Alibaba Ran the Largest Model-Theft Campaign Anthropic Has Ever Measured
Three PRC labs quietly fed customer prompts to Claude and trained on the answers, per Anthropic's new threat report — while Trump waves off extinction risk, China plans a 4x compute build-out, and Wipro tells Wall Street AI freed up 20,000 workers' worth of capacity.
September 11, 2026 · 8 min read · Issue #262
Lead
Anthropic published its fourth threat-intelligence report on misuse of Claude this week, and buried in the appendix is the most concrete evidence yet of how China's AI industry has actually been catching up. Alibaba's Qwen team ran what Anthropic calls the largest illicit distillation campaign it has ever measured: up to 3 million exchanges a day, from more than 3,500 fraudulent accounts, harvesting Claude Opus 4.6 and 4.7's chain-of-thought reasoning traces to train Qwen 3.5 through 3.7. Anthropic counted more than 151 million exchanges attributable to Alibaba between May and July alone (Anthropic).
Moonshot AI and DeepSeek did something arguably worse: rather than just scraping Claude via proxy accounts, both companies silently rerouted their own paying customers' requests to Claude, served up Claude's answers as if they were Kimi or DeepSeek outputs, then captured the exchanges to train their own models on Anthropic's dime. Anthropic says the intercepted traffic — over 23 million exchanges for Moonshot, and a comparable haul for DeepSeek — included live API credentials, internal capex spreadsheets from a pharmaceutical company, and, in one case, a user Anthropic assessed as likely PLA-affiliated running CCTV surveillance analysis through what they believed was a domestic model.
The distillation report lands the same week President Trump told reporters outside Dallas that he has "no" concerns about AI causing human extinction, days after an Anthropic safety researcher resigned publicly warning that Anthropic and OpenAI are "acting irresponsibly" (Business Standard). Trump's stated priority is unambiguous: "I have concerns that if we don't win AI, we're going to be put in a very bad position... We are leading China right now... a year, which is, you know, considered a lot."
China, meanwhile, is not conceding that year. Beijing's Ministry of Industry and Information Technology set a target this week of 9,800 exaflops of intelligent computing capacity by 2030 — more than four times the 2,185 exaflops it reported at the end of June — backed by 3.8 trillion yuan ($532 billion) in cumulative infrastructure investment through 2030 (South China Morning Post). Average daily AI token usage in China has already gone from 100 billion in early 2024 to 140 trillion in March this year. The compute race and the distillation race are the same race, run from opposite ends.
Briefs
Anthropic quits chip-policy trade group over China export controls. Anthropic is leaving the Information Technology Industry Council, an influential Washington trade group whose members include Google, OpenAI and Nvidia, after ITI lobbied to strip three chip export-control bills — the AI OVERWATCH Act, the Chip Security Act, and the MATCH Act — out of this year's defense authorization bill. Anthropic supports all three; ITI called them harmful to "American tech stack" dominance. It's the second major policy break between Anthropic and its industry peers this year, after Anthropic also declined to sign a July letter backing open-weight models over China competition fears (Axios).
Wipro says AI freed capacity equal to 20,000 workers — and it isn't cutting headcount. Wipro's CTO told press this week that the company's AI deployment across delivery has freed productive capacity equivalent to 20,000 employees, which the company is redeploying rather than eliminating, as part of what it's calling a new "human-AI operating model" for the 234,000-person IT services firm (The Economic Times / ETHRWorld). The framing — productivity gain, not layoffs — is becoming the standard line across Indian IT majors as AI-driven margin pressure collides with a politically sensitive jobs market ahead of state elections.
NPCI and HDFC Bank launch "FiMI," a sovereign AI model for retail banking. India's National Payments Corporation, which runs the UPI rail underneath most of the country's digital payments, unveiled a jointly built AI model with HDFC Bank at the Global Fintech Fest in Mumbai, aimed at fraud detection and retail banking workflows built on domestic infrastructure rather than foreign foundation models (CNBC-TV18). It's a small but telling data point in India's broader push toward AI sovereignty in financial infrastructure — the same instinct driving China's compute build-out and Mistral's sovereignty pitch in Europe below.
Newsom signs Anthropic- and OpenAI-backed AI safety bills in California. California Governor Gavin Newsom signed a package of AI safety legislation this week that both Anthropic and OpenAI lobbied for, continuing the state's role as the default regulator for frontier AI given the absence of a comprehensive federal framework (Politico). The bills add to a growing patchwork of state-level rules that labs increasingly treat as the real compliance floor while federal legislation stalls.
OpenAI adds an AI-risk researcher to its board. OpenAI named a prominent AI safety researcher — previously known for warnings about existential AI risk — to its board of directors, a move read as an attempt to shore up governance credibility after a string of safety-team departures and public criticism over the past year (TechCrunch). The appointment comes in the same week an Anthropic researcher resigned over similar concerns — a reminder that the safety-credibility gap between labs' public commitments and internal dissent hasn't closed.
