The Extended Brief
Anthropic: Detecting and Addressing AI Misuse by China – September 2026

Brief by The AI News AI newsroom · Sep 11, 2026, 12:12 AM EDT edition
Original reporting by r/LocalLLaMA — /u/External_Mood4719 · published Sep 10, 2026, 11:21 PM EDT
Anthropic's September 2026 report names seven Chinese AI firms it alleges ran large-scale campaigns to siphon Claude's reasoning into rival models, escalating pressure on API access controls and enforcement.
Key points
- Anthropic's report alleges Alibaba extracted Claude Opus 4.6/4.7 chain-of-thought across 151 million-plus exchanges to distill into Qwen 3.5, 3.6, and 3.7. source ↗
- The report accuses Moonshot's Kimi of secretly forwarding user requests to Claude and saving its replies, exceeding 23 million exchanges. source ↗
- DeepSeek allegedly used cross-session methods to extract Claude Opus CoT, exceeding 12.1 million interactions in 14 days. source ↗
- Zhipu allegedly used Claude for training-data scoring and post-training and attempted to attack Fable, exceeding 3.4 million exchanges in 17 days. source ↗
- The report also names Xiaomi, SenseTime, and MiniMax, alleging replayed user sessions, brokered data purchases, and a shell-company proxy network. source ↗
The data
Volumes as alleged in Anthropic's report; SenseTime and MiniMax volumes were not disclosed.
Numbers from the original article, machine-verified against its text
Practical applications
- Audit your API traffic for the patterns described here: bulk CoT harvesting, cross-session probing, and replayed third-party dialogues.
- If your product exposes reasoning traces, reassess whether full chain-of-thought should be returned to untrusted or high-volume accounts.
- Verify provenance of any third-party training data you buy, since the report alleges brokers resold user-Claude conversations.
- Review how your organization verifies customer identity, given the allegation that a shell company proxied model access.
Context
Distillation means training one model on another model's outputs to cheaply copy its capabilities; frontier labs' terms of service typically prohibit using outputs to train competing models. Chain-of-thought (CoT) traces are especially valuable distillation material because they expose a model's step-by-step reasoning, not just final answers. The report alleges several firms obtained these traces at scale through forwarded user traffic, proxies, or purchased data.
What to watch
- Watch whether the named companies publicly dispute the allegations or whether Anthropic pursues account, legal, or policy action.
- Watch whether the report is cited in US export-control or AI policy debates around model access for foreign labs.
Related briefs
- Cognition launches new SWE-2 model, Rivaling Fable 5.1 and GPT-Astra
- Suno launches v6 music models built with Warner, BMG, and Believe
- DeepSeek launching v4.1 flash cheaper and more capable than v4 pro
- AI coding startup Cognition raises $2B at $48B valuation as revenue nears $900M
Editorial score 4.2 / 5 · significance 4.5 · novelty 4.5 · edge 4.5 · perspective 3.0
Desks: Business · Policy & Society
Topics: Governance & policy · Cybersecurity · Copyright
Evidence basis: Reviewed from the article's full text
This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.