Anthropic Accuses Alibaba of 'Industrial-Scale' AI Distillation in Letter to US Senate
Anthropic alleges that operators linked to Alibaba's Qwen lab used 25,000 fraudulent accounts to extract advanced reasoning and coding capabilities from its Claude AI model. The accusation highlights the growing geopolitical friction over "model distillation," a technique used to train cheaper AI systems on the outputs of frontier models.
By Factlen Editorial Team
- US Frontier Labs
- View distillation as intellectual property theft that undermines billions in R&D.
- Accused International Competitors
- Deny illicit extraction and frame US actions as protectionist.
- National Security Analysts
- Focus on the geopolitical and strategic risks of capability parity.
What's not represented
- · Open-Source AI Advocates
- · Independent Legal Scholars
Why this matters
As artificial intelligence becomes a central pillar of national security and economic dominance, the methods used to train these models are under intense scrutiny. This dispute exposes the vulnerabilities of frontier AI systems to "distillation"—a practice that allows competitors to bypass billions of dollars in research costs by simply copying a leading model's homework.
Key points
- Anthropic alleges Alibaba's Qwen lab used 25,000 fake accounts to query its Claude model 28.8 million times.
- The alleged goal was "distillation," a technique used to train cheaper models on a frontier model's outputs.
- The campaign reportedly targeted Claude's advanced software engineering and agentic reasoning capabilities.
- Alibaba has denied the accusations and recently banned the internal use of Anthropic's coding tools.
- The dispute highlights a legal gray area regarding whether AI model distillation constitutes intellectual property theft.
In a significant escalation of the global artificial intelligence race, US-based Anthropic has leveled unprecedented accusations against Chinese technology conglomerate Alibaba. In a formal letter addressed to the US Senate Banking Committee, Anthropic alleges that operators affiliated with Alibaba’s Qwen AI lab orchestrated an "industrial-scale" campaign to siphon advanced capabilities from its Claude chatbot. The disclosure, directed to Committee Chair Tim Scott and Ranking Member Elizabeth Warren, elevates a corporate intellectual property dispute into a high-stakes national security issue. Anthropic describes the operation as the largest known attack of its kind, highlighting the growing friction between American frontier AI developers and international competitors racing to close the technological gap.[2]
The scale of the alleged operation is staggering. According to the letter, which covers a 44-day window between April 22 and June 5, 2026, the attackers utilized approximately 25,000 fraudulent accounts to generate more than 28.8 million interactions with Claude. These accounts were reportedly designed to mimic ordinary user traffic, allowing them to slip past standard rate limits and detection mechanisms. By operating a massive, coordinated network, the perpetrators were able to systematically extract vast amounts of data from Anthropic’s systems before the campaign was identified and halted.[2]
At the heart of the accusation is a machine learning technique known as "adversarial distillation." In standard AI development, distillation is a legitimate efficiency practice where a smaller, cheaper "student" model is trained using the outputs of a larger, more capable "teacher" model. However, Anthropic alleges that Alibaba weaponized this process. By confronting Claude with millions of carefully crafted, targeted queries, the operators could harvest the model’s responses, reasoning patterns, and generated code. This harvested data then serves as a high-quality training set for Alibaba’s own Qwen models.[1]

The economic asymmetry of model distillation makes it an incredibly potent vector for capability extraction. Developing a frontier AI model requires billions of dollars in research, massive datasets, and vast amounts of computational power. A distillation attack bypasses these immense financial and technical hurdles. The attacker does not need to steal source code, breach secure servers, or access the original model's underlying weights. By simply asking the right questions at an industrial scale, a competitor can create a usable echo of a state-of-the-art system at a fraction of the cost and time.[1]
Anthropic’s letter emphasizes that the fraudulent accounts were not engaging in basic small talk or simple question-and-answer functions. Instead, the campaign specifically targeted the most commercially valuable capabilities of Anthropic's frontier "Mythos Preview" model. The operators focused heavily on advanced software engineering and "agentic reasoning"—the ability of an AI system to independently plan, execute, and adapt to complex, multi-step tasks over long horizons. By extracting these specific capabilities, the attackers aimed to rapidly elevate the performance of their own models in high-stakes domains.[2]
The geopolitical implications of the alleged campaign are profound. Anthropic has explicitly framed the operation in national terms, arguing that such distillation efforts effectively turn hundreds of billions of dollars of American AI investment into a direct subsidy for a primary geopolitical competitor. This framing resonates strongly in Washington, where policymakers increasingly view artificial intelligence leadership as a critical component of national security and economic dominance. The accusation suggests that the fastest path to parity for foreign labs is not independent innovation, but the systematic copying of American models.[1]
The geopolitical implications of the alleged campaign are profound.
