📚 New to this topic? Read our full guide: Generative AI Explained.
Anthropic Accuses Alibaba of AI Model Theft: 28.8 Million Claude Chats Harvested
Anthropic is a US company. It makes an AI chatbot called Claude. A chatbot is a computer program you can talk to, and it answers like a person. Anthropic has now accused a big Chinese company, Alibaba, of copying its AI in secret.
Anthropic wrote a letter to US lawmakers. Lawmakers are the people who make a country’s laws. In the letter, Anthropic said a team linked to Alibaba’s AI lab secretly held about 28.8 million chats with Claude. They used around 25,000 fake accounts to do it. Anthropic says this is the biggest theft of its kind it has ever seen.
This is not normal copying. The trick has a name: “distillation.” Distillation means you train a weaker AI by feeding it the answers of a smarter AI. So you do not build a clever model from scratch. Instead, you copy how a better model thinks. Anthropic says Alibaba did this to Claude without asking.
What Anthropic Says Happened
Anthropic sent its letter on June 10, 2026. It went to the US Senate Banking Committee. (A committee is a small group of lawmakers who study one topic.) The letter went to the chairman, Tim Scott, and to the top Democrat, Elizabeth Warren. It came just before a big AI meeting in Congress.
Anthropic says the copying ran from April 22 to June 5, 2026. That is about six weeks. It blames Alibaba’s Qwen lab. Qwen is the team that builds Alibaba’s own AI models. Anthropic says the team used about 25,000 fake accounts.
They also used proxy services. A proxy hides where internet traffic really comes from. Claude has a rule that blocks users in China. The proxy helped them get past that rule, so the system thought the users were somewhere else.
Over those weeks, the fake accounts ran about 28.8 million chats with Claude. Anthropic says the plan was to collect Claude’s answers in bulk. Then they would use those answers to train a rival AI. Anthropic calls this an “adversarial distillation” attack. “Adversarial” just means it was done on purpose, against the rules.
Key facts
| Item | Reported figure |
|---|---|
| Claude chats harvested | ~28.8 million |
| Fake accounts used | ~25,000 |
| Campaign window | April 22 – June 5, 2026 (about 6 weeks) |
| Letter date | June 10, 2026 |
| Sent to | Sen. Tim Scott, Sen. Elizabeth Warren (Senate Banking Committee) |
| Accused lab | Alibaba’s Qwen AI team |
How This Compares to Past Cases
This is not the first time Anthropic has spotted this. Before, it pointed to three other Chinese AI labs. But the Alibaba case is far bigger than all three put together.
| Lab flagged earlier | Reported interactions |
|---|---|
| DeepSeek | 150,000+ |
| Moonshot AI | 3.4 million |
| MiniMax | 13 million |
| Alibaba (Qwen) | 28.8 million |
Here is what that means. The Alibaba number alone is more than twice the next-biggest case. That is why Anthropic told the Senate this is the largest case it has ever recorded.
The Export Control Backdrop
This fight is part of a bigger AI battle between the US and China. The US Commerce Department has put limits on Anthropic’s most advanced models, named Mythos and Fable. These limits are called export controls. Export controls are government rules that block certain technology from being sold or shared with other countries. Officials worry these strong models could end up with the army or spy agencies in China.
So the US is trying to keep its best AI in safe hands. But Anthropic says rivals are trying to copy that AI through the back door. This is also why other countries now want their own deals to get access. India, for example, is in talks with the US to reach Anthropic’s Fable 5 model the proper way.
FAQ
What is AI distillation in simple words?
It means training a smaller AI by using the answers of a smarter AI. The weaker model learns to copy the better one. It never builds that skill on its own.
How did the accounts get past the China block?
Anthropic says the team used about 25,000 fake accounts and proxy services. A proxy hides the real location of internet traffic. So the system thought the users were somewhere else.
Has Alibaba responded?
So far, Alibaba has not replied to requests for comment. Anthropic also did not say more beyond the letter.
Why It Matters (Especially for India and Founders)
For Indian startups and founders, this case has two clear lessons. First, the answers your AI gives are valuable. They are like a prized asset. If you run an AI service, others may try to copy your model by flooding it with questions. So you need limits on how much one user can ask. You also need account checks and a way to watch for misuse. These are no longer optional.
Second, getting the best AI models is now a political issue between countries. The top models may be locked behind export rules. So Indian companies that want the most advanced AI may need deals between governments. Signing up online may not be enough. That makes home-grown AI and trusted partners more important than ever.
The main point is simple. Countries now guard AI power like gold. As models get stronger, the line between fair learning and plain theft will be tested again and again. The Anthropic-Alibaba clash is likely just the first of many such fights.
Sources: Benzinga, CNBC and Financial Express.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.


