Anthropic Accuses Alibaba of 'Industrial-Scale' AI Distillation in Letter to US Senate
Anthropic alleges that operators linked to Alibaba's Qwen lab used 25,000 fraudulent accounts to extract advanced reasoning and coding capabilities from its Claude AI model. The accusation highlights the growing geopolitical friction over "model distillation," a technique used to train cheaper AI systems on the outputs of frontier models.
By Sofia Matos
- US Frontier Labs
- View distillation as intellectual property theft that undermines billions in R&D.
- Accused International Competitors
- Deny illicit extraction and frame US actions as protectionist.
- National Security Analysts
- Focus on the geopolitical and strategic risks of capability parity.
Perspectives this story doesn't cover
- Open-Source AI Advocates
- Independent Legal Scholars
Key terms
- Model Distillation
- A machine learning technique where a smaller, cheaper 'student' AI model is trained using the outputs generated by a larger, more advanced 'teacher' model.
- Agentic Reasoning
- The ability of an AI system to independently plan, execute, and adapt to complex, multi-step tasks over a long period without human intervention.
- Frontier AI
- The most capable, state-of-the-art artificial intelligence models that push the boundaries of current technological capabilities.
Key points
- Anthropic alleges Alibaba's Qwen lab used 25,000 fake accounts to query its Claude model 28.8 million times.
- The alleged goal was "distillation," a technique used to train cheaper models on a frontier model's outputs.
- The campaign reportedly targeted Claude's advanced software engineering and agentic reasoning capabilities.
- Alibaba has denied the accusations and recently banned the internal use of Anthropic's coding tools.
- The dispute highlights a legal gray area regarding whether AI model distillation constitutes intellectual property theft.
In a significant escalation of the global artificial intelligence race, US-based Anthropic has leveled unprecedented accusations against Chinese technology conglomerate Alibaba. In a formal letter addressed to the US Senate Banking Committee, Anthropic alleges that operators affiliated with Alibaba’s Qwen AI lab orchestrated an "industrial-scale" campaign to siphon advanced capabilities from its Claude chatbot. The disclosure, directed to Committee Chair Tim Scott and Ranking Member Elizabeth Warren, elevates a corporate intellectual property dispute into a high-stakes national security issue. Anthropic describes the operation as the largest known attack of its kind, highlighting the growing friction between American frontier AI developers and international competitors racing to close the technological gap.[2]
The scale of the alleged operation is staggering. According to the letter, which covers a 44-day window between April 22 and June 5, 2026, the attackers utilized approximately 25,000 fraudulent accounts to generate more than 28.8 million interactions with Claude. These accounts were reportedly designed to mimic ordinary user traffic, allowing them to slip past standard rate limits and detection mechanisms. By operating a massive, coordinated network, the perpetrators were able to systematically extract vast amounts of data from Anthropic’s systems before the campaign was identified and halted.[2]
At the heart of the accusation is a machine learning technique known as "adversarial distillation." In standard AI development, distillation is a legitimate efficiency practice where a smaller, cheaper "student" model is trained using the outputs of a larger, more capable "teacher" model. However, Anthropic alleges that Alibaba weaponized this process. By confronting Claude with millions of carefully crafted, targeted queries, the operators could harvest the model’s responses, reasoning patterns, and generated code. This harvested data then serves as a high-quality training set for Alibaba’s own Qwen models.[1]
The economic asymmetry of model distillation makes it an incredibly potent vector for capability extraction. Developing a frontier AI model requires billions of dollars in research, massive datasets, and vast amounts of computational power. A distillation attack bypasses these immense financial and technical hurdles. The attacker does not need to steal source code, breach secure servers, or access the original model's underlying weights. By simply asking the right questions at an industrial scale, a competitor can create a usable echo of a state-of-the-art system at a fraction of the cost and time.[1]
Anthropic’s letter emphasizes that the fraudulent accounts were not engaging in basic small talk or simple question-and-answer functions. Instead, the campaign specifically targeted the most commercially valuable capabilities of Anthropic's frontier "Mythos Preview" model. The operators focused heavily on advanced software engineering and "agentic reasoning"—the ability of an AI system to independently plan, execute, and adapt to complex, multi-step tasks over long horizons. By extracting these specific capabilities, the attackers aimed to rapidly elevate the performance of their own models in high-stakes domains.[2]
The geopolitical implications of the alleged campaign are profound. Anthropic has explicitly framed the operation in national terms, arguing that such distillation efforts effectively turn hundreds of billions of dollars of American AI investment into a direct subsidy for a primary geopolitical competitor. This framing resonates strongly in Washington, where policymakers increasingly view artificial intelligence leadership as a critical component of national security and economic dominance. The accusation suggests that the fastest path to parity for foreign labs is not independent innovation, but the systematic copying of American models.[1]
The geopolitical implications of the alleged campaign are profound.