Beyond the commercial and geopolitical stakes, distillation attacks introduce severe safety vulnerabilities. When a frontier model is developed, companies spend immense resources on "alignment"—installing safety guardrails to prevent the AI from generating malicious code, offering bioweapon guidance, or executing offensive cyber operations. However, an illicitly distilled student model inherits the raw capabilities and reasoning power of the teacher model without inheriting its safety filters. This dynamic creates a scenario where highly capable, unrestricted AI systems could be deployed globally without the safeguards engineered by their original creators.

Alibaba has firmly pushed back against the allegations. The Chinese tech giant has denied any wrongdoing, rejected claims of military affiliation, and filed a lawsuit challenging its designation in related security contexts, calling the accusations devoid of any factual or legal basis. The company maintains that its Qwen models are the product of independent research and development, and it has not publicly addressed the specific metrics regarding the 28.8 million interactions cited in Anthropic’s letter.
The dispute has already triggered internal fallout at Alibaba. In a direct response to the escalating conflict, Alibaba issued an internal notice banning its employees from using Anthropic’s "Claude Code" AI tool, effective July 10, 2026. The company cited security vulnerabilities, claiming the software carried "back-door risks," and recommended that staff transition to Qoder, Alibaba's proprietary coding agent platform. The internal ban underscores the rapid decoupling of AI toolchains between American and Chinese technology ecosystems.
This is not the first time Anthropic has raised alarms about industrial-scale capability extraction. In February 2026, the company publicly accused three smaller Chinese AI labs—DeepSeek, Moonshot AI, and MiniMax—of conducting similar distillation campaigns. At the time, Anthropic reported that those operations involved millions of interactions, but the volume now attributed to Alibaba significantly dwarfs those earlier cases. The company has warned that these extraction efforts are growing rapidly in both intensity and sophistication.
The allegations arrive amid a flurry of parallel actions by the US government aimed at protecting domestic AI assets. In April 2026, the White House Office of Science and Technology Policy issued a memorandum directing federal agencies to crack down on the exploitation of US AI models through proxy accounts. More recently, the Commerce Department placed temporary export controls on Anthropic’s Fable 5 and Mythos 5 models in June, suspending global access following the discovery of vulnerabilities, before lifting the restrictions on June 30.

Legislative momentum is also building in response to the distillation threat. In the wake of Anthropic’s disclosure, US Senators Bill Hagerty and Andy Kim announced plans to introduce an amendment to a must-pass defense bill. The proposed legislation would explicitly sanction Chinese firms found to be improperly accessing and utilizing the outputs of American AI models. A related bipartisan bill is currently under consideration in the House of Representatives, signaling a unified congressional push to address the loophole.
Despite the intense scrutiny, model distillation currently exists in a murky legal vacuum. While the practice of querying a model to train a competitor violates the terms of service of companies like Anthropic and OpenAI, there is no settled intellectual property law that explicitly classifies the automated harvesting of AI outputs as theft. This lack of clear legal precedent complicates enforcement efforts and leaves frontier labs relying on technical countermeasures and government intervention rather than traditional copyright litigation.[1]
The Alibaba dispute highlights a fundamental shift in the nature of technological espionage. As frontier AI models are increasingly deployed via public APIs to serve global customer bases, they inherently expose their capabilities to the world. The battleground has moved from traditional cyberattacks targeting source code and server infrastructure to the automated, systematic extraction of model behavior. For the AI industry, the incident underscores the immense challenge of commercializing state-of-the-art systems while simultaneously protecting them from adversaries armed with millions of fake accounts.[1]
How we got here
Feb 2026
Anthropic accuses three smaller Chinese AI labs of industrial-scale distillation campaigns.
