Logo
FrontierNews.ai

How Chinese AI Labs Are Quietly Harvesting U.S. Frontier Models to Build Their Own

Chinese AI developers have been systematically extracting capabilities from Anthropic's Claude AI model through a technique called distillation, generating hundreds of millions of queries to replicate the technology at a fraction of the development cost. According to Anthropic's September 2026 threat report, multiple major Chinese AI companies orchestrated coordinated campaigns to harvest Claude's reasoning and coding abilities, using fraudulent accounts, proxy networks, and other deceptive methods to mask their activities.

What Is Distillation and Why Does It Matter?

Distillation is a technique where companies covertly extract answers from a frontier AI model, then replicate that knowledge in their own systems using far less computing power, time, and money than developing the technology independently. Think of it as reverse-engineering a competitor's product by studying its outputs rather than accessing its internal code. The harvested data becomes training material for new models, allowing companies to leapfrog years of research and development.

The scale of these operations reveals how attractive U.S. frontier models remain to Chinese developers, despite claims that domestic alternatives have closed the capability gap. Anthropic's findings suggest that for certain specialized tasks, Claude's superior performance in reasoning, coding, and complex problem-solving made it worth the risk of detection and potential legal consequences.

Which Chinese Companies Are Involved and How Much Data Did They Extract?

Alibaba conducted the largest known distillation campaign, generating more than 151 million Claude exchanges between May and July 2026. At its peak, the operation reached approximately 3 million requests per day through thousands of fraudulent accounts. Anthropic says the harvested chain-of-thought data, which shows how Claude reasons through problems, directly contributed to training Alibaba's Qwen 3.x model, particularly for reasoning, coding, software engineering, kernel development, and long-horizon tasks.

Alibaba was far from alone in this effort. Anthropic identified similar campaigns from multiple other major Chinese AI developers:

  • DeepSeek: Generated more than 12.1 million Claude exchanges in just 14 days
  • Xiaomi: Conducted distillation operations that produced more than 400,000 exchanges
  • Zhipu/Z.ai: Engaged in similar capability-extraction campaigns
  • Other unnamed developers: Anthropic identified additional companies using comparable techniques

The methods these companies employed ranged from straightforward to sophisticated. Some used proxy networks and fraudulent accounts to hide their identity. Others disguised themselves as legitimate customers or forwarded their own clients' requests to Claude. In some cases, companies purchased harvested Claude conversations from third parties, outsourcing the extraction work entirely.

How Are These Campaigns Connected to Military and Surveillance Applications?

Beyond the distillation operations, Anthropic's report documents how Claude was directly used by Chinese military researchers and government-linked actors for sensitive applications. One China-based defense researcher used Claude to develop approximately 16 software modules for electronic warfare and suppression of enemy air defenses. The software analyzed radars, surface-to-air missile sites, command posts, and communications nodes to prioritize targets. In test scenarios, the system included 12 targets in Taiwan, including Patriot and Tien Kung air defense batteries, air bases, early-warning radar systems, and a command bunker.

Another military-related project involved drafting fire-control specifications for an anti-torpedo system, testing it against publicly available information about U.S. Navy capabilities, and preparing technical proposals for potential clients. While the actor posed as a U.S. defense contractor, Anthropic determined the operation was likely connected to a Chinese defense manufacturer developing systems for the People's Liberation Army Navy.

Beyond military applications, Anthropic disrupted surveillance operations targeting Uyghur communities. One China government-linked actor used Claude to infiltrate Uyghur armed groups in Syria, monitor diaspora activists and media, and process information from over 100 WhatsApp groups and dozens of Telegram channels. Claude helped identify individuals across platforms, map social networks, draft deceptive recruitment messages in local dialects, and evaluate the credibility of potential targets. The same operation coordinated mass-reporting and bot-amplification campaigns against diaspora journalists, including Uyghur Post.

Why Would Chinese Companies Use U.S. Models When They Have Domestic Alternatives?

The prevalence of Claude usage among Chinese military and commercial actors despite the existence of domestic AI models suggests that capability and convenience outweighed the risks. U.S. frontier models are trained on enormous amounts of English-language material, giving them particularly extensive knowledge of publicly available information about American military technologies and systems. For specialized engineering workflows involving coding, reasoning, and complex problem-solving, Claude apparently offered advantages that domestic alternatives could not readily match.

This reliance on U.S. models also explains the scale of the distillation campaigns. Rather than accept the limitations of available domestic models, Chinese developers chose to extract Claude's capabilities and incorporate them into their own systems. The industrial scale of these operations, with Alibaba alone generating 151 million exchanges, indicates this was not opportunistic activity but rather a coordinated strategy to close the capability gap.

How to Understand the Broader Implications of AI Model Distillation

The distillation campaigns documented by Anthropic reveal several critical vulnerabilities in how frontier AI models are deployed and protected:

  • Scale of Detection: Anthropic identified these campaigns through account metadata, content analysis, and behavioral patterns, but the sheer volume of queries suggests many distillation efforts may go undetected or unreported by other AI companies
  • Cost Advantage: Distillation allows companies to replicate frontier model capabilities at a fraction of the compute cost, creating a powerful incentive for competitors and state-sponsored actors to engage in the practice
  • Dual-Use Risk: The same reasoning and coding capabilities that make Claude valuable for legitimate software engineering also enable military applications, surveillance operations, and weapons development
  • Geopolitical Competition: These campaigns represent a form of technology transfer that accelerates the development of competing AI systems without the massive investment typically required

Anthropic's findings underscore a paradox in the AI industry. Despite claims by Chinese companies that they have developed competitive frontier models, hundreds of actors linked to Chinese military, government, and commercial organizations continued to rely on Anthropic's Claude for sensitive applications. This suggests that the capability gap between U.S. and Chinese AI systems remains significant enough to justify the operational risk of using a U.S. model for military and surveillance purposes.

The report also highlights the challenge of enforcing terms of service and preventing misuse when dealing with sophisticated, well-resourced actors. Fraudulent accounts, proxy networks, and third-party data purchases create multiple layers of obfuscation that make attribution and enforcement difficult. As frontier AI models become more capable and more widely deployed, the incentives for distillation and misuse will likely only increase.