Anthropic accuses Chinese AI labs of secretly using Claude to train competing models

millions of diverted exchanges accumulated over time
Anthropic alleges Chinese labs secretly routed user requests through Claude to harvest training data for competing models.
Mark

So Anthropic is saying Chinese companies basically looked over Claude's shoulder and copied what it was doing?

Mimi

More systematic than that. They routed millions of user questions through Claude, collected the answers, and used those answers to train their own models. It's like having someone else do your homework and then submitting it as your own.

Luke

But how does Anthropic know this happened? Are we talking about detected API usage patterns, or is this based on analyzing the Chinese models themselves?

Mimi

The reporting doesn't specify the forensic method. Anthropic disclosed it, which suggests they have evidence, but the exact mechanism of detection isn't detailed.

Mark

Why would these Chinese companies do this instead of just building models the normal way?

Mimi

Speed and cost. Training a frontier model from scratch requires massive computational resources and original data. If you can learn from Claude's outputs, you skip some of that work.

Luke

That's a real advantage, but it's also worth noting that distillation doesn't give you everything. You're learning patterns from outputs, not the underlying training data or architecture. There are limits to what you can copy this way.

Mark

Does this actually violate any laws, or is it just against Anthropic's terms of service?

Mimi

Legally, it's murky. It probably violates the terms of service, which Anthropic can enforce by cutting off API access. Whether it violates intellectual property law is less clear—courts haven't really settled what you own when you publish an AI model's outputs.

Luke

And we should note that Anthropic chose to disclose this publicly rather than handle it quietly. That's a strategic choice, not just a factual report. It signals frustration and possibly aims to pressure the companies or shape the policy conversation.

Mark

What happens next?

Mimi

Anthropic will likely enforce its terms more strictly. Other AI companies might do the same. Longer term, this could push toward stricter API monitoring or new regulations around model training practices.

  • Anthropic alleges that Chinese AI labs routed millions of real user queries through Claude's API without consent, turning its infrastructure into an unpaid training ground for rival models.
  • Moonshot AI is specifically accused of secretly redirecting user requests to Claude rather than its own system — a deception that affected users and competitors alike.
  • DeepSeek's ability to match frontier model performance at a fraction of the cost has drawn fresh scrutiny, with Anthropic's accusations raising the question of whether distillation of Western models helped close the gap.
  • Anthropic chose public disclosure over quiet legal action, signaling both the scale of its frustration and a deliberate warning to the broader industry about the vulnerability of API-based AI systems.
  • The incident exposes a structural weakness: detecting systematic distillation campaigns within normal API traffic is technically difficult and risks introducing surveillance that creates its own ethical complications.
  • The accusation may accelerate U.S. policy responses, reinforcing arguments that export controls on AI chips alone are insufficient if model outputs themselves can be harvested to replicate competitive advantage.

In the long contest over who will shape the intelligence of machines, Anthropic has stepped forward with a serious accusation: that Chinese AI companies — Alibaba, Moonshot AI, and DeepSeek among them — quietly harvested millions of conversations with its Claude model to train competing systems, a practice known as distillation. The allegation, made public rather than pursued in silence, raises one of the defining questions of the AI era — whether the knowledge crystallized in a model's responses belongs to its maker, and what it means when rivals learn not from raw data, but from the mind of another machine. The disclosure arrives at a moment when the race between American and Chinese AI development has grown too consequential to remain merely technical, touching now on intellectual property, geopolitical strategy, and the ethics of competitive intelligence.

Anthropic has publicly accused several Chinese artificial intelligence companies — Alibaba, Moonshot AI, and DeepSeek — of systematically harvesting millions of exchanges with its Claude model to train their own competing systems. The technique, known as model distillation, allows one AI to learn from another's outputs rather than building from raw data, dramatically reducing the cost and time of development.

According to Anthropic's account, the practice was not incidental. Moonshot AI allegedly diverted real user queries to Claude rather than processing them through its own infrastructure, effectively using Anthropic's system as an undisclosed training resource. Over time, millions of such exchanges accumulated — a shortcut that would otherwise demand enormous computational investment and original data collection.

