Anthropic has released a report highlighting ongoing distillation attacks targeting its AI models, primarily conducted by China-based companies. These attacks have grown more sophisticated and frequent amid rising competition in the AI sector. Distillation attacks involve extracting a model's internal reasoning process to train smaller models with similar capabilities. Anthropic’s models typically do not expose detailed reasoning steps to users, but attackers have developed methods to bypass these protections.

The largest campaign, attributed to Alibaba, involved 151 million interactions between May and July 2026, using a fixed prompt to extract reasoning chains. This effort is believed to support training for Alibaba’s Qwen model series. Another campaign linked to Moonshot AI, which produces the Kimi model, reportedly routed requests through thousands of accounts, including queries related to surveillance footage analysis, suggesting possible military applications.

Anthropic previously raised concerns about such attacks earlier this year, and similar activity has been reported by OpenAI, with some efforts linked to DeepSeek. The scale and aggressiveness of these recent campaigns underscore the challenges AI developers face in protecting their models’ intellectual property and maintaining competitive advantage in a rapidly evolving market.