Mistral raises €3 billion at a €21 billion valuation, with the EU and Samsung as new backers. France's Mistral AI announced a new funding round this week including direct investment from the European Union and South Korea's Samsung Electronics, pushing its valuation past €21 billion — still a fraction of Anthropic's or OpenAI's, but enough to confirm Mistral as the only European lab with a credible seat at the frontier table (Politico). The round lands as Mistral's CEO Arthur Mensch has to plan for life without the direct presidential sponsorship that helped land its Nvidia infrastructure partnership last year, with France's own political transition underway.
Google commits €13 billion to AI infrastructure in Finland. Google announced a €13 billion investment in Finnish data-center and AI infrastructure capacity, one of the largest single European AI infrastructure commitments this year and part of a broader pattern of US hyperscalers building out European capacity even as EU officials push for homegrown "sovereign AI" alternatives like Mistral (Bloomberg).
The View
The distillation report is the story of the week not because distillation is new — Anthropic disclosed its first cases in February — but because of the scale and the specific mechanism Moonshot and DeepSeek used. Silently rerouting your own customers' queries to a rival's model, serving the rival's output under your own brand, and then training on the intercepted exchanges is not an edge case of aggressive competitive intelligence. It is, per Anthropic's own read, "likely inconsistent with privacy laws and the labs' own terms of service" — a sentence doing a lot of work for a company that still sells API access in markets where DeepSeek and Moonshot compete for the same enterprise customers.
What makes this consequential rather than merely embarrassing is the safety inheritance problem Anthropic flags almost in passing: distilled models don't inherit the safeguards of the model they're distilled from. A model trained on Opus's reasoning traces can pick up dangerous-capability uplift in biology or cyber domains "even when the harvested exchanges contain little about those subjects," because general reasoning ability transfers across domains while safety training does not. If that holds, every successful distillation campaign against a frontier model is potentially also an uncontrolled proliferation event for capabilities the original lab spent significant resources trying to gate.
Set against China's public 2030 compute target, this reads less like corporate self-interest and more like a genuine bottleneck problem for Beijing's frontier labs. If domestic labs could match Western capability through legitimate scaling and algorithmic gains alone, they would not need cross-session replay attacks to trick Claude into echoing its own chain-of-thought back through a translation prompt. The compute build-out is the long-run answer; distillation is the shortcut being taken while the long-run answer is under construction.
The Miss
Coverage of Trump's Dallas comments on AI extinction risk largely framed the story as a gaffe or a culture-war moment — Trump dismissing "doomer" concerns — without connecting it to the substantive policy fight happening in the same news cycle: Anthropic's split from ITI over chip export controls. Both stories are actually about the same underlying question, which the press treated as two separate beats. Trump's stated logic — that the US "leading China... by a pretty good period" on AI is the thing worth protecting, and that extinction risk is subordinate to that — is functionally identical to the export-control position Anthropic is lobbying for, even though Anthropic frames its position as safety-motivated and Trump frames his as competition-motivated. The Wipro and NPCI items on capacity gains and sovereign models got covered as pure business or fintech news, with almost no outlet drawing the throughline to the same week's China compute-expansion plan — three countries independently converging on the same strategic instinct (build sovereign capacity, redeploy rather than shed labor) got reported as three unrelated regional stories.
Pull Quotes
"I have concerns that if we don't win AI, we're going to be put in a very bad position. We are leading China right now by a pretty good period. I would say a year, which is, you know, considered a lot."
— President Donald Trump, on AI extinction risk vs. the China race (Business Standard)
"These practices are likely inconsistent with privacy laws and the labs' own terms of service."
— Anthropic, on DeepSeek, Xiaomi, and Moonshot feeding user conversations into Claude for distillation (Anthropic threat intelligence report, September 2026)
"Anthropic informed us of its decision to leave ITI because of the broad consensus position of the ITI membership that the Chip Security Act, AI OVERWATCH Act, and MATCH Act should not advance in the NDAA."
— ITI spokesperson, on Anthropic's departure from the trade group (Axios)
Reads & Links
- Anthropic, "Detecting and countering misuse of AI: September 2026" — the full threat-intelligence report with all seven harm-area case studies, including cyber operations tied to suspected Russian state actors: anthropic.com
- Ars Technica on the same report's China-distillation findings, with additional analyst reaction: arstechnica.com
- SCMP on China's MIIT five-year compute plan and the "East Data, West Computing" build-out it extends: scmp.com
- Politico on the California AI safety bills Newsom signed this week: politico.com
- Politico's deep dive on Mistral's relationship with Macron's government and what changes with a new French president: politico.eu
Out
That's issue #262. Distillation, compute, and sovereignty are turning out to be the same story told from three different capitals — tomorrow we'll see which one moves first.