A new report released by Anthropic on September 10, 2026, has generated considerable discussion on social media. The report raises concerns about a practice known as "illicit distillation," which involves using AI models from one company to train competing models without permission. Anthropic has been monitoring this activity for several months, alleging that Chinese-based companies have bypassed their terms of service to extract capabilities from their AI models at a lower cost. The report specifically names Alibaba as a major case, citing over 151 million interactions between May and July 2026, involving more than 5,000 fraudulent accounts. At its peak, these interactions reached nearly 3 million requests per day, allegedly used to extract reasoning processes from Anthropic’s Opus 4.6 and 4.7 models to train Alibaba’s Qwen 3.5, 3.6, and 3.7 models.
Anthropic also accuses Moonshot AI (Kimi) and DeepSeek of secretly redirecting some of their users’ traffic to Claude, one of Anthropic’s AI models, without consent. These redirected requests were allegedly used to train Moonshot and DeepSeek’s own models. According to the report, Moonshot AI is said to have relayed nearly 300,000 requests in ten days, mostly to the Opus model. There are also allegations of suspicious activity, including a user possibly linked to the Chinese military querying surveillance footage to assess whether a person was acting "abnormally." Additionally, an engineer from a Chinese state-owned company is said to have accidentally exposed internal code and identifiers of major companies.
The report claims that Moonshot and DeepSeek bypassed a technical safeguard designed to prevent the extraction of Claude’s reasoning by using a "signature" reference from the API instead of the full reasoning trace. This allowed them to open new sessions, prompting Claude to generate full reasoning traces. Anthropic states it has since strengthened its protections against such methods.
In another part of the report, it is revealed that a group in northern Yemen used Anthropic’s Claude Code to develop guidance software for a rocket. The project involved dividing tasks among coding, research, and proofreading. The rocket was tested in real conditions but failed, after which the team used Claude to analyze the failure. While the report does not explicitly name the Houthi group, some social media accounts have linked them to the incident, as they control northern Yemen. The report differentiates this rocket from a long-range ballistic missile mentioned elsewhere, which was only tested in simulations.
Other findings in the report include Russian cyberespionage efforts, high-risk biological research, and surveillance of journalists and dissidents by authoritarian regimes. These topics have been previously covered in Anthropic’s earlier threat reports, highlighting ongoing concerns about the misuse of AI technologies.
Anthropic Report Details Alleged Model Theft and Misuse of AI Tools
AI-rewritten from original reportingHow it works
aiillicit-distillationanthropicalibabamoonshotdeepseek
Original sources:
- 🇫🇷Numerama



