{"slug": "deepseek-and-alibaba-are-closing-the-ai-gap-anthropic-accuses-them-of-using-to", "title": "DeepSeek And Alibaba Are Closing The AI Gap. Anthropic Accuses them Of Using Claude To Help Train Their Models.", "summary": "Anthropic's September 2026 threat intelligence report accused Alibaba of running the largest distillation operation it has measured, with more than 151 million Claude exchanges detected between May and July 2026, and linked DeepSeek to another 12.1 million exchanges over a 14-day period in July. Anthropic said Alibaba's activity peaked at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts and was tied to training Alibaba's Qwen 3.5, 3.6 and 3.7 models, while DeepSeek routed some customer requests silently to Claude. The report covers misuse detected between December 2025 and August 2026 and names seven China-based AI labs in total, including Moonshot AI.", "body_md": "# DeepSeek And Alibaba Are Closing The AI Gap. Anthropic Accuses them Of Using Claude To Help Train Their Models.\n\n## Anthropic linked Alibaba to more than 151 million Claude exchanges and DeepSeek to another 12.1 million as Chinese labs sought advanced reasoning capabilities.\n\nChinese [artificial intelligence](https://www.ibtimes.com/social-tags/artificial-intelligence) companies including Alibaba, DeepSeek and Moonshot AI used millions of exchanges with Anthropic's [Claude](https://www.ibtimes.com/anthropic-says-claude-has-internal-thinking-space-its-stopping-short-calling-it-conscious-3805022) to help train and improve their own models, Anthropic said. The company claims they sought to extract capabilities from its most advanced systems to advance their own.\n\nAnthropic went on to describe \"distillation\" campaigns by seven China-based AI labs. The findings were included in the company's latest [threat intelligence report](https://www.anthropic.com/threat-intelligence-report-september-2026), which covers misuse detected between December 2025 and August 2026.\n\nDistillation is a widely used AI training technique in which outputs from a more capable model are used to train another model. Anthropic [has previously described](https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks) the technique itself as legitimate, including when companies use their own larger models to develop smaller ones, but said competitors violated its terms by using fraudulent accounts and other methods to extract Claude's capabilities without authorization.\n\n[Alibaba](https://www.ibtimes.com/alibaba-betting-another-10-billion-ai-investors-arent-sold-yet-its-stock-fell-3806709) was responsible for the largest distillation operation Anthropic said it has measured, with more than 151 million Claude exchanges detected between May and July. Activity peaked at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts, with the requests targeting software engineering, agentic tasks, kernel development and other complex work.\n\nOperators affiliated with Alibaba targeted reasoning transcripts from Anthropic's Opus 4.6 and 4.7 models and converted them into data that could be used for supervised fine-tuning, Anthropic said. The company linked the resulting data to the training of Alibaba's Qwen 3.5, 3.6 and 3.7 models.\n\nAnthropic said Alibaba also used Claude for other AI research, including work on reinforcement-learning environments, model architecture and internal infrastructure used for model development.\n\nThe operation initially relied on nearly 5,000 fraudulent accounts using residential proxies, disposable email addresses and virtual-card payments to obscure their access, according to the report. Anthropic said the traffic shifted to a second pool of accounts after it blocked the first group.\n\n[DeepSeek](https://www.ibtimes.com/chinas-ai-models-are-catching-zais-glm-53-takes-aim-openai-anthropic-3806434) was linked to more than 12.1 million exchanges over a 14-day period in July. Anthropic said the Chinese AI developer targeted Claude Opus reasoning traces and developed a system to extract transcripts that Anthropic's technical controls were designed to prevent users from obtaining.\n\nSome DeepSeek customer requests were also silently routed to Claude, Anthropic said. The company said users believed they were interacting with DeepSeek models and were likely unaware that information they submitted was being sent to Anthropic.\n\nThe data included internal documents from a Chinese technology company and requests from an IT operator working with information from a Russian government agency associated with the country's Defense Ministry, according to Anthropic. The latter included active credentials for a Russian government database. Engineers developing a case-management system for a Chinese municipal Public Security Bureau also had requests relayed through Claude, the report said.