Tuesday, September 15, 2026
AI Infrastructure · News & Analysis
HomePolicyReport
Policy · Report

Anthropic and US authorities disclosed that Chinese military researchers and tech giants including Alibaba used Claude to develop 16 air-defense suppression tools, draft anti-torpedo specifications, and execute 151 million distillation queries.

Validates export-control rationales for US frontier models; likely to trigger stricter API access controls by Anthropic and competitors, and accelerates Chinese demands for indigenous frontier-AI systems.
Trade pressSlicast · September 13, 2026 at 12:00 UTC · Global · Source: Tom's Hardware
importance 80

While China claims to possess advanced AI models potentially competitive with those developed in the United States, Anthropic's September 2026 threat report documents that hundreds of China-linked agents used Claude for at least five distinct programs: two military, two surveillance-related, and one aimed at extracting Claude's capabilities.

One China-based actor used Claude to draft fire-control specifications for an anti-torpedo system—the core logic governing when and where to engage incoming threats—and tested the potential system against publicly known U.S. Navy capabilities. The actor created a 200+ page technical proposal while disguising itself as a U.S. defense-sector OEM. Anthropic assesses the actor was associated with a Chinese defense manufacturer developing systems for the People's Liberation Army Navy.

A second China-based military researcher used Claude to develop approximately 16 software modules for electronic warfare and suppression of enemy air defenses. The modules analyzed radars, SAM sites, command posts, and communications nodes while prioritizing targets. Default scenarios contained 12 targets in Taiwan, including Patriot and Tien Kung batteries, air bases, an early-warning radar, and a command bunker. Account metadata and content flagged by Anthropic's safeguards indicated links to PRC research institutions, including the PLA Academy of Military Sciences, though Anthropic stopped short of directly attributing the work to the PLA.

Given China's substantial AI capabilities, it is striking that military-related projects relied on Claude. Chinese-language prompts and account-level evidence suggest plausible deniability was not the primary motivation. More likely, Claude proved superior or more convenient for the specific engineering workflows—particularly coding, reasoning, and agentic tasks. U.S. frontier models trained on vast amounts of English-language material may also offer particularly extensive knowledge of publicly available information on American military technologies and systems.

In surveillance operations, Anthropic disrupted activities targeting Uyghurs outside China. One government-linked actor used Claude while posing as an Arabic-speaking consultant to infiltrate Uyghur armed groups in Syria and surveil diaspora activists and media. After establishing presence in these groups, Claude helped process information from over 100 WhatsApp groups and dozens of Telegram channels, identify individuals across platforms, map social networks, and identify vulnerable recruitment targets. The operation also targeted diaspora journalists, particularly Uyghur Post, through coordinated mass-reporting and bot-amplification campaigns.

The most striking finding involves outright theft. Anthropic reports that several major Chinese AI developers conducted industrial-scale distillation campaigns to extract Claude's reasoning and other capabilities and reproduce them in proprietary models. Alibaba's operation was the largest, generating over 151 million Claude exchanges between May and July 2026—at one point approaching 3 million requests per day through thousands of fraudulent accounts. Anthropic states the harvested chain-of-thought data trained Qwen 3.x, particularly for reasoning, coding, agentic software engineering, kernel development, and long-horizon tasks.

Alibaba was not alone. Anthropic accuses DeepSeek, Xiaomi, Zhipu/Z.ai, and others of similar campaigns using proxy networks, fraudulent accounts, identity obfuscation, and in some cases purchasing harvested Claude conversations from third parties. DeepSeek alone generated over 12.1 million exchanges in 14 days, while Xiaomi generated over 400,000. Anthropic defines this activity as distillation: covertly extracting a frontier model's answers and then replicating the knowledge at a fraction of the compute, time, and cost required for in-house development.

Read the original
Anthropic and US authorities disclosed that… · Slicast