US artificial intelligence company Anthropic has accused Chinese AI developers of “engaging in aggressive, malicious and targeted distillation activities” and steal of US AI models.
A September report from Anthropic said that companies such as “DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI have extracted billions of tokens across millions of exchanges/requests from US frontier AI models for two years, including variants of Claude, GPT, Gemini and Grok.”
It also said the Chinese government was “likely aware of this.” A report in the South China Morning Post (SCMP) expressed skepticism about the claims.
The US Cybersecurity and Infrastructure Security Agency (CISA) has described it as a “systematic extraction of proprietary functionalities and capabilities that threaten US technological leadership.”
According to Anthropic’s report, Moonshot AI secretly forwards requests to Claude and not Kimi, even though users believed it was Kimi. “Over a ten-day period, we are talking about 300,000 customer requests. They used a proxy service network of 5,380 fraudulent accounts in Singapore and Japan,” an excerpt from the report said.
The National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a joint alert to warn US companies about the suspected activities. They accused Chinese AI companies of conducting shady business on an industrial scale and using robust operations to steal capabilities from American AI systems.
Chinese AI is accused of industrial-scale distillation
The government consultancy named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as companies involved in large-scale model distillation campaigns since at least late 2024.
Distillation is a technique in which developers use the results of a more advanced AI model to train another system.
Anthropic acknowledged that distillation is a “legitimate training method,” but also stressed that there is a difference between transparent research using capable “teacher” models and conducting a “covert campaign” without authorization.
“We define illegal distillation as an industrial-scale covert campaign to extract the capabilities of one model and reproduce them in another model without authorization,” Anthropic clarified.
They believe that Chinese developers used third-party aggregators, cloud providers and proxy services called “transfer stations” to bypass limitations of American AI systems.
Anthropic’s most specific allegations were directed against Moonshot AI, the developer of the Kimi chatbot. Additionally, Alibaba appears to have conducted more than 151 million distillation activities between May and July 2026.
However, these claims were met with skepticism. Wang Zebin, an investment manager at Shenzhen-based JG Investment, questioned whether Anthropic had provided sufficient evidence to independently verify its claims.
The report “does not provide enough concrete examples to independently verify how these companies obtained or used the model results,” Wang said SCMP.
The allegations raise concerns about sensitive Chinese data
Chinese regulators have reportedly questioned domestic AI developers following Anthropic’s allegations. According to SCMP, the Cyberspace Administration of China interviewed seven developers before focusing on DeepSeek and Moonshot.
Moonshot and DeepSeek did not respond to SCMP’s requests for comment.
Meanwhile, the NSA, FBI and CISA have called on American AI companies to strengthen their detection systems, implement targeted countermeasures and share information about suspected distillation campaigns.
Anthropic said it had disrupted identified abuse operations and strengthened its protections against unauthorized extraction of Claude’s abilities.
The allegations remain controversial; questions about attribution and the involvement of third-party intermediaries remain unresolved.