Alibaba Ran 29 Million Fake Claude Conversations to Clone Its Capabilities. What That Means for Every Business Building on AI.

On June 10, 2026, Anthropic sent a letter to US Senate Banking Committee Chair Tim Scott and ranking member Elizabeth Warren.

“Distillation attacks turn hundreds of billions of dollars in American AI investment into a massive subsidy for geopolitical competitors. — Anthropic, in a letter to the US Senate Banking Committee, June 10, 2026.”

The Accusation That Shook the AI Industry This Week

On June 10, 2026, Anthropic sent a letter to US Senate Banking Committee Chair Tim Scott and ranking member Elizabeth Warren. According to CNBC and multiple sourced reports, the letter accused operators affiliated with Alibaba and its Qwen AI lab of running 28.8 million conversations with Claude through nearly 25,000 fraudulent accounts between April 22 and June 5, 2026 — a 44-day window.

Anthropic described the campaign as the largest model distillation attack it has ever publicly disclosed. It is also the first time Anthropic has publicly named a major Chinese technology company — as opposed to smaller AI labs — as the source of such a campaign. Alibaba denies the allegations. The figures are Anthropic’s account, drawn from its letter. They have not been independently verified.

Two days after the letter was sent, the Commerce Department imposed export control restrictions on Anthropic’s Mythos and Fable models globally. The sequence has not been officially confirmed as directly connected, but the timing is not coincidental in any reading of the available evidence.

What a Distillation Attack Actually Is

The Technique, Explained Simply

Distillation is a legitimate AI technique. Companies routinely use it to compress their own large models into smaller, faster, cheaper versions. As PYMNTS reported, the line Anthropic is drawing is between using distillation on your own models — standard practice — and using it on a competitor’s model without permission, which is what the letter alleges.

A distillation attack works like this: instead of spending billions training a frontier model from scratch, you create thousands of accounts on a competitor’s platform, run millions of carefully designed queries through those accounts, collect the outputs, and use those outputs as training data for your own model. The more capable the model you are querying, the more capability you can extract.

The economic logic is devastating in its simplicity. Training a frontier AI model costs hundreds of millions to billions of dollars. Running 29 million API queries costs a tiny fraction of that. If it works, you acquire a substantial portion of that model’s capability at a fraction of the development cost.

Why Safety Guardrails Don’t Transfer

The most important detail in Anthropic’s accusation, and the one that makes distillation attacks a national security issue rather than just a commercial dispute: when a lab distills a frontier model without permission, the copy does not inherit the safety guardrails built into the original. The dangerous capabilities transfer through the outputs. The months spent making the model refuse harmful requests do not.

A distilled model that can do what Claude can do, but without Claude’s safety training, is a meaningfully more dangerous artifact than a model that was simply trained to be less safe. This is the argument Anthropic made to Congress, and it is the argument that connects the commercial IP dispute to national security framing.

The Scale Compared to Prior Campaigns

This is not Anthropic’s first allegation of this type. In February 2026, Anthropic named three Chinese AI labs — DeepSeek, Moonshot AI, and MiniMax — as having collectively generated more than 16 million Claude interactions through roughly 24,000 fraudulent accounts. The alleged Alibaba campaign at 28.8 million interactions from a single organisation is nearly double that combined total. The scale escalation from February to June is itself a signal: if the February campaign was not deterred, the June campaign is the market response.

The Talent War Running Alongside the IP War

The distillation story is the week’s loudest headline. The talent story running alongside it is equally consequential for the long-term competitive picture.

In the six days between June 18 and June 24, four senior researchers from Google DeepMind’s Gemini programme announced departures to Anthropic: Jonas Adler, Alexander Pritzel, John Jumper (Nobel Prize winner in chemistry for AlphaFold), and at least one other named researcher. Noam Shazeer, co-author of the Transformer paper, left Google for OpenAI in the same window.

Google can match Anthropic’s salaries. It cannot match Anthropic’s pre-IPO equity at a company targeting a near-trillion-dollar public market debut. That is the structural incentive creating this talent outflow, and it is one that will not resolve until Anthropic completes its IPO and the equity upside is priced.

The consequence for Anthropic is significant: four of the people who best understand how Gemini is built are now inside Anthropic. For Google, the consequence is the same in reverse: the institutional knowledge of how Gemini was built, where its weaknesses are, and what architectural decisions produced its current capabilities, has transferred to a direct competitor. Unlike code or weights, institutional knowledge cannot be recovered through a legal filing.

What the Distillation Accusation Reveals About the Broader AI Security Landscape

The February Warning Was Ignored

In April 2026, the White House Office of Science and Technology Policy formally accused China of running “deliberate, industrial-scale campaigns” to steal US AI models and directed agencies to share intelligence with AI companies. Anthropic’s June 10 letter explicitly notes that the alleged Alibaba campaign ran after that warning. Whether Alibaba was aware of and indifferent to the administration’s position, or whether there is a different explanation for the timeline, is a matter the congressional hearing is intended to address.

What is not in dispute: between the February disclosure of the DeepSeek/Moonshot/MiniMax campaigns and the June disclosure of the alleged Alibaba campaign, the technique did not stop. If anything, it scaled. That trajectory is the most important signal for businesses thinking about AI provider risk.

The Connection to the Fable 5 Export Ban

The sequence now visible in the timeline: Anthropic’s letter to Congress on June 10 → Commerce Department export control restrictions on Fable 5 and Mythos on June 12. Whether the letter directly triggered the export action is not confirmed. What is clear is that the letter framed the national security case for restricting access, and the restriction followed two days later. As covered in the full account of the Fable 5 export ban, the SK Telecom concern and the Pliny jailbreak were the other contributing triggers. The distillation allegation adds a third, and potentially the most significant, dimension to what produced that access restriction.

What Adversarial Distillation Means for API Access Going Forward

The most practically important observation in the Digital Applied analysis of the campaign: the techniques used to extract a model are the same techniques that abuse a customer’s API account. Fraudulent accounts at scale, systematic querying designed to extract specific capabilities, and organised data harvesting from outputs — these are the same attack patterns that show up in account compromise and credential theft.

For AI providers, the response to distillation campaigns will increasingly involve rate limiting, usage pattern analysis, and access controls that affect legitimate users as well as bad actors. Stricter API terms of service, access gating on the most sensitive model tiers, and intelligence sharing between labs are all likely consequences if the Alibaba allegation produces legal or regulatory action. The companies best positioned to handle these changes are the ones already treating model access as a managed dependency rather than a permanent utility.

The Legal Question Nobody Has Answered Yet

There is currently no settled legal definition of adversarial distillation. Distillation itself is legal. Using another company’s model outputs to train your own model violates most AI providers’ terms of service, but terms of service violations are commercial disputes, not criminal offences. Anthropic’s framing in the Senate letter — describing the campaign as “illicit” and linking it to Chinese government complicity — is an argument for a stronger legal framework, not a statement about existing law. As Digital Applied’s analysis notes, a dispute this large with no settled law tends to force one, through legislation, litigation, or both.

If a workable legal definition of adversarial distillation emerges from this congressional hearing, the consequences will reach every company in the AI ecosystem: stricter terms of service, mandatory usage monitoring, and potentially criminal penalties for large-scale model extraction. That legal framework does not exist yet. Watch the Senate Banking Committee’s next AI hearing for signals about which direction it is moving.

What This Means for Businesses Building on AI Automation

Your Vendor’s IP Is Under Active Attack, and Your Access Changes As a Result

The practical consequence for businesses building automation on Claude, GPT, or Gemini: your vendor’s intellectual property is under active attack, and the defensive measures that follow those attacks directly affect your access. The Fable 5 export ban was a consequence of the security context the Alibaba allegations contributed to. As covered in the agent platform war analysis, the businesses that will navigate this environment best are the ones already building with multiple providers and abstraction layers, treating model access as a managed dependency rather than a permanent utility.

The Open-Source Model Case Gets Stronger

Every geopolitical intervention that restricts access to closed proprietary models strengthens the case for open-weight models with permissive licences. GLM-5.2, the MIT-licensed model from Zhipu AI scoring 62.1 on SWE-bench Pro, cannot be pulled by an export control order. Llama 4’s open weights cannot be suspended by a congressional letter. As argued in ‘Stop Chasing the Biggest Model’, the automation ratio and business ROI question is about task-model matching, not raw frontier capability. Open-weight models at frontier-adjacent performance are now a serious option for the high-volume, repetitive tasks that drive most SMB automation ROI.

Your Own Data Is Now a Moat, Not Just an Asset

The Alibaba distillation allegation is the enterprise-scale version of the same principle Satya Nadella articulated in his viral essay about building learning loops rather than renting model access: the model itself is copyable. What is not copyable is the domain-specific training data, the proprietary knowledge base, and the fine-tuning that makes a model genuinely understand your business. Alibaba allegedly spent 44 days and 29 million queries trying to extract Claude’s general capabilities. No distillation attack can extract your specific customer history, your team’s accumulated judgment, or the context that makes your automation stack produce reliable outputs for your specific use case.

This is the practical application of Nadella’s token capital argument at your business level. Build the learning loop. Fine-tune on your own data. Build the knowledge base. The general model is a commodity that can be copied, restricted, or replaced. The context layer built on your data is the moat that cannot be distilled away by 29 million fake accounts.

The Bottom Line

Anthropic’s accusation against Alibaba is the most significant corporate AI espionage allegation ever made publicly. It documents a 44-day, 28.8-million-query campaign that, if the allegations are accurate, represents the systematic industrialisation of model theft at a scale that changes how AI providers will design their access controls going forward. Alibaba denies the allegations. The legal framework to adjudicate the dispute does not yet fully exist. Both of those things are true simultaneously, and neither changes the practical reality for businesses building on AI.

That practical reality: the AI infrastructure your business depends on is caught between national interests, under active attack from state-linked actors, and producing access restrictions as a consequence of both. The businesses that navigate this correctly are the ones that built portable, multi-provider automation stacks with proprietary data layers — the architecture that is resilient to model restrictions, provider outages, and geopolitical interventions regardless of which specific incident triggers them.

Build that architecture now. The evidence that you need it keeps arriving faster than anyone expected.

Frequently Asked Questions

What is a distillation attack on an AI model?

A distillation attack, also called model extraction, is when an actor creates fraudulent accounts on an AI platform, runs large volumes of carefully designed queries, collects the outputs, and uses those outputs as training data to improve their own AI model. As PYMNTS explains, distillation itself is a legitimate technique used routinely by companies on their own models. The alleged Alibaba campaign crossed the line by running this process against a competitor’s model without permission and at industrial scale.

Did Alibaba confirm or deny the allegations?

Alibaba denied the allegations. According to TechSpot, neither Alibaba nor Anthropic responded immediately to media requests for comment at the time of publication. The 28.8 million interaction figure and the 25,000 fake account figure are Anthropic’s stated allegations in its letter to US senators, and have not been independently verified. This is a serious accusation under active dispute, not a settled finding.

How does this connect to the Fable 5 and Mythos export ban?

Anthropic sent the letter documenting the alleged Alibaba campaign to Congress on June 10, 2026. The Commerce Department imposed export control restrictions on Fable 5 and Mythos on June 12. The official explanation for the export action cited the Pliny jailbreak vulnerability and the SK Telecom geopolitical concern. Whether the Alibaba letter was also a contributing factor has not been officially confirmed, but the timeline is a matter of public record. The full context of the Fable 5 ban, including the SK Telecom angle and the jailbreak trigger, is covered in this earlier article in the series.

What should businesses building on Claude or other frontier AI models do in response?

Three immediate actions: First, build or strengthen your model-agnostic abstraction layer so your automation workflows are not hard-wired to a single provider. Second, accelerate investment in your own proprietary data layer — the fine-tuning, knowledge base, and domain-specific context that cannot be extracted by any distillation campaign. Third, monitor API terms of service updates from your AI providers closely, as the access controls responding to distillation campaigns will tighten. For a full framework on building portable, governance-first automation, read the Five Eyes AI agent security guide coverage and the no-code automation workflow guide.

Does this mean Chinese AI models like Qwen are built on stolen data?

Anthropic’s allegation concerns an ongoing effort to extract capabilities, not proof that Qwen’s existing capabilities were built on distilled Claude outputs. Qwen’s current benchmark performance predates the alleged campaign period. The allegation is that the campaign was aimed at improving Qwen’s future capability, particularly in software engineering and agentic reasoning. Whether the campaign succeeded in achieving that goal is not determinable from the available information. Alibaba denies the campaign occurred as described.

Related Reading From This Series

The Pack Hunt Jailbreak That Took an AI Model Offline — why prompt-based restrictions are soft and composition risk matters

The Five Eyes AI Agent Security Guide — the five risk categories every business deploying agents needs to address

The AI Agent Platform War — why portable architecture protects you when access changes overnight

Satya Nadella’s Learning Loop Warning — why the model you rent is never your competitive advantage

Stop Chasing the Biggest Model — why open-weight and fine-tuned models are increasingly the right choice

74% of AI Agent Deployments Get Rolled Back — what governance discipline looks like in practice

About the Author: Hamza Baig is the founder of Hexona Systems, an AI automation agency serving clients across six continents, and creator of the AI Automation Institute, where over 40,000 entrepreneurs have learned to build and scale automation businesses. He has been featured in GHL Top 50, Yahoo Finance, and Brainz Magazine. Follow him at @hamza_automates | Read more articles | Work with Hamza


About

Hamza Baig is the founder of Hexona Systems—an automation agency and softwareplatform that helps thousands of entrepreneurs and business owners implement AI-powered workflows at scale.

Share

Related Posts