← All posts

Artificial intelligence

The Serious Charge Against Moonshot Is Not Distillation. It Is the Routing

Anthropic's September threat report names seven Chinese labs and about 190 million extracted exchanges. Buried in it is a different allegation: that Moonshot and DeepSeek served Claude's answers to their own paying users. That one does not depend on unsettled copyright law — and the evidence for it is also its biggest problem.

MAI
The cover image published by Anthropic for its September 2026 threat intelligence report.

Anthropic published its September threat intelligence report on 10 September, naming seven China-based AI labs — Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax — and accusing them of extracting roughly 190 million Claude exchanges between December 2025 and August 2026.

Most of the coverage focused on that number. The number is the least interesting part. Training a model on a competitor's outputs is an old accusation, it has been made before, and as a legal matter it is close to untested. The charge worth reading twice is narrower: that Moonshot and DeepSeek took requests from their own users and quietly sent them to Claude, then returned Claude's answers under their own brand.

What the report alleges

LabScale allegedMethod described
Alibaba151M exchanges, May–July 2026, peaking near 3M/day across 3,500+ fraudulent accountsPrompts designed to make Claude expose its reasoning, not just its answers
Moonshot AI23M+ exchanges via 5,380 fraudulent accounts; ~300,000 customer requests in one ten-day windowRelay of live Kimi user requests to Claude
DeepSeek12.1M+ over 14 days in July 2026Inspecting request headers to pick out agentic coding traffic, then relaying it
"Over the last several months, unauthorized labs have developed increasingly sophisticated methods to circumvent our defenses and harvest the capabilities of US frontier models." — Anthropic, September 2026 threat intelligence report

Anthropic says it responded by returning summarised rather than verbatim reasoning, shipping a mechanism in Fable 5.1 that binds conversation context cryptographically, deploying extraction classifiers, and requiring identity verification for accounts in high-risk jurisdictions.

Why routing is a different kind of accusation

Distillation sits in genuinely unsettled legal territory. No such case has been litigated. Model outputs are generally not copyrightable, which undercuts the obvious claim. And as Georgetown Law's Anupam Chander pointed out to NPR in July, the American labs are poorly positioned to argue otherwise: "the AI companies believe, and they have argued, that learning from others is a perfectly fair use of other people's copyrighted work." Terms-of-service and trade-secret claims remain, but enforcing either against a Chinese company is largely theoretical.

Routing needs none of that. If a user pays for Kimi, asks Kimi a question, and receives an answer generated by Claude presented as Kimi's, the wrong is done to the user, not to Anthropic — and it is the kind of wrong consumer-protection regulators understand without anyone resolving what distillation is. It also cuts at the thing a model company sells. A benchmark score means something different if some share of the product was someone else's model.

The evidence is also the problem

The relay is how Anthropic says it found out. Requests routed to Claude arrived at Anthropic, which means the contents of other companies' users' conversations arrived too.

By Anthropic's account that traffic included CCTV footage uploaded by someone affiliated with the People's Liberation Army analysing tracked individuals, proprietary code carrying live credentials from a state-owned enterprise engineer, an internal analysis of a flagship PRC AI programme, Russian Ministry of Defence credentials, and material from municipal police systems matching people's movements against national ID records.

Read that twice as well. If the allegation is accurate, users of Chinese AI products — including users handling state security material — had their data delivered to an American company without knowing it. That is a more serious failure than anything in the intellectual-property argument, and it is the strongest reason the routing claim deserves scrutiny rather than a shrug.

Nobody accused is talking

Moonshot has not addressed the routing claim. Neither has DeepSeek. TechCrunch's report carries no comment from any of the named companies. On 12 September, Chinese foreign ministry spokesperson Mao Ning said Beijing firmly opposes attempts to "smear China by distorting facts," which is a government position rather than a company denial, and does not engage the specific claim.

Silence is not an admission. It is also not a rebuttal, and in a dispute this concrete it leaves the field to the accuser.

What should keep you cautious

Every number here comes from one company's internal telemetry. That telemetry has not been independently audited, the attribution methodology is described only in outline — Anthropic says it grouped the Alibaba traffic as one campaign partly because the exchanges shared a fixed prompt — and the company making the accusation competes directly with every company it names.

The timing deserves noting too. The White House accused Moonshot in July of distilling Anthropic's Fable to build Kimi K3, and Beijing has already framed that as an attempt to suppress its AI industry. A threat report that lands in the middle of that argument is not thereby wrong, but it is not arriving into a vacuum.

The specific, falsifiable claim is the routing. It is testable from the outside: users and researchers can probe whether Kimi's outputs carry Claude's fingerprints, and Moonshot can produce its own logs. Until one of those happens, this is a serious allegation supported by evidence only its author can see.

Sources: Anthropic — Detecting and countering misuse of AI: September 2026 · Bloomberg — Moonshot secretly routed user requests through Claude, Anthropic says · TechCrunch — Anthropic details distillation campaigns from Alibaba, Moonshot AI and DeepSeek · CNBC — Chinese AI labs secretly used millions of Claude exchanges to train their models · South China Morning Post — Moonshot, DeepSeek secretly routed user requests to Claude · The Hacker News — Anthropic says seven China-based AI labs ran industrial-scale distillation attacks · NPR — Allegations of AI distillation spark debate about IP theft. But is it illegal? · AI Commission — China rejects Anthropic's accusations against AI labs

Keep reading