According to reporting by Reuters and The Next Web, Anthropic has formally accused Alibaba of orchestrating the largest known AI distillation campaign ever mounted against a US technology company. In a letter sent to US senators and White House officials, the San Francisco-based AI lab alleged that operators linked to Alibaba’s Qwen AI lab ran nearly 25,000 fraudulent accounts through which they conducted close to 29 million conversations with Claude between April and June 2026. The operation was focused on harvesting Claude’s software engineering and agentic reasoning capabilities, the areas where the model commands the highest commercial value.
The accusation marks the first time Anthropic has named a major Chinese technology conglomerate as the source of a distillation attack. Previous allegations, disclosed in February, focused on smaller Chinese AI startups, including DeepSeek, MiniMax, and Moonshot AI, which collectively accounted for more than 16 million exchanges through approximately 24,000 fake accounts. In sheer volume, the Alibaba operation dwarfed all three previous campaigns combined, a magnitude that has sent a jolt through both the AI industry and Washington’s national security establishment.
What AI Distillation Is — and Why It Has Become a National Security Issue
Distillation is the practice of feeding carefully crafted queries to a frontier AI model, collecting its responses, and using those outputs to train a cheaper rival system that approximates the original’s capabilities. The technique is technically legal in many jurisdictions but sits in a contested gray zone when it involves unauthorized access through fraudulent accounts. The White House identified distillation as a national security concern in April, when OSTP Director Michael Kratsios published a memo committing the government to share intelligence with US AI labs about foreign distillation campaigns. Anthropic noted in its letter that the Alibaba campaign took place after the Kratsios memo, in direct defiance of the administration’s warnings.
Alibaba has not commented on the allegations. An Anthropic spokesperson declined to discuss specifics but emphasized the importance of combating distillation through coordinated action between government and industry. Following the news, Alibaba’s American depositary receipts fell more than 3% in afternoon trading, dropping below $100, adding to a difficult stretch for the company in Washington.
A Second Front Opens for Alibaba in Washington
The distillation accusation arrives at a particularly fraught moment for Alibaba. The Pentagon added Alibaba to its Chinese military companies blacklist on June 8, a designation Anthropic cited in its letter. Alibaba subsequently sued the Defense Department to win removal from that list, calling the label baseless and arguing it has no military affiliation. The distillation accusation now opens a second front, framing Alibaba not just as a company with alleged military ties but as an active participant in what Anthropic describes as the systematic theft of American AI capabilities.
The letter warned that distillation gives Chinese labs a shortcut to frontier-level AI at a tiny fraction of the original training cost, and that the resulting models are typically stripped of the safety architecture built into the original. Anthropic pressed the Trump administration on three fronts: loosening antitrust guidelines to allow US labs to pool intelligence on distillation campaigns, maintaining export controls on advanced AI chips, and establishing penalties for companies that exploit the technique.
The accusation also adds a new dimension to the ongoing debate about Alibaba’s Qwen model family. Qwen models have been widely praised for their performance on coding and reasoning benchmarks, and the allegation that their capabilities were partially derived from Claude’s output will raise uncomfortable questions about the provenance of those gains — even if the full picture remains disputed.
Congressional Response and Legislative Proposals
Lawmakers are moving in parallel. Senators Bill Hagerty and Andy Kim plan to introduce an amendment to must-pass defense legislation that would blacklist or sanction any Chinese firm found to be improperly accessing US AI model output. A related bipartisan bill in the House, backed by Representatives Bill Huizenga and Sydney Kamlager-Dove, is also being considered, though whether either proposal survives to the final version of the defense bill remains uncertain.
The legislative push reflects a broader frustration in Washington with the limits of existing tools. Export controls on advanced AI chips have been the primary mechanism for constraining China’s AI development, but distillation demonstrates that hardware restrictions alone cannot prevent capability transfer when the most valuable asset, model knowledge, can be extracted through the internet. China’s AI developers have consistently found creative ways to work around hardware constraints, and distillation represents a software-layer equivalent of that same ingenuity.
Anthropic’s Complicated Relationship with Washington
Anthropic’s calls for government support may not find a fully receptive audience. The company is simultaneously embroiled in a separate dispute with the Trump administration over export controls imposed on its Fable 5 and Mythos 5 models less than two weeks ago. Commerce Secretary Howard Lutnick signed an order blocking foreign nationals from accessing those models, citing security concerns, and Anthropic disabled them to comply. Even after meetings between the company’s technical staff and White House officials, little progress has been made to restore service.
The result is a company caught between two fronts. Anthropic needs the government to crack down on Chinese labs extracting its technology, but it is simultaneously fighting the same government’s decision to restrict its own products. The letter to senators attempts to separate the two issues, arguing that protecting US models from distillation and allowing them to be deployed commercially are complementary rather than contradictory goals.
The Broader Stakes for AI Intellectual Property Enforcement
The deeper challenge the Alibaba accusation exposes is structural. Unlike semiconductors, which can be physically blocked at the border, AI model capabilities are embedded in software that can be queried remotely and replicated through careful prompt engineering. Export controls on chips address one layer of the technology transfer problem; they do not address the layer where the most commercially valuable knowledge, the trained model itself, is accessible to anyone with an internet connection and a credit card.
Anthropic’s letter to senators is, in effect, a request for the US government to treat model output as a protected export. Whether that framing survives contact with antitrust law, free speech considerations, and the practical difficulty of distinguishing legitimate use from systematic extraction will determine whether distillation becomes the defining IP battleground of the AI era — or simply the latest front in a technology competition neither side has shown any willingness to slow.
