Anthropic has accused Alibaba of running a large-scale, coordinated campaign to illicitly extract capabilities from its Claude AI models, escalating an already tense debate over how frontier AI labs protect their most valuable intellectual property.

In a letter disclosed on June 24, 2026 and reported by Reuters, The Wall Street Journal, Bloomberg, and CNBC, Anthropic said operators affiliated with Alibaba and its AI research arm Alibaba Qwen used roughly 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude. The company described the activity as a deliberate attempt to copy its technology through a technique known as distillation. For more context on this story, see our ongoing AI news.

What the Letter Alleges

According to Reuters, Anthropic said the campaign was conducted between April 22 and June 5, 2026. The company told lawmakers that the operation generated over 28.8 million interactions with Claude through nearly 25,000 fraudulent accounts, and that it was carried out by operators affiliated with Alibaba and Alibaba Qwen.

Anthropic framed the effort as more than a terms-of-service violation. In the letter, the company reportedly said distillation is a way to help accelerate China's ability to reach the capabilities of its advanced Mythos Preview model, raising the stakes from a commercial dispute to a question of national competitiveness and security.

The Wall Street Journal characterized the campaign as "brazen," while Bloomberg and CNBC echoed that Anthropic accused Alibaba of "illicitly" accessing its models. Alibaba did not immediately respond to a request for comment from Reuters.

Why Distillation Has Become a Flashpoint

Distillation is a widely used machine-learning technique in which a smaller or rival model is trained on the outputs of a more powerful model, effectively absorbing some of its knowledge without access to the underlying weights or training data. It is cheap, fast, and difficult to fully prevent once an API is publicly accessible.

For frontier labs like Anthropic, which spend hundreds of millions of dollars training flagship models, distillation represents an existential threat to their moat. A competitor that can query a model millions of times can potentially replicate much of its performance for a fraction of the cost. The technique has become one of the defining tensions of the current AI era, pitting openness against the economics of frontier model development.

The Anthropic allegation is notable because it ties distillation directly to a named corporate affiliate of a major Chinese technology company, rather than to anonymous scrapers or academic researchers. By attributing the campaign to Alibaba Qwen, Anthropic is pushing the issue from quiet industry grumbling into the congressional record.

The Senate Banking Committee Connection

The letter, dated June 10, 2026, was sent to Senators Tim Scott and Elizabeth Warren, the chair and ranking member, respectively, of the U.S. Senate Banking Committee, according to Reuters. It was submitted ahead of a scheduled hearing on AI.

That detail matters. By routing the disclosure through the Banking Committee, Anthropic is signaling that it views model extraction not merely as an engineering problem but as a financial and economic security issue — one that could warrant sanctions, export controls, or other tools traditionally used against illicit technology transfer.

Anthropic said in the letter that it was supportive of the U.S. government's efforts to combat such attacks, including partnering with private-sector AI companies through threat-intelligence sharing and other exercises.

A Threat 'Growing in Intensity and Sophistication'

This is not the first time Anthropic has warned about attempts to siphon its models' capabilities. The company has previously described a broader pattern of extraction attempts it attributes to actors in China, and said in the letter that such campaigns are growing in "intensity and sophistication."

Addressing the threat, Anthropic argued, would require "rapid, coordinated action among industry players, policymakers and the global AI community." The phrasing suggests Anthropic is lobbying not just for defensive measures on its own platform but for a collective, government-backed response.

The Broader Industry Context

The allegation lands amid a wave of model-security and competitiveness concerns. U.S. policymakers have spent much of 2026 weighing how to keep frontier AI advantages from leaking to foreign competitors, with export controls, chip restrictions, and now API-level extraction all in the mix. Reports that Chinese AI models are overtaking U.S. rivals in global token usage have intensified the urgency of that debate.

For Alibaba, the accusation comes at a delicate moment. The company's Qwen models have become among the most widely used open-weight systems in the world, and a formal allegation of illicit distillation could draw scrutiny from both U.S. regulators and enterprise customers weighing which models to trust.

Anthropic itself has been at the center of the security conversation. Its Mythos Preview model has reportedly demonstrated the ability to uncover vulnerabilities in classified U.S. government systems during testing, even as export-control disputes have at times cut parts of the National Security Agency off from the very model that found those flaws.

What Comes Next

The disclosure raises immediate practical questions. If Anthropic's attribution holds up, it could accelerate industry-wide adoption of tighter rate limits, behavioral monitoring, and account-verification systems designed to detect coordinated distillation. It may also embolden other labs to publicly name the actors they believe are behind similar campaigns.

More broadly, the letter could shape the next round of U.S. AI policy. A Senate hearing that began as a general examination of artificial intelligence may now have a concrete, high-profile case to anchor its discussion of how to protect frontier models from being copied.

Anthropic's message to lawmakers is clear: the threats are no longer hypothetical, they are attributed, and they are growing. Whether that produces new legislation, new industry norms, or simply sharper rhetoric remains to be seen. But the line between a frontier model and its imitators has rarely felt as contested as it does now.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →