Why Anthropic's Distillation Report Gave Beijing a Case in 2026

Category: Industry Trends

This analysis was written by the aifreetool Editorial Team — full-time AI-industry researchers who verify every claim against primary sources. Last updated September 27, 2026. We keep no affiliate relationship with the companies covered here.

TL;DR: Anthropic's September 10, 2026 threat intelligence report accused seven China-based AI labs — Alibaba, DeepSeek, Moonshot AI, Zhipu, MiniMax, Xiaomi and SenseTime — of running roughly 190 million exchanges against Claude to extract its reasoning chains. The twist almost nobody predicted: on September 22, China's Cyberspace Administration opened its own formal probe into DeepSeek and Moonshot, not for stealing model capability, but because the same evidence shows Chinese users' data flowing to an American company's servers. One document, two national cases, read from opposite ends.

Every frontier lab now polices some version of this problem, but the Anthropic distillation report is unusually specific, and that specificity is what turned an American IP complaint into Beijing's own leak investigation — a framing AI Breaking Wire flagged the day the disclosure landed. If you follow AI industry trends, this is the clearest example yet of how capability theft and data sovereignty are the same story told twice. For background on the model ecosystem these labs compete in, see our AI engine and model coverage.

What the 190 Million Exchanges Actually Were

AI in China CAC probe DeepSeek Moonshot
Source: www.ainchina.com — https://www.ainchina.com/blog/china-cac-probe-deepseek-moonshot-data-leak-2026

Anthropic's 154-page report covers activity observed between December 2025 and August 2026, organized into five coordinated campaigns across seven companies, according to AI in China's case-file analysis. The target was not Claude's final answers but its intermediate reasoning — the chain of thought that lets a smaller model be trained to mimic frontier reasoning without paying tens of billions of dollars in pre-training compute. That practice, distillation, is the cheapest known shortcut past the capability gap.

The Alibaba campaign was the largest by an order of magnitude. Between May and July 2026, roughly 151 million exchanges ran through more than 3,500 accounts, peaking near three million requests per day. All of the traffic shared a single fixed prompt designed to force the model to reveal its full thinking traces instead of the summarized reasoning Anthropic normally exposes. That uniformity is what let Anthropic attribute the entire operation to one effort — and it is also why the attribution claim, while plausible, has never been tested by any court or regulator.

The extraction techniques were blunt. Attackers used prompt injection tricks, including instructions to translate the model's working memory into katakana characters, to slip past the summarized-thinking guardrail. Once full reasoning traces leak into a transcript, they become high-grade supervised fine-tuning data. Xiaomi's slice of the report followed a different playbook: a free developer trial that built up usage, then reconstructing developer environments from transcripts and cleaning multi-turn conversations into structured training pairs — with the bulk of the distillation clustered right as the trial period ended.

CompanyScale documentedWindowAlleged method
Alibaba (Qwen)~151M exchanges, 3,500+ accountsMay–July 2026Fixed prompt to extract chain of thought
Moonshot AI (Kimi)~300K requests via 5,380 accounts10-day stretchModel rerouting: Kimi users unknowingly answered by Claude
DeepSeek12.1M+ exchanges14 days in July 2026Relay of user requests through Claude
Xiaomi400K+ requests via 1,500 accountsMarch–April 2026Free-trial harvesting of transcripts

Model Rerouting: When Kimi Users Were Secretly Talking to Claude

Startup Fortune seven Chinese AI labs Claude
Source: startupfortune.com — https://startupfortune.com/anthropic-says-six-other-chinese-ai-labs-did-what-xiaomi-did-to-claude

Distillation and rerouting are different violations, and the report's rerouting evidence is what flipped the politics. Moonshot, according to Anthropic, forwarded nearly 300,000 requests from its own Kimi users to Claude and passed the answers back as if they came from Kimi. DeepSeek relayed more than 12.1 million exchanges across fourteen days in July. Startup Fortune's report notes that some of that relayed traffic contained Chinese police records, surveillance footage analysis and military-linked material — including a request asking Claude to flag "abnormal behavior" in CCTV footage.

That is the detail Beijing could not ignore. On the morning of September 22, Cyberspace Administration officials arrived at DeepSeek's Hangzhou offices and Moonshot's Beijing headquarters. From Washington's reading of the report, Chinese labs stole American capability. From Beijing's reading, Chinese users' data leaked to an American company without their knowledge, potentially in violation of Chinese data law. Market reaction was immediate: Zhipu's Hong Kong-listed shares fell as much as 12 percent, MiniMax slid 4 percent, and Alibaba dropped more than 4 percent — all in the same delicate week as preparations for a Xi Jinping and Donald Trump meeting with an AI incident-reporting mechanism on the agenda.

The Defense That Worked: Preserved Thinking and Fable's Guardrails

AI Breaking Wire daily brief
Source: www.aibreakingwire.com — https://www.aibreakingwire.com/news/ai-brief-2026-09-26

Not every attack succeeded, and the failures are as instructive as the successes. Zhipu reportedly tried to distill Anthropic's Fable model, hit its safeguards, and switched to Claude Opus 4.6 specifically because its defenses were weaker. Anthropic's countermeasure is called preserved thinking: the conversation context, including the system prompt and available tools, is cryptographically locked so a new API session cannot tamper with what preceded the model's reasoning, and the model summarizes its internal thinking before responding, making even a fully captured transcript far less useful as training data.

The pressure is not only corporate. On September 8, the NSA, FBI and CISA issued a joint advisory naming six Chinese AI companies for industrial-scale distillation, and a White House memo in April had already framed model extraction as a national security issue. The pattern to watch: every defensive layer that degrades the developer experience — heavier filtering, no raw reasoning, locked contexts — is also a tax paid by legitimate customers. That trade-off, not the espionage, may decide who wins the API business.

My Take / The Bottom Line

Read this story as proof that the moat of a closed frontier model is no longer just the weights — it is whether you can stop strangers from draining your capability one API call at a time. Anthropic's report is credible in its specifics but unproven in a courtroom, and seven companies' collective silence is not a verdict. The genuinely important shift is that Beijing treated the document as a leak case rather than a defamation problem, which tells you the evidence was real enough to be dangerous to its own champions. For buyers, the lesson is practical: the next frontier model you evaluate should be judged on extraction defenses, not just benchmark scores, because a lab that cannot protect its own reasoning chain is a lab whose pricing power has an expiration date.

FAQ

What is AI distillation?

Distillation is training a smaller, cheaper model on the outputs — especially the intermediate reasoning traces — of a larger frontier model, letting the smaller system copy advanced capabilities without paying frontier-scale pre-training costs.

Which companies did Anthropic accuse in its September 2026 report?

Seven China-based labs: Alibaba, DeepSeek, Moonshot AI, Zhipu, MiniMax, Xiaomi and SenseTime, together responsible for roughly 190 million exchanges with Claude between December 2025 and August 2026.

Why did China's CAC investigate DeepSeek and Moonshot?

Because the same Anthropic evidence showed Chinese user data — including police and military-linked material — being relayed to a US company's servers without users' knowledge, which Beijing reads as a Chinese data-law violation rather than a capability-theft story.

What is model rerouting?

Rerouting is when an AI product quietly forwards its users' questions to a competitor's model and displays the answers as its own. Moonshot allegedly did this with nearly 300,000 Kimi user requests sent to Claude over ten days.

Did the distillation attacks actually succeed?

Anthropic's report implies partial success against some targets, but also documents failures — Zhipu reportedly could not extract Fable's reasoning and pivoted to the more weakly defended Opus 4.6. None of the claims have been tested in court.

FacebookXWhatsAppEmail