cd /news/ai-policy/anthropics-200m-exchange-distillatio… · home topics ai-policy article
[ARTICLE · art-127261] src=forkast.news ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

Anthropic’s 200M-Exchange Distillation Report Is the Evidence Behind the Joint US Intelligence Accusation

Anthropic's September 10, 2026 threat intelligence report documented approximately 200 million exchanges across five distillation campaigns by seven China-based labs, with Alibaba's Qwen team accounting for 151 million exchanges, three days after CISA, the FBI, and the NSA issued joint advisory AA26-251A accusing six Chinese AI companies of industrial-scale distillation against US AI firms. Alibaba ran its campaign from May to July 2026, peaking at roughly 3 million exchanges per day across approximately 3,500 accounts to train Qwen 3.5, 3.6, and 3.7 models, while Moonshot AI contributed 23 million exchanges through approximately 5,380 accounts and DeepSeek contributed 12 million exchanges over fourteen days in July. The figures dwarf Anthropic's February 2026 disclosure of approximately 24,000 fraudulent accounts and 16 million exchanges, and the report serves as the evidentiary foundation for the US government accusation as Anthropic pursues a reported ~$965 billion IPO target.

by read4 min views1 publishedSep 11, 2026
Anthropic’s 200M-Exchange Distillation Report Is the Evidence Behind the Joint US Intelligence Accusation
Image: Forkast (auto-discovered)

Three days before Anthropic published its September 2026 threat intelligence report, the CISA, FBI, and NSA issued a joint advisory (AA26-251A) accusing six Chinese AI companies of industrial-scale distillation against US AI firms. Anthropic’s report, published September 10, is the evidentiary backbone of that accusation. The numbers are the story: approximately 200 million exchanges across five campaigns, seven China-based labs identified, and Alibaba’s Qwen team accounting for 151 million of those exchanges alone.

The scale dwarfs everything that came before. When Anthropic first publicly named distillation targets in February 2026, the allegations involved approximately 24,000 fraudulent accounts and 16 million exchanges. The September report expands that by an order of magnitude. Alibaba conducted its campaign from May to July 2026, peaking at roughly 3 million exchanges per day across approximately 3,500 accounts. The purpose was specific: training Qwen 3.5, 3.6, and 3.7 models, including chain-of-thought distillation targeting Claude Opus 4.6 and 4.7. Anthropic describes this as the “largest wholesale distillation effort” it has ever measured.

The other campaigns reveal the breadth of the extraction. Moonshot AI, the company behind Kimi, ran 23 million exchanges over the same period through approximately 5,380 accounts – mostly appearing to originate from Singapore and Japan, not China directly. The tactic was direct: silently forwarding Kimi user requests to Claude and displaying the responses as Kimi’s own. One request, assessed by Anthropic as originating from a user affiliated with the People’s Liberation Army, asked Claude to analyze surveillance footage from Chengdu. DeepSeek contributed 12 million exchanges over fourteen days in July, routing user requests to Claude without notification – an operation that, according to the report, exposed live credentials for a Russian government database.

This is not a security advisory. It is a legal positioning document, and its timing is coordinated. The CISA/FBI/NSA advisory on September 8 created the governmental accusation. Anthropic’s report three days later provides the evidentiary foundation. Together, they establish a public record that can be cited in future enforcement proceedings, trade negotiations, and – critically – in Anthropic’s own path toward a reported ~$965 billion IPO target. The implicit message to investors and policymakers: our technology is valuable enough that entire national labs are building their products on the back of it, and the US government has noticed.

The disclosure connects directly to the open-weights debate we tracked in July. When 25 tech companies signed a letter defending open-weight distribution, OpenAI and Anthropic both abstained. Anthropic’s position has consistently been that distillation of closed frontier models constitutes IP theft, not legitimate competition. The September report is the evidentiary backbone of that position. If you want to know why Anthropic refuses to open its weights, this report is the answer: the company has measured exactly what happens when access is available.

The gap between what Anthropic can prove and what enforcement can actually reach remains the central tension. Anthropic can name the labs, count the exchanges, describe the methods, and note the sensitive data exposed. But the US-China IP framework was not built for this class of violation. Traditional trade secret law assumes identifiable misappropriation within a jurisdiction where enforcement has teeth. Distillation across borders, through layered API access and fraudulent accounts operating from third countries, occupies a legal gray zone that no existing treaty is equipped to adjudicate.

For the Chinese open-weight ecosystem, the implications are structural. The pricing pressure from Chinese labs has already compressed margins for Western frontier providers. If some portion of that efficiency was derived from distilling Claude’s reasoning patterns rather than from independent architectural innovation, the pricing war takes on a different character. It is no longer just a competition between open and closed models; it is a question of whether the open-weight ecosystem’s cost advantage is partially subsidized by unauthorized extraction from the closed ecosystem. Anthropic’s 200 million exchanges are now on the public record. The US intelligence community has made the accusation. The evidence is filed. Whether that evidence leads to enforcement, regulatory action, or merely a stronger IPO narrative remains the open question – but the coordination between government accusation and corporate disclosure is itself the signal. In the gap between detection and enforcement, the US government and its leading AI company have chosen to make the detection visible together.

── more in #ai-policy 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropics-200m-exch…] indexed:0 read:4min 2026-09-11 ·