\n\n[Moonshot AI](https://www.ibtimes.com/moonshot-pushes-kimi-k3-us-market-microsoft-amazon-google-weigh-revenue-sharing-deals-3806829), the Beijing-based developer of the Kimi models, was linked to more than 23 million Claude exchanges between May and July. Anthropic said Moonshot sometimes forwarded customer requests to Claude instead of processing them with Kimi and then showed Claude's responses to users as if they had come from Moonshot's model.\n\nNearly 300,000 customer requests were relayed to Anthropic during one 10-day period, mostly to Claude Opus models, through a network of 5,380 accounts that Anthropic identified as fraudulent. The company said Moonshot saved at least some of the exchanges and extracted Claude reasoning transcripts to use as training data.\n\nSome of those requests contained sensitive information. Anthropic said one user it assessed as likely affiliated with China's People's Liberation Army submitted surveillance information from hundreds of cameras in Chengdu while believing it was being processed by Kimi. Another user at a major Chinese state-owned enterprise submitted internal code and active credentials belonging to several companies.\n\nAnthropic said it did not know whether Moonshot informed customers that their requests were being sent to a third party.\n\nThe report also detailed activity attributed to other Chinese developers, including [Xiaomi](https://www.ibtimes.com/topic/xiaomi) and Zhipu, which operates internationally as Z.ai. Anthropic linked Xiaomi to more than 400,000 exchanges during a 20-day period in March and April and said some of the traffic included names, contact information and corporate data belonging to users of third-party model-routing services.\n\nThe latest findings expand on [distillation campaigns Anthropic disclosed in February](https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks), when it said DeepSeek, Moonshot and MiniMax generated more than 16 million Claude exchanges through approximately 24,000 fraudulent accounts. Those operations also targeted Claude's reasoning and coding capabilities, the company said.\n\nDeepSeek on Thursday released its [V4.1-Flash model](https://www.reuters.com/world/asia-pacific/chinas-deepseek-launches-v41-flash-model-2026-09-10/), which the company said offers faster inference and higher throughput, while Moonshot released its Kimi K3 model in July.\n\nU.S. officials this week separately accused six [Chinese AI companies](https://www.ibtimes.com/china-just-unveiled-ai-model-that-rivals-americas-best-silicon-valley-no-longer-clearly-leading-3805416), including DeepSeek, Moonshot and Alibaba, of conducting large-scale distillation campaigns targeting American models. The officials said the companies had targeted systems developed by Anthropic, OpenAI, [Google](https://www.ibtimes.com/company/google-inc) and [SpaceX](https://www.ibtimes.com/social-tags/spacex), [Reuters](https://www.reuters.com/technology/us-accuses-chinese-ai-firms-industrial-scale-theft-ai-technology-2026-09-08/) reported.\n\nChina has rejected the U.S. allegations, with its Commerce Ministry calling distillation a widely used and neutral technical method. The ministry accused Washington of interfering with normal commercial activity and said some U.S. companies had also distilled Chinese models.\n\nAnthropic said it has responded to the activity by shutting down accounts associated with the operations and strengthening systems designed to detect attempts to extract Claude's capabilities. The company has also introduced additional verification requirements for accounts linked to regions where Claude is not directly available.\n\n© Copyright IBTimes 2026. All rights reserved.", "url": "https://wpnews.pro/news/deepseek-and-alibaba-are-closing-the-ai-gap-anthropic-accuses-them-of-using-to", "canonical_source": "https://www.ibtimes.com/deepseek-alibaba-are-closing-ai-gap-anthropic-accuses-them-using-claude-help-train-their-3807381", "published_at": "2026-09-11 17:17:23+00:00", "updated_at": "2026-09-11 17:45:17.755234+00:00", "lang": "en", "topics": ["artificial-intelligence", "large-language-models", "ai-safety", "ai-policy", "ai-ethics"], "entities": ["Anthropic", "Alibaba", "DeepSeek", "Moonshot AI", "Claude", "Qwen 3.5", "Qwen 3.6", "Qwen 3.7"], "alternates": {"html": "https://wpnews.pro/news/deepseek-and-alibaba-are-closing-the-ai-gap-anthropic-accuses-them-of-using-to", "markdown": "https://wpnews.pro/news/deepseek-and-alibaba-are-closing-the-ai-gap-anthropic-accuses-them-of-using-to.md", "text": "https://wpnews.pro/news/deepseek-and-alibaba-are-closing-the-ai-gap-anthropic-accuses-them-of-using-to.txt", "jsonld": "https://wpnews.pro/news/deepseek-and-alibaba-are-closing-the-ai-gap-anthropic-accuses-them-of-using-to.jsonld"}}