Anthropic Alibaba Distillation Dispute Escalates AI Security War

Anthropic has publicly accused Alibaba of conducting a large-scale campaign to extract capabilities from its Claude AI models using nearly 25,000 fraudulent accounts and 28.8 million interactions. The allegation intensifies concerns over AI model security, intellectual property theft, and the growing geopolitical dimension of frontier AI development.

Jun 26, 2026
Anthropic Alibaba Distillation Dispute Escalates AI Security War
Source: SQ Magazine

Anthropic has escalated tensions in the global AI race by accusing Chinese technology giant Alibaba of orchestrating what it describes as the largest known campaign to illicitly extract capabilities from its Claude AI models.

In a letter sent to U.S. Senators Tim Scott and Elizabeth Warren on June 10, the company alleged that operators affiliated with Alibaba and its Qwen AI lab used nearly 25,000 fraudulent accounts to generate approximately 28.8 million exchanges with Claude between April 22 and June 5.

The campaign, described by Anthropic as a "distillation attack," targeted Claude's most advanced features, including software engineering, agentic reasoning, and complex decision-making processes.

"These distillation attacks are illegal, systematic, and industrial-scale attempts to steal U.S. frontier AI capabilities and repackage them as their own, without bearing the R&D costs required to train advanced models." – Anthropic letter to U.S. Senators

Distillation itself is a widely accepted machine learning technique where a smaller model is trained on the outputs of a larger, more capable "teacher" model.

The dispute hinges on the method of access, with Anthropic arguing that Alibaba's use of fraudulent accounts to systematically query Claude for the purpose of training rival models constitutes intellectual property theft and a national security concern.

The company warned that such campaigns allow competitors to bypass the billions of dollars in research and development investment required to build frontier AI systems, effectively turning American innovation into a "massive subsidy for geopolitical competitors."

The allegations have drawn attention to the emerging concept of adversarial distillation, which industry analysts warn poses a new supply chain risk.

As analysts told Infoworld, "the enterprise supply chain no longer ends at software, APIs, and cloud regions—it now includes rented intelligence, and rented intelligence can be copied and redeployed well outside the safety controls it was born with."

Anthropic is urging Congress to impose penalties on organizations found conducting such attacks and to strengthen protections for advanced AI systems. The company's stance has been criticized by some in the AI community who argue that the issue lies in the use of fraudulent accounts and terms of service violations rather than the distillation technique itself.

The dispute unfolds as Anthropic prepares for a potential public listing and navigates a separate conflict with the U.S. government over export controls that forced it to disable its Fable 5 and Mythos 5 models globally.

The timing of the allegations has led observers to suggest that Anthropic may be using the distillation issue to reinforce its position as a defender of U.S. AI leadership. Alibaba has not publicly responded to the allegations.

The dispute underscores the intensifying competition in AI development between the U.S. and China and the growing recognition that access to frontier model outputs is increasingly viewed as a strategic asset worth defending.