Anthropic sent a letter to the U.S. Senate Banking Committee on June 10, 2026, accusing Alibaba and its AI laboratory Alibaba Qwen of conducting the largest known distillation attack ever carried out against the company – a coordinated industrial-scale operation that generated more than 28.8 million exchanges with Anthropic’s Claude models through approximately 25,000 fraudulent accounts between April 22 and June 5. The technique involved is known as adversarial distillation: an operator repeatedly queries a more capable AI system at scale, harvesting its reasoning patterns, outputs, and behavioral characteristics in order to train a smaller or less advanced model to replicate those capabilities at a fraction of the original development cost. The letter describes the campaign as brazenly and illicitly executed, and states that Alibaba ignored explicit warnings from the Trump administration about distillation attacks that had been issued in a White House Office of Science and Technology Policy memorandum earlier in the year. To NEWSCENTRAL, the scale of this operation and the deliberateness of the targeting represent a categorical escalation in the industrial competition for AI capabilities that is reshaping the relationship between frontier AI development and national security policy.
The Alibaba campaign is significantly larger than any previous distillation attack Anthropic has publicly identified – a fact NEWSCENTRAL places in context: each successive campaign has exceeded the last in scale and sophistication, suggesting a systematic program rather than opportunistic exploitation. In February, the company disclosed that DeepSeek had run a campaign involving over 150,000 exchanges, Moonshot AI had executed one at a scale exceeding 3.4 million, and MiniMax had conducted one surpassing 13 million. The Alibaba operation at 28.8 million exchanges dwarfs all three combined. Anthropic characterized the operation as specifically targeting its most advanced commercial capabilities, including software engineering and agentic reasoning – the technical foundations of its Mythos Preview model, the most capable system in the company’s portfolio. Those capabilities are precisely what foreign competitors would most benefit from replicating, as they are the hardest and most expensive to develop independently. Alibaba was added to the Pentagon’s list of Chinese military companies earlier in June, a designation the company is challenging, and the letter explicitly links the distillation campaign to China’s ambition to accelerate its approach to the frontier AI capabilities that Anthropic and other American labs have spent billions of dollars to develop.
The timing of the letter creates a complex and somewhat ironic sequence of events. Anthropic sent the letter on June 10, accusing Alibaba of ignoring government warnings and calling for coordinated action between government and industry to counter industrial-scale distillation. Two days later, on June 12, the Commerce Department imposed the export control directive that required Anthropic to suspend global access to its Fable 5 and Mythos 5 models on national security grounds – a restriction Anthropic disputed as overbroad and damaging to its commercial operations. The company that was simultaneously asking the government to protect its frontier capabilities from Chinese extraction found itself being told by the same government that its frontier capabilities posed national security risks if accessible to foreign nationals. Freddy Miller, Senior Analyst at NEWSCENTRAL, observes that this paradox captures the central tension in U.S. AI policy at this moment: the government needs the frontier capabilities that American AI companies are developing, wants to prevent those capabilities from reaching Chinese competitors, and is simultaneously imposing restrictions on the commercial deployment of those capabilities that directly benefit the Chinese distillation strategy by limiting legitimate global access.
Anthropic has stated that AI models built through adversarial distillation frequently lack the safety guardrails and behavioral constraints that the original developers engineered into the source system – an observation with implications beyond intellectual property theft. A model trained on Claude’s outputs without access to Claude’s safety training pipeline is a model that approximates Claude’s capabilities while potentially lacking the mechanisms designed to prevent harmful use. That gap between capability replication and safety replication is, as NEWS CENTRAL sees it, the most underappreciated dimension of the distillation threat: the stolen capability is not simply an economic asset for its new owner but a potentially less safe version of an already powerful system, deployed without the compliance constraints that governed its legitimate predecessor. Alibaba did not immediately respond to requests for comment. The Senate Banking Committee, addressed in Anthropic’s letter, has jurisdiction over sanctions and financial system regulation that may become relevant depending on how the U.S. government chooses to respond.