Follow us on Facebook → fresh APAC stories, daily

Tech & AI

China’s AI labs are cloning Claude at industrial scale. Washington is ready to sanction them.

Six Chinese firms—including Alibaba, DeepSeek, and Moonshot AI—harvested 151 million Claude exchanges using fraudulent accounts. The FBI, NSA, and CISA named them on September 8, giving Treasury a sanctions list.

The FBI, NSA and CISA say China-based AI firms have run industrial-scale knowledge distillation campaigns against American frontier models since at least late 2024. The firms named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.

The advisory lists specific techniques: fraudulent accounts, proxy infrastructure, and routing services. Treasury Secretary Scott Bessent has said Washington can sanction overseas firms found to be stealing American models.

Alibaba‘s Qwen models now carry a specific accusation. So do Moonshot AI’s Kimi systems and DeepSeek’s R1 and V3. Their training data includes outputs harvested from American frontier models. The accusation is no longer a blog post, and the scale has no legitimate academic parallel.

The shift is not the technique; it is who has named it. On September 8, 2026, the FBI, NSA and CISA issued joint advisory AA26-251A. It named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI and called the campaigns “likely with Chinese government awareness.” Two days later, Anthropic tied its largest detected operation to Alibaba.

Get the latest APAC news as it happens — follow Indoneo on Facebook

Industrial-scale model theft now carries a sanctions-grade label. Treasury Secretary Scott Bessent had already said Washington could act. The September documents give him a list of names. Sanctions are no longer a hypothetical threat.

The abstraction ends with six names

The joint NSA-CISA-FBI advisory did not read like a routine abuse notice. It called the campaigns “aggressive, malicious, and targeted.” It said they were “likely with Chinese government awareness.” The agencies framed them as a threat to U.S. technological leadership.

The agencies tied the campaigns to variants of Claude, GPT, Gemini, and Grok. Their technique mapping runs from initial access through exfiltration. That sequencing treats distillation as an intrusion, not a licensing dispute.

Anthropic’s report gives that warning a specific body count. The largest operation, attributed to Alibaba, generated roughly 151 million exchanges with Claude between May and July 2026. The traffic arrived through fraudulent accounts, not ordinary use.

That is not experimentation.

The method is no longer a secret. Anthropic says the labs used stolen payment credentials and grey-market relay points called transfer stations. Third-party routing services also relayed queries, and Anthropic warns that can expose user data.

Scott Bessent put the Treasury’s position plainly in July, saying the U.S. could sanction overseas models found to be stealing from American companies. Michael Kratsios, who leads the White House Office of Science and Technology Policy, has asserted that Moonshot AI distilled Anthropic’s Fable model to build Kimi K3.

Anthropic’s head of policy, Sarah Heck, calls the campaigns industrial espionage rather than a commercial dispute. In 2026 testimony before the Senate Judiciary Committee, Yasmin Toner stated there is strong evidence Chinese AI firms are using distillation to extract capabilities from American models. Mahmood Y. described fake accounts generating synthetic data to train Chinese systems.

Anthropic also warns that distilled copies do not inherit Claude’s safety guardrails. Such systems may be used to pursue dangerous capabilities. That is the thread running from a stolen API key to a national-security concern.

One claim remains more fragile than the others. According to Anthropic’s report, Moonshot AI traffic was routed through Chinese military networks, but that detail rests on a single source and has not been independently corroborated by other named parties.

Measured distillation campaigns linked to Chinese AI firms
Metric Figure Source Date
Named Chinese firms in advisory 6 firms NSA-CISA-FBI Sept 8 2026
Moonshot AI-attributed Claude exchanges >23 million Anthropic May-July 2026
DeepSeek distillation attacks, 14-day window >12 million Anthropic July 2026
Alibaba-linked fraudulent accounts >3,500 Anthropic May-July 2026
Alibaba peak daily exchanges ~3 million Anthropic May-July 2026
Source: NSA-CISA-FBI advisory AA26-251A; Anthropic threat intelligence report

The sequence below shows how a teacher model becomes training data for a student that never asked permission.

The documented scale raises a different question: why Washington had no legal category for it until now.

A legal system built for contracts, not model theft

Washington’s tools still rely on contract law, trade-secret statutes, and export controls. Providers ban industrial extraction in their terms of service and treat violations as computer misuse. That framework was not built for campaigns measured in millions of queries across fraudulently created accounts.

China’s domestic AI rules deepen the asymmetry. They regulate content safety and algorithm registration, but they do not expressly forbid distillation of foreign models. That leaves room for appropriation by design.

The asymmetry is structural.

The immediate Western exposure is procurement, not cyber risk. A compliance officer at a European bank piloting a Chinese open-weight model now faces a provenance question no standard vendor contract answers. Regulators could still pressure banks and health providers to avoid models named in the advisory, even before sanctions bite.

