June 27, 2026

29 Million Questions

Anthropic sent a letter to US senators this month accusing Alibaba of running the largest known distillation campaign against a Western AI lab. The numbers are staggering: nearly 29 million exchanges with Claude, routed through roughly 25,000 fraudulent accounts, targeting the model's most commercially valuable capabilities, including software engineering and agentic reasoning [1].

Distillation, in this context, is not some exotic attack. You feed carefully constructed queries to a frontier model, collect the responses, and use them to train a cheaper rival system that approximates the original's capabilities. No code injection, no zero-day exploit. Just a lot of questions, asked very fast, by someone who is not supposed to be building a replica [2].

The scale problem

What makes this noteworthy is the scale. Anthropic previously accused three smaller Chinese labs, DeepSeek, MiniMax, and Moonshot AI, of distillation campaigns totalling about 16 million exchanges across 24,000 accounts. The Alibaba campaign alone exceeded all three combined. We are talking about industrial-scale data harvesting, not a few curious researchers pushing the limits of an API [3].

And the timing is uncomfortable. The White House flagged distillation as a national security concern back in April, when the OSTP director published a memo committing the government to share intelligence about foreign distillation campaigns with US labs. The Alibaba operation reportedly ran from April through June, meaning it continued after the administration drew its line in the sand [4].

Why this is hard to stop

Here is the uncomfortable technical reality: there is no clean way to distinguish a distillation query from a legitimate one. A developer asking Claude to help debug code could be working on a real product. Or they could be building a training dataset. The query looks identical. The response looks identical. The only signal is volume and pattern, which is why Anthropic had to detect 25,000 coordinated accounts rather than block a single bad actor.

Rate limiting helps but does not solve the problem. A determined operator can spread queries across thousands of accounts, each staying under individual thresholds. The fundamental issue is that API access means the model's outputs are, by design, available to anyone who pays. Once those outputs leave the server, there is no technical mechanism to prevent them from being saved, catalogued, and used as training data [5].

Anthropic's awkward position

There is a layer of irony here that is hard to ignore. Anthropic is simultaneously asking the US government to crack down on Chinese labs extracting its technology, while fighting the same government's decision to restrict its own Fable 5 and Mythos 5 models under export controls imposed less than two weeks ago. The company needs Washington's help to protect its intellectual property, but it is also in an active dispute with Washington over whether its products can be deployed at all [6].

The letter to senators is an attempt to separate these two issues. Protecting US models from foreign distillation and allowing those models to operate commercially are, Anthropic argues, complementary goals. Whether lawmakers see it that way will shape the regulatory environment for the entire industry.

What happens next

A bipartisan group of senators is planning an amendment to defence legislation that would blacklist or sanction any Chinese firm found improperly accessing US AI model output. A parallel House bill is also in the works. If either gains traction, the consequences could extend well beyond Anthropic, establishing an intellectual property border around AI systems that exist as software, not hardware, and that can be copied through nothing more than a well-crafted prompt [7].

Meanwhile, Alibaba's American depositary receipts dropped more than 3% on the news, falling below $100 in afternoon trading. The company also sued the Defense Department this week over its addition to the Pentagon's Chinese military companies blacklist, calling the designation baseless. The distillation accusation opens a second front, framing Alibaba not just as a company with alleged military ties but as an active participant in what Anthropic calls the systematic theft of American AI capabilities [8].

The real question

Strip away the geopolitics and the stock prices, and the core question is simple: what does ownership mean when your product is a model that answers questions? If someone can replicate your multi-billion-dollar model by asking it enough questions, the concept of a trade secret gets very fuzzy. The law has not caught up. The technology has not solved it. And 29 million queries suggest that someone is very motivated to find out.

← All posts

Sources

  1. Bloomberg, "Anthropic accuses Alibaba of illicitly accessing its AI models," June 24, 2026. Reported by The Next Web, June 25, 2026. ^
  2. BBC News, "Anthropic accuses Chinese rival Alibaba of illicitly extracting AI capabilities," bbc.com, June 25, 2026. ^
  3. The Next Web, "Anthropic accuses Alibaba of running largest distillation campaign against Claude," thenextweb.com, June 25, 2026. ^
  4. The Next Web, reporting on White House OSTP memo on AI model distillation, April 2026. thenextweb.com. ^
  5. TechRadar, "Anthropic says Alibaba may have copied Claude by asking it millions of questions," techradar.com, June 27, 2026. ^
  6. The Next Web, reporting on the Commerce Department's export control order on Fable 5 and Mythos 5, June 2026. thenextweb.com. ^
  7. Nikkei Asia, "Anthropic accuses Alibaba of 'largest known distillation attack' on Claude," asia.nikkei.com, June 2026. ^
  8. Business Insider, "Anthropic accused Alibaba of exploiting its AI models," businessinsider.com, June 2026. ^