In September 2026, a quiet but consequential dispute emerged between Anthropic and several Chinese AI laboratories over the practice of model distillation — the harvesting of one system's reasoning to train another. Anthropic named DeepSeek, Moonshot AI, Xiaomi, and Alibaba as participants in what it characterized as unauthorized extraction at scale, while China's Foreign Ministry dismissed the allegations as geopolitical distortion rather than technical fact. The exchange reveals something older than any algorithm: the enduring tension between those who build knowledge and those who seek to i
China Rejects Anthropic's Claims of AI Model Misuse by Chinese Labs
China rejected the accusation as fact-distorting, not the practice itself
So Anthropic is saying Chinese labs basically used Claude as a training tool without permission. How exactly does that work?
They redirected user queries to Claude, captured the model's reasoning, and fed that into their own systems. It's like having someone solve a complex problem, then using their solution method to teach your own team.
But we should be clear—Anthropic made these claims in a report. We don't have independent verification of the scale or even confirmation that the companies named actually did this.
And China just said no?
More or less. They called it fact-distorting and said they support beneficial AI. They didn't engage with the specific allegations.
Right. Which is notable. If the practices were clearly happening, you'd expect either a denial with evidence or an explanation of why it's legitimate. Instead, it's a categorical rejection of the framing.
Does this matter beyond the companies involved?
It matters because it shows how AI development is becoming a geopolitical flashpoint. Data security, intellectual property, training methods—these are all contested now.
And we don't yet have international norms around what's acceptable. Model distillation itself isn't illegal, but unauthorized query redirection is murkier.
So this could happen again?
Almost certainly. Until there are clearer rules or enforcement mechanisms, companies will keep pushing boundaries and governments will keep denying or defending them.
The real question is whether Anthropic's public report changes anything, or if it's just positioning for future negotiations.
Der Puls
- Anthropic published a report naming specific Chinese AI companies it accused of systematically redirecting user queries to Claude in order to harvest its reasoning for their own model training.
- The allegations carried serious implications beyond intellectual property — Anthropic suggested that confidential third-party data, including internal surveillance footage from facilities in Chengdu, may have been inadvertently exposed through these redirections.
- China's Foreign Ministry responded swiftly, with spokesperson Mao Ning calling the report a fact-distorting attempt to smear China, without addressing any of the specific technical claims.
- The rhetorical gap between Anthropic's granular technical accusations and Beijing's broad geopolitical rebuttal left the core dispute entirely unresolved.
- The confrontation now sits uneasily at the frontier of AI governance, where model distillation is legal, unauthorized query redirection is contested, and no international framework yet exists to adjudicate the difference.
In September 2026, a quiet but consequential dispute emerged between Anthropic and several Chinese AI laboratories over the practice of model distillation — the harvesting of one system's reasoning to train another. Anthropic named DeepSeek, Moonshot AI, Xiaomi, and Alibaba as participants in what it characterized as unauthorized extraction at scale, while China's Foreign Ministry dismissed the allegations as geopolitical distortion rather than technical fact. The exchange reveals something older than any algorithm: the enduring tension between those who build knowledge and those who seek to inherit it, and the absence of shared rules to govern the difference.
In September 2026, Anthropic published a report alleging that Chinese AI laboratories — including DeepSeek, Moonshot AI, Xiaomi, and Alibaba — had engaged in coordinated model distillation attacks against Claude. The company claimed these entities had systematically redirected user prompts to its system, capturing Claude's reasoning chains to train their own models. Beyond the intellectual property concern, Anthropic warned that the process may have inadvertently exposed sensitive third-party information, including internal surveillance footage from facilities in Chengdu. The decision to name specific companies signaled a deliberate push for accountability.
China's Foreign Ministry responded quickly and categorically. Spokesperson Mao Ning rejected the allegations as an effort to "smear China by distorting facts," reaffirming Beijing's commitment to beneficial AI development without engaging with any of the technical specifics Anthropic had raised. The response followed a familiar pattern: reframing a pointed accusation as a symptom of Western hostility toward China's technological rise, rather than addressing the underlying practices.
The dispute exposes a structural fault line in global AI development. Model distillation is a legitimate and widely used technique, but the unauthorized redirection of user queries to extract proprietary reasoning occupies a legal and ethical gray zone that existing frameworks have not resolved. Anthropic sees the practice as a violation; Beijing does not accept that framing. What neither side has yet offered is a path toward concrete norms — leaving the question of what constitutes fair competition in AI training as contested as ever.
Anthropic, the artificial intelligence company behind Claude, published a report in September 2026 documenting what it described as coordinated efforts by Chinese laboratories to extract and repurpose its model's responses. The company alleged that entities including DeepSeek, Moonshot AI, Xiaomi, and Alibaba had systematically redirected user prompts to Claude in order to capture the model's reasoning chains and use that material to train their own systems. This practice, known as model distillation, is a recognized technique in AI development where a less sophisticated system learns from the outputs of a more advanced one. What distinguished Anthropic's accusation was the scale and method: the company suggested these redirections were unauthorized and potentially exposed sensitive third-party information in the process, including internal surveillance footage from facilities in Chengdu.
China's Foreign Ministry responded swiftly and categorically. Spokesperson Mao Ning, speaking at a regular briefing, rejected the allegations as an attempt to "smear China by distorting facts." The statement reframed the dispute around Beijing's broader commitment to artificial intelligence development, with Mao Ning emphasizing that China supports the use of AI for beneficial purposes. The response did not directly address the specific technical claims Anthropic had made about model distillation or data exposure, instead positioning the accusation itself as a mischaracterization rooted in geopolitical tension rather than substantive evidence of wrongdoing.
The dispute sits at the intersection of two competing interests: Western AI companies' concern over intellectual property and data security, and China's rapid advancement in artificial intelligence through methods that sometimes blur the line between legitimate research and unauthorized extraction. Anthropic's report documented not just the alleged practice but also its potential consequences—the possibility that confidential information belonging to third parties could have been inadvertently compromised through these redirected queries. The company's decision to name specific Chinese entities suggested a deliberate effort to create accountability and transparency around the practice.
Mao Ning's response, by contrast, avoided engaging with the technical specifics. Instead, it treated the report as part of a broader pattern of Western criticism aimed at constraining China's technological development. This rhetorical move—reframing a specific allegation as a general attack—is characteristic of how Beijing has responded to similar accusations in other technology domains. It allows the government to reject the claim without either confirming or denying the underlying practices, while simultaneously asserting China's right to pursue AI development on its own terms.
The tension reflects a deeper structural problem in global AI governance. As companies like Anthropic invest heavily in developing advanced models, they face the challenge of protecting those systems from being reverse-engineered or their outputs being harvested at scale. Model distillation itself is not illegal, but the unauthorized redirection of user queries to extract proprietary reasoning represents a gray area where technical capability, intellectual property law, and international norms have not yet fully aligned. China's response suggests it does not accept the framing of these practices as violations, viewing them instead as part of the normal competitive landscape of AI development. What remains unresolved is whether either side will move beyond rhetorical positioning toward concrete agreements about acceptable practices in training and deploying large language models.
Bemerkenswerte Zitate
China firmly opposes attempts to smear China by distorting facts— Mao Ning, Chinese Foreign Ministry spokesperson
Beijing supports the use of artificial intelligence for good— Chinese Foreign Ministry statement