Apr 2026
The White House issues a memo directing agencies to crack down on the exploitation of US AI models.
Apr 22 - Jun 5, 2026
The window during which Anthropic alleges the Alibaba-linked distillation campaign took place.
Jun 10, 2026
Anthropic sends a formal letter detailing the allegations to the US Senate Banking Committee.
Jul 10, 2026
Alibaba officially bans its employees from using Anthropic's Claude Code tool internally.
Viewpoints in depth
US Frontier Labs
View distillation as intellectual property theft that undermines billions in R&D.
American AI developers argue that unauthorized distillation is a direct threat to their business models and national security. They emphasize that building frontier models requires billions of dollars in compute and research. By using automated scripts to harvest outputs, competitors can bypass these costs and create near-peer models. Furthermore, labs warn that distilled models often strip away the rigorous safety guardrails installed in the original systems, creating proliferation risks for malicious code and bioweapon guidance.
Accused International Competitors
Deny illicit extraction and frame US actions as protectionist.
Companies accused of distillation, including Alibaba, consistently deny engaging in illicit capability extraction. They maintain that their models are the product of independent research and massive domestic investments in AI infrastructure. From this perspective, the accusations and subsequent US export controls are viewed as anti-competitive measures designed to stifle international competition and maintain an American monopoly over the global artificial intelligence market.
National Security Analysts
Focus on the geopolitical and strategic risks of capability parity.
Defense and policy analysts view the extraction of advanced reasoning and coding capabilities as a critical strategic vulnerability. They argue that the current legal vacuum surrounding AI training data allows foreign adversaries to rapidly close the technological gap without bearing the associated R&D costs. This camp is pushing for aggressive legislative action, including strict export controls and sanctions, to prevent American AI investments from inadvertently subsidizing geopolitical rivals.
What we don't know
- Whether the US Senate will introduce specific legislation explicitly outlawing AI model distillation.
- The exact extent to which Alibaba's Qwen models benefited from the alleged interactions with Claude.
- How US regulators plan to enforce intellectual property protections on AI outputs globally.
Key terms
- Model Distillation
- A machine learning technique where a smaller, cheaper 'student' AI model is trained using the outputs generated by a larger, more advanced 'teacher' model.
- Agentic Reasoning
- The ability of an AI system to independently plan, execute, and adapt to complex, multi-step tasks over a long period without human intervention.
- Frontier AI
- The most capable, state-of-the-art artificial intelligence models that push the boundaries of current technological capabilities.
Frequently asked
Is model distillation illegal?
Currently, model distillation exists in a legal gray area. While AI companies prohibit it in their terms of service, there is no settled intellectual property law explicitly classifying it as theft.
Why would a company use distillation instead of training its own model?
Distillation allows a company to replicate the high-level performance of an advanced AI model without spending the billions of dollars and massive computational power required to develop it from scratch.
How did Anthropic detect the alleged campaign?
Anthropic claims it identified a coordinated network of approximately 25,000 fraudulent accounts designed to mimic ordinary traffic and bypass rate limits.
Sources
[1]The Washington PostNational Security Analysts
Anthropic says Alibaba copied its AI on an industrial scale
Read on The Washington Post →[2]Inc. MagazineUS Frontier Labs
Anthropic Accuses Alibaba of 'Largest Known' AI Distillation Attack
Read on Inc. Magazine →
More in ai
See all 6 stories →AI Workforce
AI Adoption Accelerates Job Losses in Tech and Finance to 28,000 Per Month
7 sources
AI Regulation
How 42 State Attorneys General Are Using Consumer Law to Regulate OpenAI
6 sources
Silicon Sovereignty
$1 Trillion AI Chip Selloff Follows Wave of Custom Silicon Shipments, Reshaping Compute Market
7 sources
Macroeconomics
Federal Reserve Raises US Growth Forecast, Citing Surging AI Infrastructure Investment
4 sources
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.






