Anthropic has formally accused Alibaba of conducting a large-scale model distillation attack, alleging that the Chinese technology company created thousands of fake accounts to harvest approximately 28.8 million Claude conversations. According to Anthropic's disclosure, this systematic effort was designed to extract and replicate Claude's capabilities without authorization or payment. The accusation, detailed in multiple reports and statements, represents one of the most substantial documented cases of unauthorized AI model extraction and raises critical questions about API security and the scalability of safeguards protecting proprietary AI systems. Alibaba has not publicly responded to the allegations as of publication, declining to comment on the specific claims.

Anthropic's investigation identified technical signatures indicating coordinated, large-scale access patterns inconsistent with legitimate user behavior, including the creation of shell accounts and automated harvesting workflows. The company has implemented concrete countermeasures in response, including enhanced rate-limiting mechanisms, behavioral anomaly detection systems, and stricter account verification protocols designed to identify and block similar coordinated attacks. The timeline of discovery and public disclosure remains partially unclear, though reports indicate the company identified the activity during routine security audits. Security researchers have characterized the incident as a sophisticated adaptation of well-known model distillation techniques, wherein competitors systematically query AI systems to train cheaper alternatives that approximate their performance.

Beyond the immediate security implications, the Alibaba incident underscores vulnerabilities in API-based AI distribution models and raises broader questions about enforcement mechanisms in competitive AI markets. Anthropic simultaneously announced Claude Tag integrations for Slack enterprise and team plans, signaling continued product expansion even amid security challenges. Industry analysts note that such large-scale attacks may prompt broader adoption of authentication frameworks, usage analytics, and contractual protections across the AI sector. The incident highlights why Constitutional AI and robust safety mechanisms remain central to Anthropic's competitive positioning, as customers increasingly factor security practices into vendor selection for critical AI infrastructure.