Beyond the commercial and geopolitical stakes, distillation attacks introduce severe safety vulnerabilities. When a frontier model is developed, companies spend immense resources on "alignment"—installing safety guardrails to prevent the AI from generating malicious code, offering bioweapon guidance, or executing offensive cyber operations. However, an illicitly distilled student model inherits the raw capabilities and reasoning power of the teacher model without inheriting its safety filters. This dynamic creates a scenario where highly capable, unrestricted AI systems could be deployed globally without the safeguards engineered by their original creators.
Alibaba has firmly pushed back against the allegations. The Chinese tech giant has denied any wrongdoing, rejected claims of military affiliation, and filed a lawsuit challenging its designation in related security contexts, calling the accusations devoid of any factual or legal basis. The company maintains that its Qwen models are the product of independent research and development, and it has not publicly addressed the specific metrics regarding the 28.8 million interactions cited in Anthropic’s letter.
The dispute has already triggered internal fallout at Alibaba. In a direct response to the escalating conflict, Alibaba issued an internal notice banning its employees from using Anthropic’s "Claude Code" AI tool, effective July 10, 2026. The company cited security vulnerabilities, claiming the software carried "back-door risks," and recommended that staff transition to Qoder, Alibaba's proprietary coding agent platform. The internal ban underscores the rapid decoupling of AI toolchains between American and Chinese technology ecosystems.
This is not the first time Anthropic has raised alarms about industrial-scale capability extraction. In February 2026, the company publicly accused three smaller Chinese AI labs—DeepSeek, Moonshot AI, and MiniMax—of conducting similar distillation campaigns. At the time, Anthropic reported that those operations involved millions of interactions, but the volume now attributed to Alibaba significantly dwarfs those earlier cases. The company has warned that these extraction efforts are growing rapidly in both intensity and sophistication.
The allegations arrive amid a flurry of parallel actions by the US government aimed at protecting domestic AI assets. In April 2026, the White House Office of Science and Technology Policy issued a memorandum directing federal agencies to crack down on the exploitation of US AI models through proxy accounts. More recently, the Commerce Department placed temporary export controls on Anthropic’s Fable 5 and Mythos 5 models in June, suspending global access following the discovery of vulnerabilities, before lifting the restrictions on June 30.
Legislative momentum is also building in response to the distillation threat. In the wake of Anthropic’s disclosure, US Senators Bill Hagerty and Andy Kim announced plans to introduce an amendment to a must-pass defense bill. The proposed legislation would explicitly sanction Chinese firms found to be improperly accessing and utilizing the outputs of American AI models. A related bipartisan bill is currently under consideration in the House of Representatives, signaling a unified congressional push to address the loophole.
Despite the intense scrutiny, model distillation currently exists in a murky legal vacuum. While the practice of querying a model to train a competitor violates the terms of service of companies like Anthropic and OpenAI, there is no settled intellectual property law that explicitly classifies the automated harvesting of AI outputs as theft. This lack of clear legal precedent complicates enforcement efforts and leaves frontier labs relying on technical countermeasures and government intervention rather than traditional copyright litigation.[1]
The Alibaba dispute highlights a fundamental shift in the nature of technological espionage. As frontier AI models are increasingly deployed via public APIs to serve global customer bases, they inherently expose their capabilities to the world. The battleground has moved from traditional cyberattacks targeting source code and server infrastructure to the automated, systematic extraction of model behavior. For the AI industry, the incident underscores the immense challenge of commercializing state-of-the-art systems while simultaneously protecting them from adversaries armed with millions of fake accounts.[1]
Why this matters
As artificial intelligence becomes a central pillar of national security and economic dominance, the methods used to train these models are under intense scrutiny. This dispute exposes the vulnerabilities of frontier AI systems to "distillation"—a practice that allows competitors to bypass billions of dollars in research costs by simply copying a leading model's homework.
Sources
[1]The Washington PostNational Security AnalystsAnthropic says Alibaba copied its AI on an industrial scale
Read on The Washington Post →
[2]Inc. MagazineUS Frontier LabsAnthropic Accuses Alibaba of 'Largest Known' AI Distillation Attack
Read on Inc. Magazine →
Comments
More in Artificial Intelligence
See all →AI Infrastructure
How FlashAttention Bypasses the GPU Memory Bottleneck to Enable Long-Context AI
5 sources
Open Source Standards
How the Open Source Initiative's 1.0 Definition Excludes the Most Downloaded Open-Weight AI Models
7 sources
Generative Adversarial Networks
How a Generator and a Discriminator Compete to Create Realistic AI Output
8 sources
Machine Learning
How Generative AI Maps the Joint Probability Distribution of Data
5 sources
Every angle. Every day.
Get Artificial Intelligence stories with full source coverage and perspective breakdowns delivered to your inbox.




