AI & Models
Anthropic accuses Chinese AI labs of mining Claude for model training
Anthropic alleges three Chinese AI labs used more than 24,000 fake accounts to mine its Claude model, fueling debates over the necessity of strict AI chip export controls.
US-based AI safety company Anthropic has accused three Chinese AI labs—DeepSeek, Moonshot AI, and MiniMax—of setting up more than 24,000 fake accounts to conduct more than 16 million exchanges with its Claude model. According to Anthropic, the activity was aimed at “illicit distillation,” a training method where one AI model learns from the output of another to improve its own capabilities. The allegations follow a memo sent by OpenAI to House lawmakers earlier this month, which reported that DeepSeek used distillation to mimic its products.
The scale of the targeted exchanges varied significantly among the three Chinese entities:
- MiniMax: 13 million exchanges, which targeted agentic coding, tool use, and orchestration.
- Moonshot AI: More than 3.4 million exchanges targeting agentic reasoning—the AI capability to perform tasks autonomously—as well as tool use, coding, data analysis, computer-use agent development, and computer vision. Last month, Moonshot released its Kimi K2.5 model.
- DeepSeek: More than 150,000 exchanges that appeared aimed at improving foundational logic and alignment, specifically around censorship-safe alternatives to policy-sensitive queries. This follows DeepSeek’s release of its open source R1 reasoning model a year ago.
The incident has intensified discussions around export controls—government restrictions on selling technology to foreign entities—particularly regarding advanced AI chips. Last month, the Trump administration allowed U.S. companies like Nvidia to export advanced AI chips to China. However, Anthropic asserts that the scale of extraction performed by the Chinese labs requires access to advanced chips, arguing that distillation attacks reinforce the rationale for export controls. Dmitri Alperovitch, chairman of the Silverado Policy Accelerator and former CTO of CrowdStrike, supported this view. “It’s been clear for a while now that part of the reason for the rapid progress of Chinese AI models has been theft via distillation of U.S. frontier models. Now we know this for a fact,” Alperovitch said.
Beyond commercial competition, Anthropic warns of significant safety and national security risks. The company asserted that models built through illicit distillation are unlikely to retain safety safeguards. This creates a risk that “dangerous capabilities can proliferate” with many protections stripped out entirely, potentially allowing state and non-state actors to deploy these models for offensive cyber operations, disinformation campaigns, or mass surveillance.
Why it matters
The incident highlights the growing tension between open-model development and national security. Anthropic argues that illicit distillation undermines US export controls and risks the proliferation of models stripped of safety guardrails, complicating the global race for AI dominance.