US Accuses Chinese AI Labs of Industrial-Scale Model Theft

Anthropic's 154-page report alleges Moonshot routed 300,000 customer requests to Claude through 5,380 fraudulent accounts in 10 days and DeepSeek ran 12 million distillation attacks in July, days after NSA, CISA and FBI named six Chinese AI firms and Beijing dismissed the claims as groundless.

Sep 11, 2026 - 08:32
0 11
US Accuses Chinese AI Labs of Industrial-Scale Model Theft

Anthropic Tells Washington That China's AI Labs Went Looking for Answers in Claude

Anthropic published a 154-page threat intelligence report on Thursday alleging that two of China's most prominent artificial intelligence developers, DeepSeek and Moonshot AI, quietly routed their own customers' requests into its Claude models and then showed the answers back as if they had been generated at home.

The numbers attached to the allegation are what make it hard to dismiss. Over a single 10-day window, Moonshot relayed nearly 300,000 customer requests to Anthropic through 5,380 accounts the company describes as fraudulent, most of which appeared to be located in Singapore and Japan. DeepSeek was linked to more than 12 million distillation attacks over 14 days in July 2026. Across five campaigns, Anthropic says it observed nearly 200 million exchanges.

The report landed two days after three United States agencies named six Chinese companies in a joint cybersecurity advisory. Beijing rejected both documents within a day. What began as a technical argument between AI laboratories is now the most concrete dispute on the agenda for the American and Chinese officials who are supposed to meet this month.

What Distillation Is, and Why Washington Now Calls It Theft

Distillation is not exotic. It is a standard technique in which a smaller model is trained on the outputs of a larger one, and it is used openly by laboratories on both sides of the Pacific, including in the United States. The dispute is about scale, permission and method.

Anthropic says its terms prohibit access from inside mainland China, which is why Moonshot and DeepSeek are alleged to have gone around the front door. The company describes the traffic as passing through a network of intermediary platforms, fake accounts and stolen credit cards, and it says the harvested material targeted some of Claude's most valuable capabilities: agentic tool use, coding, data analysis and logical reasoning.

There is a consumer-protection dimension that Chinese readers may find more uncomfortable than the intellectual property one. The Wall Street Journal reported that some diverted requests carried sensitive user data, including location information and passwords. Anthropic says one Kimi user, described as likely affiliated with China's People's Liberation Army, asked the model to assess closed-circuit footage of a specific person in Chengdu, Sichuan province to judge whether the subject was behaving abnormally. Those requests reached an American company's servers, which is a data-governance failure in either legal system.

Joe Khawam, managing director for legal and AI policy at the Law Reform Institute in Washington, told the South China Morning Post that the details are potentially legally relevant under Chinese law too, and that the sequence of the two reports points to a bilateral negotiation rather than a courtroom.

The Campaigns, Company by Company

Anthropic attributes the largest single effort to Alibaba, the owner of this newspaper - a campaign it describes as the biggest wholesale distillation operation it has ever observed. Between May and July 2026 the company counted 151 million exchanges spread across 3,500 accounts, peaking at nearly three million exchanges a day. Because every account sent the same fixed prompt designed to extract the model's chain of thought, Anthropic concluded the traffic was feeding training material for Alibaba's Qwen family.

Moonshot's method was different and, from a customer's perspective, more troubling. Anthropic alleges that the Kimi developer forwarded a portion of user requests to Claude and displayed Claude's answers to users who believed they were talking to a Chinese model, then saved some of the exchanges and extracted the reasoning transcripts as training data. The report accuses five further Chinese companies of distilling its models since February 2026, among them GLM developer Z.ai, MiMo developer Xiaomi and MiniMax.

Commercial momentum is the backdrop. Moonshot's K3 model, released in July, made the Beijing company one of the most visible Chinese AI champions abroad. Nomura Securities expects Moonshot's annual recurring revenue to reach 1 billion US dollars by the end of the year, double its level in mid-2026. Moonshot is also exploring dual listings in Hong Kong and Shanghai, which makes the reputational question more than academic.

A Federal Advisory Turned a Laboratory Dispute Into a Security Case

On September 8, the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation published a joint advisory, AA26-251A, that names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.

The advisory asserts that these companies extracted billions of tokens across millions of exchanges from American frontier models, including variants of Claude, GPT, Gemini and Grok, since at least late 2024, and that the campaigns were conducted "likely with Chinese government awareness". It identifies the tradecraft in unusual detail: native application programming interfaces, remote cloud providers and third-party aggregators that strip user metadata, plus a grey market of proxies the advisory calls transfer stations, used to defeat geographic restrictions.

