Morning Edition · Friday, September 11, 2026Published at 2:22 AM EDT · New York
The September threat report names DeepSeek, Moonshot AI and MiniMax in smaller efforts, and puts model extraction alongside cyber operations and weapons research as a named harm category.

Anthropic released its September 2026 threat intelligence report on Wednesday, covering misuse it says it detected and disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.
The largest single case involves distillation. Anthropic says accounts it links to Alibaba conducted more than 151 million exchanges with Claude models between May and July 2026, spread across roughly 3,500 accounts that all used one fixed prompt designed to extract the model's chain of thought. Because the prompt was identical across accounts, Anthropic attributes the traffic to a single coordinated effort to build training data for the Qwen model family. TechCrunch reports that the Alibaba case was the largest of five campaigns Anthropic attributes to China-based AI companies, with smaller volumes tied to DeepSeek, Moonshot AI and MiniMax. CNBC notes that this follows a June accusation from Anthropic against Alibaba over a separate, earlier extraction effort.
What is confirmed here is limited. Anthropic controls the logs, the account data and the attribution method, and it is also the commercial party harmed if Qwen closes the capability gap using Claude's outputs. The companies Anthropic names have not, by its own account, admitted to the activity. A shared prompt appearing across thousands of accounts is reasonable evidence of coordination, but tying those accounts to a specific corporate owner is a judgment call that no outside party has yet reproduced. The exchange counts should be read as Anthropic's own measurement of its own service, not as an independently confirmed finding.
The report also describes a broader shift in who can carry out advanced operations. Anthropic argues that model assistance across reconnaissance, tooling, data processing, exploitation and exfiltration lets less skilled operators achieve results that previously required experienced teams, a framing CyberScoop summarizes as small actors running state-level campaigns. Anthropic also describes a new category of actors building software for firearms, missiles, armed drones and munitions, and says it blocked attempts at research relevant to biological weapons.
Part of a tracked trend
Chinese Open-Weight Models Emerge as the Non-US AI Stack
As Washington restricts foreign access to US frontier models, governments and enterprises cut off from American AI increasingly standardize on downloadable Chinese open-weight models, splitting the world into competing AI supply blocs rather than a single frontier.
Start a discussion in Townsquare.
More from this edition
Anthropic and the other US frontier labs, whose commercial case against low-cost Chinese rivals becomes a national-security argument, and US legislators already drafting defense-bill amendments to restrict Chinese access to American model application programming interfaces (APIs), while Alibaba's Qwen line takes provenance risk with enterprise buyers.
That the traffic existed and shared one extraction prompt is Anthropic's own telemetry, which no outside party has audited, and the load-bearing step is corporate attribution: Anthropic says it does not serve mainland China, so linking roughly 3,500 accounts to Alibaba itself rests on inference, Alibaba denies training on proprietary model outputs without issuing a technical rebuttal, and experts quoted by Global Times call the claims commercial anxiety recast as security policy.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Distillation is now a named security category rather than a licensing dispute, and that changes what frontier vendors do at the API layer. Expect tighter identity verification, limits on how much chain-of-thought output any account can extract, and refusal to serve regions or resellers a vendor cannot vet. That adds cost and delay for every legitimate high-volume API customer, and it gives US policymakers a concrete case for extending export controls from chips to model access itself. Alibaba carries the direct reputational exposure, and buyers evaluating Qwen's model weights now face a provenance question they cannot resolve on their own. Two outcomes matter most: either Alibaba or the other named labs produce a rebuttal that survives scrutiny, or the accusation becomes the accepted factual basis for US rules on who may access a frontier model.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Anthropic News · TechCrunch · CNBC · CyberScoop
Comments
0No comments yet.