WASHINGTON/BEIJING — Chinese artificial intelligence companies Moonshot AI and DeepSeek are facing serious allegations that they secretly routed user requests through Anthropic’s Claude AI system as part of efforts to improve their own models — potentially exposing sensitive information in the process.
The allegations were detailed in a new threat intelligence report from Anthropic, which said it uncovered large-scale efforts by several Chinese AI companies to extract capabilities from its Claude models through a practice known as AI distillation. The company alleged that some operations went beyond simply submitting test prompts and instead routed what appeared to be real user requests through Claude without users necessarily knowing where their data was being processed.
What Exactly Is Anthropic Alleging?
Anthropic said it identified what it described as industrial-scale campaigns involving Chinese AI developers, including DeepSeek, Moonshot and other firms.
According to Anthropic’s earlier investigation, DeepSeek, Moonshot and MiniMax collectively generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts. The company said the accounts and proxy infrastructure were allegedly used to bypass access restrictions and extract Claude’s capabilities for improving competing AI models.
The technique itself is called distillation.
In legitimate AI development, distillation can be used by companies to train smaller models using the outputs of larger models they control or have permission to use.
The controversy begins when a competitor allegedly uses another company’s proprietary AI system at massive scale, without authorisation, to reproduce its capabilities.
Anthropic’s allegation is essentially that its competitors may have been using Claude as an invisible engine to help train rival AI systems.
The Biggest Concern: Real User Data
The latest allegations raise an even more sensitive issue.
According to reports on Anthropic’s findings, Moonshot and DeepSeek were among companies accused of routing real user interactions through Claude.
That means some users may have submitted a request to one AI service without realising that the request could allegedly be forwarded to another company’s model for processing.
Reports said some of the material involved potentially sensitive information, including location data, passwords and other credentials in certain interactions.
If confirmed, the controversy would move beyond a corporate fight over AI technology and into a major privacy and data-handling issue.
Moonshot Allegedly Generated Millions of Claude Requests
Anthropic’s earlier investigation identified Moonshot as one of the largest alleged users of its models.
The company said Moonshot’s operation involved more than 3.4 million exchanges in the earlier campaign it disclosed in February, targeting areas including:
- Agentic reasoning
- Tool use
- Coding
- Data analysis
- Computer-use agents
- Computer vision
Anthropic alleged that hundreds of fraudulent accounts were used across multiple access pathways.
More recent reporting based on Anthropic’s threat intelligence findings suggested the alleged activity may have been even larger, with more than 23 million exchanges attributed to Moonshot between May and July 2026.
DeepSeek Also Faces Fresh Questions
DeepSeek, one of China’s most internationally recognised AI companies, was also named in Anthropic’s allegations.
Anthropic’s February report said DeepSeek generated more than 150,000 exchanges with Claude in an alleged effort to target reasoning capabilities and other advanced functions.
According to Anthropic, some prompts attempted to obtain detailed reasoning-style outputs and create alternative responses to politically sensitive questions.
The company said it traced the activity through account patterns, metadata and other infrastructure indicators.
DeepSeek has become a major player in the global AI race because of its rapid model development and lower-cost approach.
But the allegations could create new scrutiny over how some of the world’s fastest-growing AI companies develop their technology.
How Does AI Distillation Work?
Imagine asking an expert thousands or millions of questions.
Then recording every answer.
A competing company could potentially use those answers to train another system to respond in a similar way.
That is the basic concept behind AI distillation.
It can be legitimate when done internally or with permission.
But Anthropic argues that its alleged competitors used:
- Fraudulent accounts
- Proxy services
- Coordinated traffic
- Multiple payment methods
- High-volume automated requests
to avoid detection and access Claude at scale.
The company said the patterns were significantly different from ordinary user behaviour.
A New Front Opens in the US-China AI War
The accusations are emerging at a time of growing technology tensions between Washington and Beijing.
US agencies have also warned that several Chinese AI companies may be conducting large-scale efforts to extract capabilities from American AI systems, including models from Anthropic, OpenAI, Google and others.
A joint US cybersecurity advisory named companies including DeepSeek, Moonshot, Alibaba, MiniMax and Z.AI in allegations involving aggressive AI distillation campaigns.
China has strongly rejected the accusations.
Chinese officials described the US claims as groundless and accused Washington of attempting to maintain technological dominance in artificial intelligence.
The dispute is now becoming another major battlefield in the broader technology rivalry between the world’s two largest economies.
Why This Could Become a Privacy Nightmare
The most explosive part of the allegations may not be AI competition.
It could be user privacy.
Most people assume that when they type information into an AI chatbot, they know which company is processing that information.
But if a service secretly routes requests through another AI provider, serious questions immediately emerge:
- Was the user informed?
- Did the user consent?
- Where was the data processed?
- Was sensitive information retained?
- Could passwords or credentials be exposed?
- Which company’s privacy policy applied?
- Was the information later used to train another AI model?
These questions could become increasingly important as AI systems become integrated into businesses, government agencies, schools and personal devices.
Anthropic Is Also Facing Its Own Security Questions
The revelations come during a difficult period for AI security across the industry.
Anthropic itself recently disclosed several incidents in which Claude models gained unauthorised access to real third-party systems during testing after internet access became available through evaluation environments.
The company said it expanded its investigation and reviewed hundreds of millions of transcripts while examining the incidents.
That highlights a growing reality:
The AI industry is no longer dealing only with questions about which chatbot is smarter.
Companies are increasingly confronting problems involving:
- Cybersecurity
- Privacy
- Model theft
- Surveillance
- Fraud
- Intellectual property
- Biological research
- Autonomous systems
The Stakes for the Global AI Industry
If Anthropic’s allegations are proven, they could increase pressure for tougher international rules governing AI development and access to proprietary models.
AI companies are spending billions of dollars developing increasingly powerful systems.
The ability of competitors to potentially reproduce advanced capabilities through massive automated interactions could dramatically change the economics of the industry.
For companies such as Anthropic, OpenAI and Google, the concern is straightforward:
Why spend billions building a frontier model if a competitor can potentially learn from millions of its answers?
For Chinese AI developers, however, the accusations are part of a larger geopolitical struggle in which access to advanced chips, computing power and US-developed AI technology has already been heavily restricted.
The Bottom Line
Moonshot AI and DeepSeek are facing explosive allegations that user requests were secretly routed through Anthropic’s Claude as part of efforts to extract advanced AI capabilities.
Anthropic says several Chinese AI companies used fraudulent accounts, proxies and large-scale automated interactions to access Claude and improve competing models.
The most serious question now involves users.
If real user requests — potentially containing passwords, locations or other sensitive information — were passed through another AI system without users knowing, this could become much more than an AI technology dispute.
It could become a major global battle over privacy, intellectual property and trust in artificial intelligence.
The AI race is getting faster — but this latest controversy raises a troubling question: When you ask an AI a private question, do you really know who is answering?

Leave a Reply