business 5 min read

Alibaba Used 150M Claude Queries to Train Its AI — Anthropic Calls It Theft

Anthropic has published its most detailed evidence yet of Chinese companies siphoning Claude's outputs for model training — including Alibaba's use of 15,000 fraudulent accounts to generate 151 million interactions in a single quarter. The disclosure raises urgent questions about export controls and the future of frontier-model access.

  • Anthropic
  • China AI
  • AI & Security
  • Export Controls
  • AI Distillation

A Report That Changes the Conversation

Anthropic did not just accuse Alibaba of siphoning Claude — it produced a 154-page dossier. The document, released on October 10 under the title “AI Misuse Detection and Response,” is the most detailed public accounting yet of what the U.S. government has been calling “industrial-scale malicious distillation” by Chinese actors.

The central finding: between May and July of this year, operators linked to Alibaba used more than 3,500 fraudulent accounts to generate over 151 million interactions with Claude. On peak days, that figure reached roughly 3 million queries. The purpose was not casual exploration. Anthropic says the output was used to reverse-engineer Claude’s reasoning process, then converted into supervised training data for Alibaba’s Qwen 3.5, 3.6, and 3.7 models.

In other words, Claude was turned into a factory floor for a rival product.

What Distillation Actually Looks Like at Scale

Distillation itself is a standard technique in machine learning. A large “teacher” model generates responses to a wide range of prompts; those responses then train a smaller, cheaper “student” model to approximate the teacher’s behavior. The process is legitimate when done with permission — it is how OpenAI, Google, and others have built faster, leaner versions of their own flagship models.

Anthropic’s point is that the Chinese campaigns described in the report were unauthorized and covert. The company says it detected and blocked seven research institutes based in China during the reporting period. The scale, however, is what makes this case distinctive.

Alibaba is not the only actor. Anthropic estimates that Moonshot AI, the company behind the Kimi chatbot, routed more than 23 million user interactions through Claude between May and July — despite telling users they were querying Kimi directly. DeepSeek accounted for over 12.1 million such interactions. Xiaomi, Zhipu AI, SenseTime, and MiniMax were also flagged for similar practices.

These numbers are staggering because they reveal a systematic approach rather than opportunistic scraping. The query volumes alone suggest dedicated infrastructure: bot farms, account rotation, and automated prompt pipelines designed to extract as much high-quality reasoning data as possible before detection kicked in.

The Data Problem Is Bigger Than Model Weights

Perhaps the most alarming detail in Anthropic’s report is not that these companies were distilling Claude — it is what else flowed through the pipeline.

Anthropic claims that interactions handled by DeepSeek and CCTV (Chengdu Fixed-Loop Television) contained sensitive Chinese state data, including surveillance system information and internal code from state-owned enterprises. Xiaomi’s extracted data reportedly included personal names, contact information, and corporate details. Some users connected to entities believed to be linked to the Chinese military were identified in the dataset.

This is a double violation. On one hand, it represents the unauthorized extraction of Anthropic’s proprietary capabilities. On the other, it suggests that Claude was being used as an inadvertent conduit for sensitive Chinese institutional data — information that may have been submitted by unwitting or careless users who assumed they were talking to a domestic model.

For Western companies operating AI systems globally, this raises a troubling question: how much proprietary training data, safety alignment, and reasoning capability are being passively harvested by foreign competitors who simply route user queries through a frontier model they do not own?

The U.S. Government Was Already Speaking in Circumlocutions

Prior to Anthropic’s disclosure, the NSA, FBI, and CISA had issued a joint cyber alert describing Chinese AI firms engaging in “industrial-scale malicious distillation” of American models. But that advisory stopped short of naming specific companies or publishing concrete data. It was a warning shaped by diplomatic caution.

Anthropic’s report removes the ambiguity. It supplies the case studies, the account counts, the query volumes, and the model names involved. The effect is to convert a generalized security concern into a documented commercial intelligence operation — one conducted at a scale that rivalries over semiconductor exports alone cannot address.

China’s Ministry of Commerce responded immediately, characterizing distillation as a neutral and routine technology used across the global AI industry and accusing the United States of politicizing technical disputes to suppress Chinese industry. The framing is familiar, but the specifics in Anthropic’s report make it harder to dismiss as mere rhetoric. The question now is whether the U.S. will treat frontier-model access as a controlled commodity in the same way it has treated advanced chips.

What Happens Next

The most likely immediate impact is on how American AI companies structure their API terms and access controls. Anthropic has already implemented blocking measures for the detected campaigns, but the report implies that the techniques used — account rotation, proxy routing, user-facing obfuscation — are replicable. Defending against them requires continuous investment in detection infrastructure, which raises costs for everyone.

More broadly, the disclosure could accelerate moves within the U.S. government to treat access to frontier models as an export-control issue. The current regime governs the sale of hardware — GPUs, interconnects, chiplets. What Anthropic’s report effectively argues is that the software layer matters just as much: if a Chinese company can generate 150 million distilled training samples from a U.S. model in a single quarter, restricting chip sales becomes only part of the strategy.

For Alibaba and the other companies named, the report creates reputational risk even as it confirms that their distillation campaigns yielded tangible results — Qwen 3.7 exists, and Anthropic is explicitly linking its capabilities to data extracted from Claude. Whether U.S. regulators act on that linkage remains to be seen.

What is clear is that the boundary between open research and competitive extraction has blurred in a way that neither side fully anticipated. Anthropic is now publishing its security findings as public documents. That itself is a strategic choice — it signals to the market that the company will no longer treat these incidents as private grievances but as matters of record.

The 150 million queries are a number. The report behind them is a precedent.