Technology

Anthropic urges penalties over alleged Alibaba Claude cloning

Anthropic told senators that Alibaba-linked operators used nearly 25,000 accounts to extract Claude capabilities, according to a letter obtained by Ars Technica.

Maya Lindqvist

By Maya Lindqvist · Senior Technology Correspondent

3 min read

Anthropic urges penalties over alleged Alibaba Claude cloning
Photo: Ars Technica

Anthropic has accused Alibaba-linked operators of running what it calls the largest known effort to copy Claude’s capabilities. The allegation matters because Anthropic is asking Congress to respond with new penalties and stronger controls on Chinese access to U.S. AI systems and chips.

In a June 10 letter to Sens. Tim Scott, R-S.C., and Elizabeth Warren, D-Mass., obtained by Ars Technica, Anthropic said it had found “new, confidential evidence” of a campaign to extract Claude’s abilities. The letter was sent one day before a Senate committee hearing on “AI and the American Dream.”

Anthropic said the activity ran from April 22 to June 5 and involved operators affiliated with Alibaba and Alibaba Qwen, the company’s AI lab. According to Anthropic, the operators created more than 28.8 million exchanges with Claude through nearly 25,000 fraudulent accounts.

The company said the campaign violated Claude’s terms and access restrictions. Anthropic alleged that the activity focused on high-value functions including agentic reasoning, software engineering and long-running tasks.

Anthropic also told senators that the operators used proxy networks and other concealment methods to avoid detection. The company warned that demand for such tools in China is feeding what it described as a growing market for circumvention services used in model-distillation attacks.

Claims of broader Chinese efforts

Anthropic said Alibaba’s alleged goal matched a pattern it has described among Chinese AI labs: using U.S. models to improve domestic systems without paying the full cost of training and research. The company said such attacks convert American AI investment into a benefit for geopolitical competitors.

The letter connected the alleged Alibaba campaign to earlier U.S. warnings. Anthropic noted that the activity took place after President Donald Trump moved in April to curb foreign attempts to copy U.S. frontier AI models.

Anthropic previously accused Chinese firms DeepSeek, Moonshot and MiniMax of using similar methods to generate more than 16 million exchanges with Claude through about 24,000 fraudulent accounts. Anthropic said OpenAI and Google have also published findings on comparable attacks against their models.

Alibaba could not immediately be reached for comment by Ars Technica. Separately, Reuters reported that Alibaba sued the Trump administration after the Pentagon designated it a Chinese military company, a label Alibaba said had “no basis in fact or law.”

In that lawsuit, Reuters reported, Alibaba said it is run by an independent board with no military affiliation and that its products serve retail, logistics and enterprise information technology rather than weapons, defense or intelligence.

Policy changes sought

Anthropic urged Congress to pass legislation aimed at deterring future model-copying campaigns. The company recommended changes to antitrust law so AI firms can share information about Chinese tactics, tighter export controls on advanced chips, and penalties for Chinese labs that rely on distillation attacks.

Possible penalties, Anthropic said, could include restricting Chinese firms’ access to U.S. models, advanced U.S. chips or data centers outside China. The company said stronger measures are needed to keep China from reaching capabilities similar to Anthropic’s Mythos Preview system sooner.

Anthropic declined to tell Ars Technica whether the alleged Alibaba activity was enough to meaningfully speed up Chinese AI development. A company spokesperson said Anthropic believes government and industry must work together to combat illicit distillation and preserve U.S. AI leadership.

The letter also warned that if China closes the gap, it could use advanced cyber capabilities against the U.S. government and American companies. Anthropic said a larger U.S. lead would give officials more time to strengthen cyber defenses and adopt AI in national security work.

The South China Morning Post reported that Zhou Hongyi, founder of 360 Security Technology, recently described Anthropic’s Mythos as a “cyber nuclear weapon” at a Beijing cybersecurity conference. SCMP reported that Zhou said Chinese firms remain well short of Mythos-level capabilities and argued that China needs its own comparable model.

This story draws on original reporting from Ars Technica.