China's star AI labs routed user requests to Claude at least 35 million times in the summer: Anthropic Anthropic said in a Thursday report that Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi combined launched nearly 190 million distillation attacks against Claude between May and July, including 23 million user requests rerouted by Moonshot and 12.1 million by DeepSeek over 14 days in July. Anthropic attributed the largest attack it has ever measured to Alibaba, which it said ran over 151 million exchanges from 3,500 fraudulent accounts to train its Qwen models. In response, Anthropic added safeguards to ban suspicious activity, made Claude produce less detailed reasoning transcripts, and will require identity verification for users appearing to operate from China, Russia, or Iran. China's star AI labs routed user requests to Claude at least 35 million times in the summer: Anthropic Business Insider https://www.businessinsider.com Anthropic said Alibaba, Moonshot, Zhipu, DeepSeek, and Xiaomi all tried to use Claude to train their models in various ways. - Anthropic said China's top AI labs carried out millions of distillation attacks on Claude /compare/claude-4-opus-vs-gpt-o3 . - It said Alibaba, Moonshot, Zhipu, DeepSeek /compare/llama-4-vs-deepseek-r1 , and Xiaomi all tried to use Claude to train their models. - In response, Anthropic is beefing up its guardrails /glossary/guardrails against these attacks. Anthropic said the top Chinese AI labs bombarded Claude with millions of distillation attacks over the summer. The AI lab said in a Thursday report that Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi combined launched nearly 190 million distillation attacks against Claude between May and July. Distillation attacks refer to using the outputs of advanced frontier AI models to train and improve the capabilities of less advanced models. Anthropic said https://www.businessinsider.com/anthropic-researcher-quits-over-ai-safety-concerns-2026-9 that DeepSeek and Moonshot AI https://www.businessinsider.com/moonshot-ai-kimi-k3-founder-professor-on-unique-strengths-qualities-2026-7 fed their users' requests into Claude rather than their own models. It said it had recorded 23 million of such reroutings by Moonshot between May and July, and 12.1 million by DeepSeek over 14 days in July. Anthropic also said that some of these requests — intended for Chinese AI models but routed to Claude instead — exposed sensitive data from the Chinese and Russian governments and militaries. This included CCTV footage uploaded by a PLA-affiliated Kimi user and information on a Russian government database submitted by a Russian military contractor. Per the report, Alibaba ran the largest attack Anthropic had ever measured, recording over 151 million exchanges between May and July carried out by 3,500 fraudulent accounts. The accounts made Claude write out its reasoning /glossary/reasoning processes, which were used to train its Qwen models, Anthropic said. Anthropic accused Z.ai — which made headlines recently for its mysterious Ox Alpha model https://www.businessinsider.com/ox-alpha-model-made-by-china-z-ai-2026-8 — of launching an attack similar in nature to Alibaba's. And in Xiaomi's case, Anthropic said the company recorded user chats with its own MiMo models and fed those conversations into Claude to create training /glossary/training data. Representatives for Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi did not respond to queries from Business Insider asking about Anthropic's allegations. Anthropic did not respond to a request for comment either. Anthropic said that to prevent future distillation attacks, it has added new safeguards to ban suspicious activity and made Claude produce less detailed reasoning transcripts, which are less useful for training new models. It will also require users to verify their identities if they appear to be operating from China, Russia, or Iran, where Claude is not available. This is not the first time Anthropic has publicly called out https://www.businessinsider.com/anthropic-china-alibaba-exploiting-ai-models-distillation-attack-2026-6 Chinese AI labs for distillation attacks. In June, Anthropic's head of policy, Sarah Heck, said in a letter to lawmakers that Alibaba had illicitly engaged in "28.8 million exchanges with Claude" between April 22 and June 5, and called for legislation to address such attacks. Business Insider https://www.businessinsider.com/china-ai-labs-millions-distillation-attacks-anthropic-claude-2026-9 Get AI news in your inbox Daily digest of what matters in AI.