Anthropic Catches DeepSeek, Alibaba, and Moonshot Siphoning Claude Outputs 

Anthropic accused Chinese AI labs innovation for disrupting large-scale attempts by Alibaba, Moonshot and DeepSeek to use Claude outputs.

On September 10, Anthropic accused Chinese AI labs innovation for disrupting large-scale attempts by Alibaba, Moonshot, and DeepSeek to use Anthropic’s Claude outputs for model training through fake accounts across Asia, without authorization or customer disclosure. 

As Chinese AI labs race to improve their systems, Anthropic claims developers are turning another company’s model responses into valuable training material instead of building every capability independently. 

Claude Outputs Turn Training Data 

Anthropic described the practice as illicit distillation, where outputs produced by a more capable AI system are collected and used to improve another model. The case puts Chinese AI labs innovation at the center of a wider debate over who owns the knowledge produced by AI models. 

Its threat intelligence report covers activity disrupted between December 2025 and August 2026. Anthropic said the campaigns stretched across seven areas, highlighting how AI training labs can interact with powerful external models on a scale that is difficult for users to see. 

“Some of these exchanges included sensitive information, including from individual users, major multinational companies, and state-affiliated actors … These practices are likely inconsistent with privacy laws and the labs’ own terms of service,” said Anthropic. 

Operators linked to Alibaba allegedly used Claude outputs to help train Qwen models. According to Anthropic, the operation involved more than 151 million exchanges between May and July, making it the largest campaign it detected and questioning Chinese AI labs innovation. 

At its peak, Alibaba-linked activity reached almost three million exchanges per day through more than 3,500 accounts of Anthropic, classified as fraudulent. The company said Claude was also used for wider research, showing how AI training labs may draw on competing systems for reinforcement learning and model architecture work. 

Chinese Moonshot AI, which develops the Kimi model family, allegedly followed another approach. Anthropic said some customer requests intended for Kimi were silently forwarded to Claude, creating concerns over how Moonshot training was being carried out behind the service users believed they were accessing. 

During a 10-day period, nearly 300,000 requests were sent to Anthropic, mostly through Claude Opus models. More than 5,000 accounts were involved, and Anthropic said Moonshot training also included saving exchanges and extracting Claude reasoning transcripts for future model development. 

Model Training Becomes a Data Risk 

Anthropic attributed more than 23 million exchanges to Moonshot between May and July. The scale shows why Chinese AI labs innovation is increasingly connected not only to computing power, but also to access to high-quality model outputs and reasoning data. 

The company said some forwarded prompts contained sensitive information. That creates a separate privacy problem for Chinese AI labs, because users may not know when their requests are being transferred from one AI provider to another. 

DeepSeek was also named in the report. Anthropic said it observed more than 12 million attacks over a 14-day period in July, placing DeepSeek AI training under scrutiny over how rival model outputs may have been collected. 

Following the report, DeepSeek AI training relied on tactics similar to Moonshot, including moving exchanges to Claude without informing customers. Such routing can make it difficult for users to know which company is processing their information. 

For the Chinese AI lab DeepSeek, the allegations also touch on the technical methods used to build lower-cost models while competing against larger US developers with greater computing resources. 

Questions surrounding DeepSeek model training have become more important since the company gained global attention for producing capable AI systems at costs that challenged assumptions about how much computing power advanced models require. 

The idea that Chinese AI lab DeepSeek rattles Silicon Valley reflects a wider industry concern: cheaper models can challenge established players, but the methods used to train them may now receive much closer attention. 

Ultimately, Chinese AI labs innovation is becoming a question of both technical progress and data control. Anthropic’s report suggests the next stage of AI competition may depend as much on how models obtain training knowledge as on how powerful they become. 

Alibaba, Moonshot, DeepSeek, Xiaomi, and Anthropic did not immediately respond to CNBC’s requests for comment. 


Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Intelligent Tech sections to stay informed and up-to-date with our daily articles.

Advertise with Inside Telecom and reach decision-makers across telecom, AI, and technology.
Join our WhatsApp Channel WhatsApp Channel