Also documented are bulk procurement of premium subscriptions shared across teams of developers, automated failover between pathways when a route is blocked, and quality-evaluation frameworks designed to detect defensive countermeasures. The advisory does not accuse distillation itself of being illegitimate; it argues that this volume and this intent amount to systematic extraction of proprietary capabilities.

Beijing's Answer: Double Standards, and a Warning

China's Ministry of Commerce responded on Wednesday that the allegations are groundless and lack legal basis, and that Washington is politicising a neutral technical practice. A ministry spokesperson pointed out that distillation is used by model developers around the world, including American ones, and argued that the advisory is evidence of an effort to monopolise computing power and suppress competition.

The Chinese embassy in Washington went further, calling the distillation concept a deliberate attack on China's progress in the AI industry and warning that such actions will only stifle global advances. Beijing has said it will take all necessary measures to protect its interests, language that leaves open the possibility of countermeasures against American firms.

The counter-argument from Chinese officials leans on American industry itself: close to 200 US startups have urged their own government not to cut off access to Chinese open-source models, and several large multinationals have said distillation is a widely used technique. That is a genuine fault line, not a talking point. Silicon Valley is split between companies that want Chinese open-weight models freely available and laboratories that want the practice policed.

The Calendar Is Doing the Escalating

The timing leaves little room for coincidence. President Xi Jinping is due in Washington on September 24, and American and Chinese officials have been preparing a dedicated dialogue on artificial intelligence governance, to be led on the US side by Treasury Secretary Scott Bessent, as a follow-up to the May summit in Beijing.

The two governments do not want the same conversation. Washington wants to focus on AI safety and on cooperation to monitor AI-directed cyberattacks, and has floated the idea of asking laboratories in both countries to police themselves. Beijing wants a broader discussion that includes development and access. A White House official has even disputed that the dialogue is scheduled, which tells you how unsettled the agenda still is.

Bessent has pre-loaded the argument. Speaking in Dallas on September 8, before the advisory was published, he said: "The technical word for stealing and copying American AI models is distillation. So the Chinese distil our models and they can never get ahead of us," adding that copying someone's homework never earns a better grade. He has also rejected any pause in American development.

What to Watch For: Tokyo's Stake in the Standards Fight

Japan appears in this story twice, once as a fact and once as a policy model. The accounts Anthropic says Moonshot used were mostly located in Singapore and Japan, which means Japanese infrastructure was used to bypass a vendor's geographic restrictions. Data-governance agencies in Tokyo will read that line carefully.

Japan's institutional answer has been evaluation rather than prohibition. The Japan AI Safety Institute, established in February 2024 inside the Information-technology Promotion Agency, assesses model risk and coordinates with British and American counterparts. Its AI Promotion Act, in full effect since September 2025, is a principles-based law with no penalties attached, paired with training-data traceability guidance.

That is a different instrument from export controls and federal advisories, and it may be the one that ages better. If the September talks produce a monitoring framework rather than a sanctions list, it will look closer to the Japanese approach than to the American one. Japan also has direct exposure to Moonshot's trajectory: Nomura's 1 billion dollar revenue forecast is the kind of estimate that shapes how Japanese institutional investors price Chinese AI listings.

The immediate tests are concrete. Watch whether Washington moves from advisory to sanctions, which Beijing has already declared a red line. Watch whether the AI dialogue survives its own denials and produces anything joint on cyber monitoring. And watch the listing calendars of DeepSeek and Moonshot, both of which are raising capital in markets that will now price a compliance risk nobody was worrying about a month ago. Ultimately the fight is not about a training technique. It is about whether the next layer of the AI stack is governed by negotiated standards or by national controls.

By Kenji Tanaka, Staff Writer

This article was produced with AI-assisted research and editorial support. Sources: Anthropic threat intelligence report, September 2026; CISA advisory AA26-251A; Global Times; China Ministry of Commerce; South China Morning Post; Reuters; CNBC; The Wall Street Journal; Bloomberg; TechCrunch; Japan AI Safety Institute.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Kenji Tanaka

Japan Correspondent at Global1.News. Tokyo-based voice covering Japanese politics, technology, economy, and culture. Tracks the intersection of tradition and innovation in one of the world's most dynamic societies.

Comments (0)

User