Anthropic Says Chinese AI Firms Quietly Extracted Its Claude Model at Industrial Scale This Summer

Anthropic reports Chinese AI labs routed 35 million requests through Claude in a covert model distillation campaign flagged by U.S. officials.

Anthropic Says Chinese AI Firms Quietly Extracted Its Claude Model at Industrial Scale This Summer

Chinese artificial intelligence companies conducted what U.S. officials are characterizing as an industrial-scale covert operation against American AI systems this summer, routing user requests to Anthropic’s Claude model at least 35 million times in an effort to extract and replicate its underlying capabilities. The campaign, which Business Insider detailed this week, represents one of the most quantified examples yet of so-called model distillation attacks — a technique in which an adversary bombards a frontier AI with queries, then uses the responses to train a cheaper, competing system. The scale of the operation has drawn formal attention from U.S. cybersecurity authorities and marks a significant escalation in technology competition between Washington and Beijing. As electronic warfare sensors and military AI systems grow more intertwined with commercial AI development, vulnerabilities in the civilian frontier-model ecosystem carry direct implications for national security.

The Cybersecurity and Infrastructure Security Agency has issued a formal advisory — catalogued as AA26-251A — warning that China-based AI companies are conducting what it describes as distillation campaigns against U.S. AI firms at industrial scale. CISA’s advisory, which was released in conjunction with the broader reporting, frames the activity not as opportunistic scraping but as a deliberate, coordinated effort to close the capability gap with American frontier models without incurring the associated research and compute costs.

a large server room filled with rows of illuminated data center racks, wide-angle shot emphasizing the industrial scale of the infrastructure

How Distillation Attacks Work — and Why the Volume Matters

Model distillation is a well-understood technique within the AI research community, typically used to compress large models into smaller, more efficient ones. When weaponized by a competitor, however, the same method becomes a form of intellectual property extraction: a sufficiently large corpus of high-quality input-output pairs from a leading model can be used to fine-tune a weaker model toward near-equivalent performance on specific tasks. At 35 million requests, the volume reported by Anthropic goes well beyond incidental use and suggests systematic, automated querying designed to produce exactly such a training corpus.

The implications extend beyond Anthropic alone. If Chinese labs can replicate the reasoning and language capabilities of frontier American models at reduced cost — offloading the most expensive phase of AI development onto the target company’s infrastructure — the competitive advantage that U.S. firms have built through years of investment and proprietary data becomes substantially easier to erode. Officials have not publicly confirmed which specific Chinese organizations were responsible or whether legal action is being pursued, but the CISA advisory signals that the U.S. government regards the activity as a national security concern rather than a purely commercial dispute.

National Security Dimensions of a Commercial AI Breach

The campaign lands at a moment when American AI companies are facing compounding pressures. Anthropic and its peers have been scrutinized for their exposure to adversarial actors even as they compete fiercely for capital and government contracts. The convergence of commercial AI development and defense applications means that a model trained in part on distilled outputs from Claude could, in principle, be adapted for military or intelligence purposes by entities outside U.S. jurisdiction. That risk is central to why CISA chose to issue a formal public advisory rather than handle the matter quietly through industry channels.

exterior of a modern government cybersecurity operations facility, showing a nondescript office building with federal signage in a suburban campus setting

The episode also highlights the structural difficulty of defending frontier AI systems against this class of attack. Unlike traditional cyber intrusions, distillation attacks operate through legitimate API access — exploiting the same commercial interfaces that paying customers use. Detecting them requires Anthropic and similar companies to monitor usage patterns at scale and identify anomalous query volumes or behavioral signatures that suggest automated extraction rather than genuine end-user activity. Whether the 35 million figure represents the totality of the campaign or only the portion Anthropic was able to attribute remains unclear; officials have not confirmed a ceiling on the scope. The broader competitive context — including concerns raised by prominent investors about the durability of U.S. AI firms’ market positions — suggests the pressure on companies like Anthropic to protect their core model capabilities will only intensify. Israel’s approach of standing up a AI robotics branch within its military reflects how seriously allied governments are treating the intersection of AI capability and strategic competition, a calculus that distillation attacks directly threaten to disrupt.

Follow Global Defense Digest

Subscribe

To receive updates about new articles, or opt in to our daily digest!

Choose one:

We don’t spam! Read our privacy policy for more info.

Subscribe

To receive updates about new articles, or opt in to our daily digest!

Choose one:

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *