Skip to main content
AI GeopoliticsIP Dispute· 6 min read· in Artificial Intelligence

Anthropic Accuses Alibaba of 'Industrial-Scale' AI Distillation in Letter to US Senate

Anthropic alleges that operators linked to Alibaba's Qwen lab used 25,000 fraudulent accounts to extract advanced reasoning and coding capabilities from its Claude AI model. The accusation highlights the growing geopolitical friction over "model distillation," a technique used to train cheaper AI systems on the outputs of frontier models.

By Sofia Matos

US Frontier Labs 40%Accused International Competitors 30%National Security Analysts 30%
US Frontier Labs
View distillation as intellectual property theft that undermines billions in R&D.
Accused International Competitors
Deny illicit extraction and frame US actions as protectionist.
National Security Analysts
Focus on the geopolitical and strategic risks of capability parity.

Perspectives this story doesn't cover

  • Open-Source AI Advocates
  • Independent Legal Scholars

Key terms

Model Distillation
A machine learning technique where a smaller, cheaper 'student' AI model is trained using the outputs generated by a larger, more advanced 'teacher' model.
Agentic Reasoning
The ability of an AI system to independently plan, execute, and adapt to complex, multi-step tasks over a long period without human intervention.
Frontier AI
The most capable, state-of-the-art artificial intelligence models that push the boundaries of current technological capabilities.

Key points

  • Anthropic alleges Alibaba's Qwen lab used 25,000 fake accounts to query its Claude model 28.8 million times.
  • The alleged goal was "distillation," a technique used to train cheaper models on a frontier model's outputs.
  • The campaign reportedly targeted Claude's advanced software engineering and agentic reasoning capabilities.
  • Alibaba has denied the accusations and recently banned the internal use of Anthropic's coding tools.
  • The dispute highlights a legal gray area regarding whether AI model distillation constitutes intellectual property theft.

In a significant escalation of the global artificial intelligence race, US-based Anthropic has leveled unprecedented accusations against Chinese technology conglomerate Alibaba. In a formal letter addressed to the US Senate Banking Committee, Anthropic alleges that operators affiliated with Alibaba’s Qwen AI lab orchestrated an "industrial-scale" campaign to siphon advanced capabilities from its Claude chatbot. The disclosure, directed to Committee Chair Tim Scott and Ranking Member Elizabeth Warren, elevates a corporate intellectual property dispute into a high-stakes national security issue. Anthropic describes the operation as the largest known attack of its kind, highlighting the growing friction between American frontier AI developers and international competitors racing to close the technological gap.[2]

The scale of the alleged operation is staggering. According to the letter, which covers a 44-day window between April 22 and June 5, 2026, the attackers utilized approximately 25,000 fraudulent accounts to generate more than 28.8 million interactions with Claude. These accounts were reportedly designed to mimic ordinary user traffic, allowing them to slip past standard rate limits and detection mechanisms. By operating a massive, coordinated network, the perpetrators were able to systematically extract vast amounts of data from Anthropic’s systems before the campaign was identified and halted.[2]

At the heart of the accusation is a machine learning technique known as "adversarial distillation." In standard AI development, distillation is a legitimate efficiency practice where a smaller, cheaper "student" model is trained using the outputs of a larger, more capable "teacher" model. However, Anthropic alleges that Alibaba weaponized this process. By confronting Claude with millions of carefully crafted, targeted queries, the operators could harvest the model’s responses, reasoning patterns, and generated code. This harvested data then serves as a high-quality training set for Alibaba’s own Qwen models.[1]

The scale of the alleged capability extraction campaign targeting Claude.

The economic asymmetry of model distillation makes it an incredibly potent vector for capability extraction. Developing a frontier AI model requires billions of dollars in research, massive datasets, and vast amounts of computational power. A distillation attack bypasses these immense financial and technical hurdles. The attacker does not need to steal source code, breach secure servers, or access the original model's underlying weights. By simply asking the right questions at an industrial scale, a competitor can create a usable echo of a state-of-the-art system at a fraction of the cost and time.[1]

Anthropic’s letter emphasizes that the fraudulent accounts were not engaging in basic small talk or simple question-and-answer functions. Instead, the campaign specifically targeted the most commercially valuable capabilities of Anthropic's frontier "Mythos Preview" model. The operators focused heavily on advanced software engineering and "agentic reasoning"—the ability of an AI system to independently plan, execute, and adapt to complex, multi-step tasks over long horizons. By extracting these specific capabilities, the attackers aimed to rapidly elevate the performance of their own models in high-stakes domains.[2]

The geopolitical implications of the alleged campaign are profound. Anthropic has explicitly framed the operation in national terms, arguing that such distillation efforts effectively turn hundreds of billions of dollars of American AI investment into a direct subsidy for a primary geopolitical competitor. This framing resonates strongly in Washington, where policymakers increasingly view artificial intelligence leadership as a critical component of national security and economic dominance. The accusation suggests that the fastest path to parity for foreign labs is not independent innovation, but the systematic copying of American models.[1]

The geopolitical implications of the alleged campaign are profound.

