Chinese artificial intelligence companies attempted to clone American AI models by funneling real Chinese user queries to them via a network of intermediate platforms, Anthropic said in a report published Thursday.
Companies including Moonshot AI and DeepSeek used these middlemen to relay millions of their own users' queries, including ones containing sensitive data such as location information and passwords, to Anthropic's Claude, the report alleges, offering a detailed new look at the cloning technique known as distillation that American officials liken to industrial-scale theft.
U.S. labs generally ban outside distillation of their proprietary models, but American officials say the technique remains a widely used shortcut for rivals to catch up to more advanced competitors.
The details about AI theft come as concerns are mounting inside AI companies and Washington about the potential safety risks of powerful AI models, with some safety advocates and companies calling for a slowdown in AI research.
Anthropic in its report said it has seen increasing evidence that Claude was used for things like criminal hacking campaigns and potentially dangerous biological research. In one case, a user attempted to adapt avian flu to infect mammals. OpenAI has also seen similar types of queries about bioweapons and poisons, The Wall Street Journal has reported.
"Where before we were hypothetically worried about these classes of misuse, I think we've moved away from hypothetical to real," said Jacob Klein, Anthropic's head of threat intelligence.
The key to the Chinese distillation effort was the series of illicit intermediary services-called transfer stations-that in turn connected to Claude, Anthropic said. These sites operate in jurisdictions outside of China and often used stolen or fraudulently obtained credentials to access U.S. AI services, according to Anthropic.
Using the transfer stations to access Claude, the Chinese performed their distillation by monitoring the back and forth communications between their customers and products such as Claude, Anthropic said.
"This would be a large scandal if somebody like Anthropic or one of our peers did what they're doing," said Jacob Klein, Anthropic's head of threat intelligence.
Distillation, a vector by which powerful AI spreads, has been a focus of U.S. attention. Michael Kratsios, a top AI adviser to President Trump as director of the White House Office of Science and Technology Policy, said in late July that Moonshot, the maker of the popular model series Kimi, distilled Anthropic's Fable tool for the development of its K3 model. Treasury Secretary Scott Bessent warned at the time that sanctions and blacklists could be used against Chinese companies engaging in "industrial-scale distillation attacks."
Administration officials have been considering such restrictions for months, but many companies have warned that harsh crackdowns on Chinese model developers could end up hurting U.S. businesses that rely on them. Lawmakers have introduced legislation that would make it easier for companies to coordinate their responses to distillation without having to worry about antitrust concerns.
Anthropic says in its report that some of the schemes go beyond the normal distillation methods companies use and instead resemble sophisticated illicit schemes.
In one case, Anthropic said, a user asked Moonshot's Kimi AI service to analyze surveillance data of one person taken from hundreds of closed-circuit television system cameras in Chengdu, China. Moonshot routed that data to Claude, using a network of middlemen. In another, Kimi passed on login credentials for several companies to Claude when an engineer tried to use Kimi's service to build software for a Chinese company.
"The user had no way of knowing that their use of Kimi was being forwarded to Claude," the report states.
Using a network of thousands of fake accounts, Moonshot had more than 23 million exchanges with Claude between May and July of this year, the report said.
DeepSeek also quietly passed on sensitive customer information to Claude as part of a similar distillation effort, Anthropic said. In total, seven China-based labs attempted to learn new Claude capabilities via distillation over the past seven months, the company said.
A Moonshot spokesperson declined to comment on Anthropic's allegations. DeepSeek didn't respond to messages seeking comment.
Chinese companies haven't denied that they engage in distillation, but earlier this year, a Moonshot executive told local media that the company's Kim K3 achieved "breakthrough performance" due to fundamental innovations, not distillation or copying. A spokeswoman at China's Foreign Ministry said Wednesday that the U.S. should stop making false accusations and smearing China.