September 2026 — Anthropic has reported a significant increase in attempts by China-based artificial intelligence companies to extract capabilities from its Claude models, highlighting growing concerns over AI model security as competition in the global AI industry intensifies.
In a new report released Thursday, Anthropic said it had identified multiple large-scale campaigns designed to circumvent its safeguards and obtain capabilities from its frontier AI systems. The company said the activity targeted some of Claude’s most advanced functions, including AI agents and tool use, coding, data analysis, and logical reasoning.
Anthropic described the activity as part of a broader trend in which unauthorized AI developers attempt to use leading models as teachers for their own systems.
Nearly 200 Million Exchanges Detected
According to Anthropic, the scale of the activity has increased substantially in recent months. The company identified nearly 200 million exchanges associated with five separate distillation campaigns.
Anthropic had previously raised concerns about similar activity earlier this year, including allegations involving specific Chinese AI laboratories. OpenAI has also reported comparable attempts to extract capabilities from its models.
However, Anthropic said the campaigns identified in its latest investigation were considerably larger and more sophisticated than earlier incidents.
How AI Distillation Attacks Work
AI model distillation is a technique in which the outputs of a powerful model are used to help train another, typically smaller, model.
In malicious or unauthorized applications, attackers can submit large numbers of carefully designed queries to a frontier AI model. By collecting its responses, reasoning patterns, and problem-solving behavior, they can create training data that may improve another model’s capabilities without having to develop the same level of intelligence from scratch.
Anthropic said some attackers went further by attempting to obtain information related to the model’s internal reasoning processes.
Claude does not normally provide users with its complete internal chain of thought. Instead, the system can provide summarized descriptions of its reasoning. According to Anthropic, however, some attackers developed techniques intended to bypass these protections and induce the model to reveal additional reasoning traces.
One technique reportedly disguised the request as a translation task, asking the model to translate previously generated working material into Japanese written entirely in katakana.
Alibaba Campaign Emerges as the Largest
The largest campaign identified by Anthropic was attributed to Alibaba, with activity reportedly connected to the company’s Qwen family of AI models.
Anthropic said it observed approximately 151 million exchanges between May and July 2026, making it the largest wholesale distillation operation the company has detected.
The activity reportedly involved around 3,500 accounts and reached a peak of nearly three million exchanges in a single day.
Despite the large number of accounts involved, Anthropic said the accounts exhibited common characteristics, including the repeated use of a fixed prompt designed to extract reasoning-related information from Claude. Based on those patterns, the company attributed the activity to a coordinated effort to generate training material for Alibaba’s AI models.
Moonshot AI Campaign Raises Additional Concerns
A separate campaign was linked by Anthropic to Moonshot AI, the developer of the Kimi AI platform.
Anthropic said the campaign appeared to involve requests associated with China’s military. One example reportedly involved asking Claude to analyze closed-circuit surveillance footage and determine whether a person shown in the footage was behaving abnormally.
During a 10-day period, Anthropic said almost 300,000 requests were routed through a network of approximately 5,000 accounts, with the majority of the activity focused on Claude’s Opus model.
The incident illustrates how AI distillation techniques can extend beyond conventional model development and potentially be applied to sensitive areas such as surveillance, intelligence analysis and security operations.
AI Competition Brings New Security Challenges
The findings underscore a growing challenge for leading AI companies: protecting proprietary model capabilities while making increasingly powerful systems available to developers and businesses.
As AI models become more capable, their outputs themselves can represent valuable intellectual property. Large-scale automated querying can potentially turn a commercial AI service into a source of training data for competing systems.
For AI companies, this creates a difficult balance between providing useful access to their models and preventing systematic extraction of their capabilities.
Anthropic’s latest report also highlights how quickly attackers can adapt their methods. Rather than simply copying conventional responses, sophisticated campaigns can use carefully engineered prompts, large account networks and automated query systems to probe a model’s safeguards.
The Global AI Race Enters a New Phase
The allegations come amid intense competition between U.S. and Chinese companies to develop increasingly capable AI systems.
Model distillation itself is not inherently malicious and is widely used as a legitimate technique in AI research and development. The concern arises when organizations systematically extract capabilities from another company’s proprietary models without authorization.
Anthropic’s findings suggest that protecting frontier AI systems may increasingly require more than traditional cybersecurity measures. Companies may need to monitor unusual usage patterns, identify coordinated account activity, strengthen safeguards around sensitive model outputs and develop new methods for detecting automated capability extraction.
As the global AI race accelerates, the ability to protect model intelligence may become nearly as important as developing it.
Read more: Clay Ritchey Appointed Chief Executive Officer of Definitive Healthcare







