← Google News

Anthropic accuses Alibaba of largest-known AI model theft attempt, cites 28.8 million Claude queries - Firstpost

Google News · June 24, 2026
Anthropic accuses Alibaba of largest-known AI model theft attempt, cites 28.8 million Claude queries Firstpost [truncated: Google News RSS provides only a snippet, not full article

Detailed Analysis

Anthropic has leveled a serious accusation against Chinese technology giant Alibaba, alleging the company orchestrated what Anthropic describes as the largest-known attempt to steal an AI model's underlying capabilities, involving approximately 28.8 million queries directed at Claude. The scale of the alleged activity suggests a systematic, coordinated effort rather than incidental use, with the sheer volume of interactions pointing toward a process known in the AI industry as model extraction or distillation — a technique by which an adversary probes a proprietary model extensively to replicate its behavior, reasoning patterns, and outputs in a separate system without access to the original training data or weights.

The significance of 28.8 million queries cannot be understated in the context of AI intellectual property disputes. Model distillation at this scale would allow an actor to construct a so-called "shadow model" that mimics the target system's capabilities by learning from its responses. Anthropic's terms of service explicitly prohibit using Claude's outputs to train competing AI systems, and if the allegations are substantiated, Alibaba's conduct would represent not only a contractual violation but potentially a broader legal challenge touching on trade secret protections and unfair competition law. The framing of this as the "largest-known" such attempt signals that Anthropic views this as a landmark case rather than a routine enforcement action.

The accusation arrives amid an intensifying global competition in frontier AI development, particularly between American and Chinese technology firms. Alibaba has invested heavily in its own large language model ecosystem, most notably through its Qwen model series, which has demonstrated competitive performance on international benchmarks. The allegation, if proven, would suggest that rather than relying solely on internal research, actors within Alibaba's orbit may have sought to shortcut the expensive and time-consuming process of original model development by leveraging access to a leading Western AI system. This raises questions about the adequacy of API-level safeguards and the enforcement mechanisms available to AI companies when confronting well-resourced adversaries.

For Anthropic specifically, this dispute carries reputational and strategic weight beyond the immediate legal dimensions. As a safety-focused AI company that has positioned Claude as a commercially valuable and ethically governed system, the alleged theft strikes at both its business model and its brand integrity. The case also highlights a vulnerability inherent in offering powerful AI systems as accessible cloud services: broad access, by design, creates surface area for potential misuse at scale. Anthropic's decision to go public with the accusation — naming Alibaba specifically and citing a precise query count — suggests a deliberate strategy to establish public accountability and signal to the broader industry that such extraction attempts will be pursued aggressively.

More broadly, this case is likely to accelerate conversations within the AI industry and among policymakers about how to protect proprietary AI systems from extraction attacks. Detection of anomalous query patterns, rate limiting, behavioral fingerprinting, and output watermarking are among the technical countermeasures that have been discussed in research contexts, and high-profile incidents of this nature are likely to push companies toward deploying them more systematically. The Anthropic-Alibaba dispute may thus serve as an inflection point, prompting the industry to treat model extraction as a first-order security concern rather than a theoretical risk.

Read original article →