Author: Core Contributor of Biteye Denise
Anthropic has once again included Chinese AI companies in its threat intelligence report.
On September 10, Claude's developer Anthropic released its latest report, naming Alibaba, Darkmoon, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax, accusing them of engaging in unauthorized model distillation activities.
The largest of these involved Alibaba: Anthropic claimed that from May to July of this year, it observed over 151 million interactions attributable to Alibaba, used for extracting Claude's reasoning capabilities.
Another part of the allegations directly relates to users: Anthropic stated that Darkmoon and DeepSeek had forwarded some user requests to Claude and then returned Claude's answers to the users; other companies were accused of using user conversations to generate training data.
Of course, these are the results of the investigation published by Anthropic.
01 First, let's see what this report says
The whole report covers the AI abuse activities that Anthropic claims to have discovered and stopped between December 2025 and August 2026, involving seven types of issues: cyber attacks, surveillance, public opinion manipulation, fraud, biological field abuse, conventional weapons development, and distillation.
One of the main observations in the report is that attackers are increasingly allowing AI to execute and coordinate tasks directly.
For example, automatically advancing network intrusions, or operating a large number of fake social accounts.
Directly related to domestic models is the final distillation chapter. The accusations against the seven companies are as follows:

These figures are all statistics from Anthropic, with different observation periods, so they cannot be directly treated as usage rankings for the same period.
02 Why is "distillation" marked as "illegal"?
Distillation can be understood as having one model learn from another model: first, let the more capable "teacher model" generate answers or problem-solving processes, and then use these materials to train the "student model", allowing it to learn similar handling methods.

Distillation itself is a common training method. Anthropic also clearly acknowledges this in the report.
What it refers to as "illegal distillation" specifically indicates the extraction activities carried out without authorization, in a covert manner, and reaching an industrial scale. According to the report description, related activities may use proxy "transit points," fake accounts, or stolen credentials to bypass access restrictions and then gather model outputs in large quantities.
The focus of this dispute is the reasoning process of the model. The final answer tells the student "what to choose for this question," while the reasoning process can provide training materials on "how to analyze and complete tasks." Anthropic claims that the related activities mainly target capabilities such as programming, tool invocation, data analysis, and long-term tasks.
Therefore, judging the controversy requires examining where the data comes from, whether access was authorized, whether restrictions were bypassed, and whether users were informed. Merely using "distillation technology" does not determine whether a company's specific actions are illegal.
03 Why are user data also involved?
According to the report, some Darkmoon and DeepSeek users thought their requests were given to the selected model, but were actually forwarded to Claude.
If the allegations are true, users need to question: which service providers accessed their information, and whether it was used for model training?
However, the original text has different levels of certainty regarding whether users were notified.

For example, in the section about Darkmoon, it states that Anthropic does not know whether the company informed its customers.
Anthropic also raised security concerns: extracting model capabilities does not necessarily replicate the original model's security limitations. This is one of the reasons why it included distillation in the threat report.
The disclosed countermeasures include detecting abnormal extraction behaviors, banning relevant accounts, replacing complete reasoning content with summaries, and strengthening identity verification.
04 How did the named companies and the industry respond?
As of September 11, 2026, when this material was verified, no verifiable formal response from the seven companies regarding this September report had been found.
There has already been public discussion in the industry. The following statements all predate the September report and belong to the background of the controversy.
On July 24, Microsoft released an open letter signed by companies such as Hugging Face, Meta, Mistral, and NVIDIA.
The letter argues that policymakers should distinguish between normal model development techniques and improper encroachments: distillation is a widely used method for model improvement; issues caused by illegal extraction of closed-source model values should be addressed through targeted laws and business rules and should not be generalized into a one-size-fits-all restriction on technology.
There are also technical disagreements.
On July 23, TechCrunch, discussing the distillation controversy of Kimi K3, quoted AI researcher Nathan Lambert's view: as models approach the cutting edge and the training focus shifts to reinforcement learning, it is challenging to explain all capability enhancements solely relying on supervised fine-tuning-like distillation.
Braden Hancock, a researcher at Laude Institute and co-founder of Snorkel AI, also believes that U.S. public opinion underestimates the technical strength of Chinese teams.
These viewpoints discuss the technical effects and regulatory boundaries of distillation, and do not verify the allegations of the September report item by item. Future attention will still be needed on whether the named companies respond specifically to account and data source inquiries, whether user requests have been forwarded, and how the relevant training data was authorized.
05 In conclusion
Distillation itself is not a sin; normal technical borrowing and unauthorized large-scale capability extraction should not be confused.
Currently, what the outside world sees is still mainly Anthropic's one-sided investigation conclusions, and the named companies have not publicly responded to key details. How the 151 million interactions are attributed, whether user requests were forwarded with authorization, and which conversations were used for training all require more evidence and explanations from the involved companies.
For ordinary users, this controversy is not far away. When we provide code, business information, or even private conversations to an AI, the entity processing that information may not just be the model displayed on the page.
AI companies are competing for the capabilities of the next generation of models, but what may be implicated are the data of every individual.
When a conversation is forwarded, stored, or even used for training without the user's knowledge, we may need to re-examine: in front of the AI's input box, are we truly users of the product, or raw materials for training the product?
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。