Anthropic Accuses Alibaba of Massive AI Distillation Attack on Claude Amid Regulatory Focus

The White House's Office of Science and Technology Policy had issued a memorandum pledging to help AI companies detect and coordinate against industrial-scale distillation, signaling heightened federal focus on AI governance alongside Anthropic's allegations.
Anthropic previously disclosed three other industrial-scale distillation campaigns from DeepSeek, Moonshot, and MiniMax in February, and urged collaboration across the AI industry, cloud providers, and policymakers to counter the threat.
The June 10 letter to Sen. Tim Scott and Sen. Elizabeth Warren described the attack as 'the largest known distillation attack' against Claude and was delivered ahead of a forthcoming Senate Banking Committee hearing on AI.
Alibaba did not immediately respond to CNBC's request for comment regarding the allegations.
Bloomberg was the first to report the existence of the letter detailing the distillation allegations, as reported and cited in subsequent coverage.
Anthropic has accused Alibaba of running the largest known AI distillation attack ever recorded, involving about 28.8 million exchanges across roughly 25,000 fake accounts over just 44 days, according to Bloomberg. The company sent a formal letter on June 10 to Senators Tim Scott and Elizabeth Warren detailing the alleged scheme, which it linked to Alibaba's Qwen AI lab.
"Distillation" means training a cheaper AI model by feeding it outputs from a more advanced one — in this case, Claude — to copy its capabilities without the costly original research. Anthropic says the operation ran from April 22 to June 5, 2026, and targeted Claude's software engineering and agentic reasoning skills, according to CNBC.
Anthropic's internal forensic team linked clusters of fraudulent accounts to infrastructure tied to Alibaba's Qwen AI lab, according to CNBC. The 25,000 accounts were designed to bypass rate limits and detection systems. Over 44 days, they generated 28.8 million structured exchanges — not casual queries, but highly targeted prompts designed to extract specific reasoning logic from Claude.
Anthropic framed the incident as more than a business dispute. The company said it goes to the heart of "American AI leadership" and requires coordinated action from government, cloud providers, and the wider AI industry. Alibaba did not immediately respond to CNBC's request for comment.
This is not Anthropic's first distillation alarm. In February 2026, the company disclosed three other industrial-scale campaigns tied to Chinese AI labs: DeepSeek, Moonshot, and MiniMax. Anthropic called for the AI industry to share intelligence and work together to stop what it described as a pattern of "rapid capability acquisition" by foreign competitors.
The June allegations against Alibaba represent a sharp escalation. Earlier campaigns focused on general conversational data. The Alibaba operation, by contrast, zeroed in on agentic reasoning — the ability of an AI to plan and execute multi-step tasks — and advanced software engineering, according to the Anthropic letter cited by Bloomberg.
Two days after Anthropic's letter, the White House Office of Science and Technology Policy issued a memorandum on June 12 pledging to help AI companies detect and coordinate against industrial-scale distillation. The memo signals that the federal government now views distillation as a priority threat to the U.S. AI ecosystem.
Senators Scott and Warren have used the letter to push for stricter "Know Your Customer" rules for cloud providers. Senator Warren called the incident "corporate espionage via API." Senator Scott focused on protecting American intellectual property from state-linked foreign entities. A Senate Banking Committee hearing on AI is expected to put these proposals front and center.
Not everyone agrees the practice itself is illegal. Distillation is widely used in AI development, including by U.S. startups. Some researchers argue the legally actionable part of Anthropic's claim is the use of 25,000 fraudulent accounts — not the distillation technique itself, since the data was pulled through a paid API.
Critics of the U.S. stance say the allegations may also serve a strategic purpose: justifying tighter controls on API access for Chinese firms and limiting the rise of competitive open-source models like Qwen. Market analysts noted volatility in Alibaba stock after Bloomberg published the story, warning that sanctions or restricted U.S. cloud access could hurt Alibaba's international expansion plans.
Publishers
20
Articles
71
Reach
91