Treasury has not yet issued a formal designation. Its authority, Bessent has said, runs through existing economic sanctions frameworks rather than new legislation. The two frames remain surprisingly far apart.

The Treasury’s first designation decision is the moment the pattern could break. If sanctions land, the named labs stop being a warning and become entities few Western firms can legally touch. If they do not, the same technique continues under contract terms written for a different era.

Beyond the headline

The Money Trail

The financial benefit accrues in layers. First, labs skip the training bill. Then app builders and cloud providers gain a low-cost model. Finally, state-linked integrators embed it in sectors where pricing matters more than provenance.

The Power Behind It

The advisory’s “likely with Chinese government awareness” phrasing is the operative line. It shifts the issue from intellectual property litigation to statecraft. Washington’s response follows the same logic: sanctions and export authority sit with Treasury and national-security agencies, not civil courts.

The Timing

The report lands during pending U.S. rules on remote GPU access and a political cycle in which AI security has become headline news. Publishing named attributions now looks like an effort to shape the decision calendar before export and sanctions actions lock in.

A sanctions decision turns the list into exposure

With a designation decision possible within the coming quarters, four groups face immediate choices.

  • Western enterprise procuring or integrating Chinese AI models

    You should pull the NSA-CISA-FBI advisory from cisa.gov and map it against any Chinese model in your pipeline. Check contracts for IP warranties and indemnity clauses, especially in finance or healthcare. Prepare for a compliance review before the next procurement cycle closes.

  • US-based investor with exposure to Chinese AI companies

    Monitor the Treasury Department page at treasury.gov for any designation decision tied to AA26-251A or Anthropic’s September report. Assess whether your positions include the six named firms or their parents. Early movement in export controls may be the leading indicator before formal sanctions.

  • US government official or policy professional focused on AI and China

    Use the advisory’s technique mapping and Anthropic’s casebook to inform enforcement options. The distinction between legitimate distillation and industrial extraction in AA26-251A is the line policy can cite. Coordinate with CISA and Treasury on whether existing sanctions authority is sufficient before drafting new legislation.

  • AI developer or researcher at a Western frontier model lab

    Treat fraudulent accounts, transfer stations, and routing services as the primary attack surface. Tighten anomaly detection on high-volume, domain-specific prompts and limit chain-of-thought logging where possible. Share detection patterns with peer labs through U.S. AI security channels.

FAQ

Will existing contracts with Chinese AI providers be affected?

Contracts may be renegotiated if U.S. agencies formally treat illicit distillation as IP theft. Look for clauses on IP warranties, indemnity, and foreign-law compliance. Regulated sectors such as finance and healthcare face the most immediate counterparty pressure to suspend or terminate agreements.

How would sanctions change access to Chinese AI models?

If Treasury designates specific labs or parents, U.S. persons would be barred from providing services or transacting with them. Hosted APIs and related compute could be cut off. Secondary sanctions risk might also deter non-U.S. integrators. Past designations led cloud providers to block accounts and marketplaces to delist services.

What practical steps can secure API use against distillation abuse?

Organizations exposing APIs can tighten rate limits, monitor query patterns, and require verified billing for reseller accounts. The advisory suggests campaigns favor proxies and fraudulent identities. High-volume, domain-specific prompts deserve anomaly detection, and chain-of-thought logging should be limited where possible.

Explainer

Knowledge distillation
A training method in which a smaller student model learns from a larger teacher model’s outputs rather than raw data. Legitimate use happens with the teacher owner’s consent and within agreed rate limits. The U.S. government has not banned the technique itself; legality turns on authorization and scale.
Transfer stations
Grey-market relay points that forward prompts to model APIs while hiding the requester’s true location or identity. They help bypass regional blocks and fraud checks. A 2026 campaign attributed to Alibaba used more than 3,500 fraudulent accounts along with such relays.
AA26-251A
Identifier for a joint cybersecurity advisory issued by the NSA, CISA, and FBI on September 8, 2026. It names six China-based AI firms and maps their tactics to the MITRE ATLAS framework. The advisory is the first formal U.S. government document to separate legitimate distillation from “aggressive, malicious, and targeted” industrial campaigns.
Qwen
Alibaba’s family of AI models. The Qwen 3.5–3.7 series was implicated in Anthropic’s largest detected distillation campaign. Alibaba has also used distillation to improve software engineering and customer service capabilities, according to the advisory.

Covered in this article: East Asia Australia China

Indoneo APAC Desk

The editorial operation behind Indoneo's breaking news and developing story coverage. The APAC Desk monitors primary sources across 75 countries and territories — governments, regulators, research institutions — and answers the question regional coverage rarely asks: what does this mean for a Western reader's money, travel, safety, or decisions. Indoneo's reporting is produced using AI-assisted drafting within an editorial pipeline built for source verification and originality.