A new report from Growth Dragons estimates that Chinese artificial intelligence laboratories sent approximately 190 million queries to Claude, Anthropic's flagship AI system. The scale of the activity suggests a coordinated effort to extract model outputs that could be used to train competing systems, a practice commonly known as distillation. The findings arrive as competition between American and Chinese AI developers intensifies across nearly every major benchmark.

What the Numbers Suggest

One hundred and ninety million queries is not casual usage. At that volume, the traffic patterns point toward automated pipelines rather than human researchers experimenting with a new tool. Distillation attacks work by feeding a target model large volumes of carefully structured prompts, then using the responses as training data for a smaller or less capable model. The goal is to transfer the knowledge embedded in the larger system without paying the cost of training from scratch. Anthropic has previously identified seven China-based AI labs it says ran distillation attacks against Claude, and the new figures suggest the problem is broader than those early disclosures indicated.

Key Facts

  • An estimated 190 million queries were sent to Claude by Chinese AI labs, per Growth Dragons.
  • The activity is consistent with model distillation, a technique used to replicate capabilities from a more advanced system.
  • Anthropic has publicly named seven China-based labs in connection with prior distillation attempts.
  • Chinese labs have simultaneously released models claiming competitive performance with Claude on leading benchmarks.
  • Anthropic's terms of service prohibit using Claude outputs to train competing AI systems.

The report frames the behavior within a wider story about China's AI development pace. Despite substantial investment and rapid iteration, Chinese labs have repeatedly benchmarked their best models against Claude's performance tiers, treating Anthropic's systems as the standard to beat. Alibaba's AI team has claimed its models match Claude across several benchmarks, while other Chinese developers have made similar assertions in recent months. Whether those claims hold under independent testing is a separate question, but the ambition is clear.

The volume of queries suggests this was not exploratory research. Pipelines at this scale are built with a specific data collection objective in mind.Growth Dragons report analysis
Claude AI Handboek by Leon Tindemans
Get the Claude AI Handboek
458 pages on getting more out of Claude, by AI expert Leon Tindemans. A printed book, written in Dutch, shipped worldwide with track and trace.
View the book →

The Business and Security Implications

For Anthropic, the situation presents overlapping concerns. On the commercial side, allowing competitors to harvest model outputs at scale undercuts the investment required to develop frontier AI. Training runs for leading models cost tens of millions of dollars, and distillation offers a shortcut that bypasses most of that expense. On the policy side, the company has positioned itself as a safety-focused lab, and systematic misuse of its systems by foreign competitors complicates that narrative.

Anthropic's terms of service explicitly ban using Claude's outputs to train competing models. Enforcement, however, is technically difficult. IP addresses can be masked, query patterns can be varied to avoid automated detection, and API access through intermediaries can obscure the true origin of traffic. The company has begun investing more heavily in behavioral detection, but the 190 million figure suggests those controls were not sufficient to stop the activity described in the Growth Dragons report.

There is also a competitive irony embedded in the story. Chinese labs are seeking to close a gap that, by their own benchmarks, may be narrowing anyway. Alibaba's Qwen3.8 recently claimed a second-place finish behind Claude Fable 5 on a widely watched benchmark, which suggests Chinese developers are making organic progress alongside any data extraction efforts. The two strategies are not mutually exclusive, but the benchmark results complicate any simple narrative about one side being comprehensively ahead.

What the 190 million query figure ultimately reveals is the degree to which Claude has become a reference point in global AI development. Labs benchmark against it, attempt to replicate it, and in some cases appear to be systematically studying its outputs. That attention reflects the current state of the competitive landscape as much as any single product announcement or funding round does. How Anthropic responds, both technically and through policy channels, will matter for how that landscape develops over the next year.

Further reading: Learn more about Claude's model family, read our background on Anthropic, or browse the latest Claude AI news.