Anthropic has leveled serious accusations against two of China's most prominent AI companies, alleging that both Alibaba and DeepSeek used outputs from its Claude models to train their own systems. The claims have drawn sharp responses from industry analysts, with Futurum Group CEO Daniel Newman calling the practice "freaking insane" during a recent media appearance. The allegations add fuel to a growing debate over intellectual property, model distillation, and the ethics of competitive AI development.
What Anthropic Is Alleging
According to Anthropic, both Alibaba and DeepSeek sent millions of queries to Claude through API access, then used the responses to fine-tune or otherwise improve their own large language models. This technique, known as knowledge distillation or model distillation, involves extracting behavioral patterns from a more capable model to boost a weaker one. Anthropic accuses Alibaba of gaining illicit access to Claude AI in a manner that violated its terms of service, making the data collection not just ethically questionable but potentially actionable in court.
Key Facts
- Anthropic alleges both Alibaba and DeepSeek used Claude outputs for model training.
- The technique at issue is knowledge distillation, using one model's responses to train another.
- Anthropic says the access violated its API terms of service.
- Analyst Daniel Newman described the behavior as industry-wide among Chinese AI labs.
- The allegations are part of broader U.S.-China tensions over AI development and intellectual property.
The scale of the alleged data collection is significant. Chinese AI labs reportedly used millions of Claude conversations to train their models, according to earlier reporting on the broader pattern of distillation attacks. Anthropic has not disclosed the precise number of queries attributed to each company in the latest round of accusations, but previous filings and public statements suggest the volume ran into the tens of millions.
"These companies didn't build from scratch. They took a shortcut straight through someone else's work. That's not competition, that's extraction."Daniel Newman, CEO, Futurum Group
A Pattern Across the Industry
Newman's comments reflect a view held by a growing number of Western AI observers: that the rapid capability gains seen in Chinese frontier models cannot be fully explained by independent research alone. DeepSeek's models, in particular, surprised many in the industry earlier this year with their performance relative to their reported training costs. Critics have suggested those numbers look more plausible if significant behavioral knowledge was transferred from existing frontier systems. Anthropic has detailed distillation attacks by multiple Chinese AI firms, describing a coordinated effort to exploit its models rather than isolated incidents.
For Anthropic, the stakes extend beyond competitive fairness. The company has built its public identity around safety-focused AI development, and the prospect of its models being used to accelerate less safety-conscious systems is a reputational as well as a legal concern. Anthropic's terms of service explicitly prohibit using Claude's outputs to train competing AI models, giving the company potential grounds for civil litigation against both firms.
What Comes Next
It remains unclear whether Anthropic will pursue legal action or whether the allegations will primarily serve as public pressure and policy advocacy. Enforcement against companies operating primarily in China is notoriously difficult, and no U.S. court has yet issued a definitive ruling on the legality of model distillation at scale. What is clear is that the practice is not going away. As long as frontier models are accessible via public APIs, and as long as the performance gap between U.S. and Chinese labs remains, the incentive to extract knowledge through distillation will persist.
For now, Anthropic appears focused on drawing a clear public line. By naming Alibaba and DeepSeek specifically, the company is making both a legal argument and a broader appeal to policymakers and enterprise customers about the risks of unregulated model access. Whether that strategy produces meaningful consequences remains to be seen.