BTC $77,016.37 -1.17%
ETH $2,464.14 -0.11%
BNB $713.69 -0.52%
XRP $1.34 -2.70%
SOL $99.49 -1.56%
TRX $0.3384 -0.58%
DOGE $0.0835 -1.60%
ADA $0.2034 -4.26%
BCH $225.45 -8.56%
LINK $11.42 -3.28%
HYPE $79.36 -4.10%
AAVE $122.27 -0.94%
SUI $0.7299 -4.09%
XLM $0.1751 -2.35%
ZEC $1,108.58 -8.98%
AAPL $325.70 +1.98%
AMZN $253.65 +0.29%
GOOGL $334.00 +0.74%
MSFT $493.42 +0.29%
META $648.34 -2.18%
NVDA $220.42 -1.18%
TSLA $364.85 -0.37%
SNDK $1,701.17 -2.48%
INTC $101.44 -2.86%
SPCX $149.44 +1.51%
MU $987.22 -2.74%
AMD $509.31 -1.36%
BTC $77,016.37 -1.17%
ETH $2,464.14 -0.11%
BNB $713.69 -0.52%
XRP $1.34 -2.70%
SOL $99.49 -1.56%
TRX $0.3384 -0.58%
DOGE $0.0835 -1.60%
ADA $0.2034 -4.26%
BCH $225.45 -8.56%
LINK $11.42 -3.28%
HYPE $79.36 -4.10%
AAVE $122.27 -0.94%
SUI $0.7299 -4.09%
XLM $0.1751 -2.35%
ZEC $1,108.58 -8.98%
AAPL $325.70 +1.98%
AMZN $253.65 +0.29%
GOOGL $334.00 +0.74%
MSFT $493.42 +0.29%
META $648.34 -2.18%
NVDA $220.42 -1.18%
TSLA $364.85 -0.37%
SNDK $1,701.17 -2.48%
INTC $101.44 -2.86%
SPCX $149.44 +1.51%
MU $987.22 -2.74%
AMD $509.31 -1.36%

Seven domestic AI companies were secretly distilled and named by Anthropic!

Core Viewpoint
Summary: Anthropic's report accuses seven Chinese AI companies, including Alibaba, Moonlight Shadow, and DeepSeek, of distilling Claude without authorization, involving over 151 million interactions. The named companies have not yet responded.
Biteye
2026-09-11 17:25:03
Anthropic's report accuses seven Chinese AI companies, including Alibaba, Moonlight Shadow, and DeepSeek, of distilling Claude without authorization, involving over 151 million interactions. The named companies have not yet responded.

Author: Biteye Core Contributor Denise

Anthropic has once again included Chinese AI companies in its threat intelligence report.

On September 10, Claude's developer Anthropic released its latest report, naming Alibaba, Dark Side of the Moon, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax, accusing them of engaging in unauthorized model distillation activities.

The largest case involves Alibaba: Anthropic claims that from May to July of this year, it observed over 151 million interactions attributable to Alibaba, used to extract Claude's reasoning capabilities.

Another part of the accusation directly relates to users: Anthropic states that Dark Side of the Moon and DeepSeek have forwarded some user requests to Claude and then returned Claude's responses to the users; other companies are accused of using user conversations to generate training data.

Of course, these are the investigative conclusions published by Anthropic.

01 Let's first look at what this report discusses

The entire report covers AI abuse activities that Anthropic claims to have discovered and blocked between December 2025 and August 2026, involving cyber attacks, surveillance, public opinion manipulation, fraud, biological field abuse, conventional weapons development, and distillation among seven categories.

One major observation in the report is that attackers are increasingly having AI directly execute and coordinate tasks.

For example, automatically advancing network intrusions or operating a large number of fake social media accounts.

Directly related to domestic models is the final distillation chapter. The behaviors of the seven companies accused are as follows:

Seven domestic AI companies were secretly distilled and named by Anthropic!

These figures are statistics from Anthropic, with different observation periods, so they cannot be directly treated as rankings of usage during the same period.