Beyond the commercial and geopolitical stakes, distillation attacks introduce severe safety vulnerabilities. When a frontier model is developed, companies spend immense resources on "alignment"—installing safety guardrails to prevent the AI from generating malicious code, offering bioweapon guidance, or executing offensive cyber operations. However, an illicitly distilled student model inherits the raw capabilities and reasoning power of the teacher model without inheriting its safety filters. This dynamic creates a scenario where highly capable, unrestricted AI systems could be deployed globally without the safeguards engineered by their original creators.

How adversarial distillation extracts capabilities from frontier AI models.

Alibaba has firmly pushed back against the allegations. The Chinese tech giant has denied any wrongdoing, rejected claims of military affiliation, and filed a lawsuit challenging its designation in related security contexts, calling the accusations devoid of any factual or legal basis. The company maintains that its Qwen models are the product of independent research and development, and it has not publicly addressed the specific metrics regarding the 28.8 million interactions cited in Anthropic’s letter.

The dispute has already triggered internal fallout at Alibaba. In a direct response to the escalating conflict, Alibaba issued an internal notice banning its employees from using Anthropic’s "Claude Code" AI tool, effective July 10, 2026. The company cited security vulnerabilities, claiming the software carried "back-door risks," and recommended that staff transition to Qoder, Alibaba's proprietary coding agent platform. The internal ban underscores the rapid decoupling of AI toolchains between American and Chinese technology ecosystems.

This is not the first time Anthropic has raised alarms about industrial-scale capability extraction. In February 2026, the company publicly accused three smaller Chinese AI labs—DeepSeek, Moonshot AI, and MiniMax—of conducting similar distillation campaigns. At the time, Anthropic reported that those operations involved millions of interactions, but the volume now attributed to Alibaba significantly dwarfs those earlier cases. The company has warned that these extraction efforts are growing rapidly in both intensity and sophistication.

The allegations arrive amid a flurry of parallel actions by the US government aimed at protecting domestic AI assets. In April 2026, the White House Office of Science and Technology Policy issued a memorandum directing federal agencies to crack down on the exploitation of US AI models through proxy accounts. More recently, the Commerce Department placed temporary export controls on Anthropic’s Fable 5 and Mythos 5 models in June, suspending global access following the discovery of vulnerabilities, before lifting the restrictions on June 30.

Frontier AI labs are struggling to protect their models from automated capability extraction.

Legislative momentum is also building in response to the distillation threat. In the wake of Anthropic’s disclosure, US Senators Bill Hagerty and Andy Kim announced plans to introduce an amendment to a must-pass defense bill. The proposed legislation would explicitly sanction Chinese firms found to be improperly accessing and utilizing the outputs of American AI models. A related bipartisan bill is currently under consideration in the House of Representatives, signaling a unified congressional push to address the loophole.

Despite the intense scrutiny, model distillation currently exists in a murky legal vacuum. While the practice of querying a model to train a competitor violates the terms of service of companies like Anthropic and OpenAI, there is no settled intellectual property law that explicitly classifies the automated harvesting of AI outputs as theft. This lack of clear legal precedent complicates enforcement efforts and leaves frontier labs relying on technical countermeasures and government intervention rather than traditional copyright litigation.[1]

The Alibaba dispute highlights a fundamental shift in the nature of technological espionage. As frontier AI models are increasingly deployed via public APIs to serve global customer bases, they inherently expose their capabilities to the world. The battleground has moved from traditional cyberattacks targeting source code and server infrastructure to the automated, systematic extraction of model behavior. For the AI industry, the incident underscores the immense challenge of commercializing state-of-the-art systems while simultaneously protecting them from adversaries armed with millions of fake accounts.[1]

Why this matters

As artificial intelligence becomes a central pillar of national security and economic dominance, the methods used to train these models are under intense scrutiny. This dispute exposes the vulnerabilities of frontier AI systems to "distillation"—a practice that allows competitors to bypass billions of dollars in research costs by simply copying a leading model's homework.

Sources

Source coverage

2 outlets

3 viewpoints surfaced

US Frontier Labs 40%Accused International Competitors 30%National Security Analysts 30%
  1. [1]The Washington PostNational Security Analysts

    Anthropic says Alibaba copied its AI on an industrial scale

    Read on The Washington Post
  2. [2]Inc. MagazineUS Frontier Labs

    Anthropic Accuses Alibaba of 'Largest Known' AI Distillation Attack

    Read on Inc. Magazine

Comments

Stay informed

Every angle. Every day.

Get Artificial Intelligence stories with full source coverage and perspective breakdowns delivered to your inbox.