The accusation carries particular weight given DeepSeek's recent prominence. The Chinese lab has attracted attention for releasing models that rival American frontier systems at a fraction of the reported cost, prompting questions about whether distillation of Western models contributed to that efficiency.

What distinguishes this moment is Anthropic's decision to go public. Rather than pursuing the matter through quiet legal channels or silent API enforcement, the company detailed the distillation campaigns openly — a choice that signals both the scope of the problem and a broader anxiety within the American AI industry. Frontier models built at enormous expense are, in principle, partially replicable by any competitor willing to observe their outputs and learn from them.

Enforcing prohibitions against such use is harder than writing them. Identifying when API traffic reflects systematic data harvesting rather than ordinary use requires behavioral analysis that itself raises privacy concerns. The incident may ultimately push major AI providers toward stricter monitoring policies, while renewing debate about whether chip export controls alone are sufficient to protect the competitive investments American companies have made in frontier AI.

Anthropic has accused multiple Chinese artificial intelligence companies of systematically harvesting millions of conversations from its Claude model to train their own competing systems. The San Francisco-based AI safety company says that Alibaba, Moonshot AI, and DeepSeek engaged in what's known as model distillation—a technique where one AI learns from another's outputs without permission or compensation.

The practice works like this: instead of building models from scratch using raw data, these Chinese labs allegedly routed user requests directly through Claude's API, collected the responses, and used those exchanges as training material for their own models. Moonshot AI, according to Anthropic's account, secretly diverted user queries to Claude rather than processing them through its own system, effectively turning Anthropic's infrastructure into an unpaid training ground. The scale was substantial—millions of these diverted exchanges accumulated over time, providing a shortcut to model development that would otherwise require enormous computational resources and original data collection.

This disclosure marks a significant escalation in the ongoing competition between American and Chinese AI companies. The tension centers on a fundamental question: who owns the knowledge embedded in an AI model's responses, and what rights does a company have when others use its outputs to build rival systems? Anthropic's public accusation suggests the company views this not as a gray area of competitive intelligence but as a violation of its terms of service and intellectual property.

The companies named—Alibaba, Moonshot, and DeepSeek—represent some of China's most ambitious AI efforts. DeepSeek in particular has gained attention for releasing models that perform competitively with American frontier models at a fraction of the reported training cost. Whether that efficiency came partly through distillation of Claude or other Western models remains part of the broader question Anthropic is raising.

What makes this accusation noteworthy is not just the allegation itself but the fact that Anthropic chose to disclose it publicly. The company could have pursued the matter quietly through legal channels or API enforcement. Instead, it detailed the distillation campaigns in a way that signals both the scope of the problem and its frustration with the practice. The disclosure also reflects a wider anxiety in the American AI industry: that the competitive advantage of frontier models—built at enormous cost and trained on proprietary data—can be partially replicated by competitors who simply observe the outputs and learn from them.

The incident raises practical questions about how API providers can monitor and prevent such use. Anthropic's terms of service almost certainly prohibit using Claude to train competing models, but enforcing that prohibition at scale is difficult. Detecting when a user is systematically collecting responses for distillation, rather than using the API for its intended purpose, requires either explicit monitoring or behavioral analysis that itself raises privacy concerns.

This moment also sits within a larger geopolitical context. The United States has pursued export controls on advanced AI chips partly to slow China's AI development. Anthropic's accusation suggests that even without access to the most advanced hardware, Chinese labs can accelerate their progress by learning from American models' outputs. That dynamic may prompt both stricter API usage policies across the industry and renewed debate about what safeguards are necessary to protect the investments American companies have made in frontier AI development.

Anthropic disclosed the distillation campaigns publicly, signaling both the scope of the problem and frustration with the practice
— Anthropic's public disclosure
Möchten Sie die ganze Geschichte? Das Original lesen bei Google News ↗
Kontakt FAQ