addresses, corporate information and other sensitive material.

In one example, Anthropic said DeepSeek-linked activity generated more than 12.1 million exchanges over a 14-day period in July 2026. The company said some relayed requests contained sensitive information from a Chinese technology company and credentials associated with a Russian government database. Anthropic also reported observing more than 400,000 exchanges attributed to Xiaomi over a 20-day period in March and April.

These findings are Anthropic's assessment based on its internal investigations. The report does not establish that every piece of sensitive information constituted a classified state secret, and the allegations should not be treated as independently proven findings about the companies named.

Anthropic said it banned accounts associated with the identified activity and introduced additional safeguards designed to detect adversarial model extraction. These include classifiers for suspicious activity, identity verification in some cases and changes intended to make Claude's internal reasoning more difficult to extract for training rival systems.

The findings highlight an emerging challenge for AI companies as frontier models become both commercial products and potential sources of training data for competitors. They also raise questions about what happens to sensitive information when prompts pass through third-party AI platforms, model routers and proxy services before reaching another provider.

Disclaimer: This article may include information derived from interviews, press releases, public statements, research, company communications and other publicly available or third-party sources. Such material may be summarised, paraphrased or contextualised for journalistic and editorial purposes. All rights in third-party content remain with their respective owners.