02 Why is "distillation" labeled as "illegal"?

Distillation can be understood as allowing one model to learn from another model: first, let the more capable "teacher model" generate answers or problem-solving processes, and then use these materials to train the "student model," allowing it to learn similar processing methods.

Seven domestic AI companies were secretly distilled and named by Anthropic!

Distillation itself is a common training method. Anthropic explicitly acknowledges this in the report.

What it refers to as "illegal distillation" specifically denotes unauthorized, covert, and industrial-scale capability extraction activities. According to the report, related activities may bypass access restrictions using proxy "transit stations," fake accounts, or stolen credentials to collect model outputs in large quantities.

The focus of this contention is the reasoning process of the model. The final answer tells the student "what to choose for this question," while the reasoning process can provide training materials on "how to analyze and complete tasks." Anthropic states that related activities mainly target capabilities in programming, tool invocation, data analysis, and long-process tasks.

Therefore, to judge the controversy, one needs to look at where the data comes from, whether access is authorized, whether restrictions are bypassed, and whether users are informed. Merely relying on "using distillation technology" cannot determine whether a company's specific behavior is illegal.

03 Why are user data also involved?

According to the report, some users of Dark Side of the Moon and DeepSeek believed their requests were given to the selected model, but they were actually forwarded to Claude.

If the accusations are valid, users need to question: which service providers handled their information, and whether it was used for model training?

However, the original text has varying degrees of certainty regarding whether users were notified.

Seven domestic AI companies were secretly distilled and named by Anthropic!

For example, the section on Dark Side of the Moon states that Anthropic does not know whether the company notified its customers.

Anthropic also raised concerns about security: extracting model capabilities does not necessarily replicate the original model's security restrictions. This is one of the reasons it included distillation in the threat report.

The disclosed countermeasures include detecting abnormal extraction behaviors, banning related accounts, replacing complete reasoning content with summaries, and strengthening identity verification.

04 How have the named companies and the industry responded?

As of September 11, 2026, when this document was verified, no verifiable formal responses from the seven companies regarding this September report had been found.

There has been public discussion in the industry prior to this. The following statements were all made before the September report and belong to the background of the controversy.

On July 24, Microsoft released an open letter co-signed by companies such as Hugging Face, Meta, Mistral, and NVIDIA.

The letter argues that policymakers should distinguish between normal model development techniques and improper encroachments: distillation is a widely used model improvement method; issues arising from illegal extraction of closed-source model value should be addressed through targeted legal and commercial rules, rather than imposing a blanket restriction on technology.

There are also technical disagreements.

On July 23, TechCrunch, discussing the distillation controversy of Kimi K3, cited AI researcher Nathan Lambert's viewpoint: as models approach the cutting edge and the training focus shifts to reinforcement learning, it is difficult to explain all capability improvements solely through supervised fine-tuning distillation.

Braden Hancock, a researcher at Laude Institute and co-founder of Snorkel AI, also believes that American public opinion underestimates the technical strength of Chinese teams.

These viewpoints discuss the technical role of distillation and regulatory boundaries, and do not verify the accusations in the September report item by item. Attention should still be paid to whether the named companies respond regarding specific accounts and data sources, whether user requests were forwarded, and how related training data was authorized.

05 In conclusion

Distillation itself is not an original sin; normal technical borrowing and unauthorized large-scale capability extraction cannot be conflated.

Currently, what the outside world sees is still mainly Anthropic's unilateral investigative conclusions, and the named companies have not publicly responded to key details. How the 151 million interactions are attributed, whether user requests were authorized for forwarding, and which conversations were used for training all require more evidence and explanations from the involved companies.

For ordinary users, this controversy is not distant. When we hand over code, business materials, or even private conversations to an AI, the information being processed behind the scenes may not just be the model displayed on the page.

AI companies are competing for the capabilities of the next generation of models, but what is potentially involved is the data of every individual.

When a conversation is forwarded, stored, or even used for training without the user's knowledge, we may need to re-examine: in front of the AI input box, are we users of the product, or the raw materials for training the product?

Join ChainCatcher Official
Telegram Feed: @chaincatcher
X (Twitter): @ChainCatcher_
warnning Risk warning
app_icon
ChainCatcher Building the Web3 world with innovations.