Tuesday, September 15, 2026
AI 인프라 · 뉴스 & 분석
정책리포트
정책 · 리포트

중국 AI 연구소들이 Claude API 대화 1억 9,000만 건을 추출해, 생성형 AI 데이터 흐름의 수출통제 집행 공백을 노출시켰다.

이 침해는 AI 모델 상호작용 보호의 취약점을 드러내며, 중국에 대한 현재 수출 제한의 실효성에 의문을 제기한다.
업계 전문지Slicast · 2026년 9월 12일 12:24 UTC · 미국 · 출처: Tech Times
중요도 75

Seven Chinese AI companies collectively ran approximately 190 million unauthorized exchanges with Anthropic's Claude between May and July 2026—a roughly 12-fold increase from the 16 million exchanges documented in February 2026—even as the US government issued a White House national security memo, the Commerce Department restricted access to Anthropic's most advanced models, Anthropic testified before the Senate, and bipartisan legislation moved through the House Foreign Affairs Committee. Anthropic confirmed the scale in its September threat intelligence report, published September 10.

Anthropic's 154-page September 2026 threat intelligence report is the most detailed accounting to date of what the company calls "illicit distillation": the systematic extraction of a frontier AI model's capabilities through unauthorized API access, without bearing the billions of dollars in compute and research that produced those capabilities. The report arrived two days after the NSA, CISA, and FBI issued a joint US intelligence advisory identifying "aggressive, malicious, and targeted distillation activities at an industrial scale," naming six Chinese AI companies.

The scale increase carries profound implications because it occurred not despite US government attention but during it. Every major US policy response preceded or overlapped with the seven-lab September campaign: the White House Office of Science and Technology Policy's April 23 memo designating foreign distillation a national security threat; the Commerce Department's June 12 directive restricting Anthropic's Fable 5 and Mythos 5 models for all foreign nationals; Anthropic's June Senate Banking Committee testimony framing the attacks as a "national security problem, not a terms-of-service dispute"; and the House Foreign Affairs Committee's unanimous April 22 vote advancing the Deterring American AI Model Theft Act.

**How Export Controls Fail Against Software-Layer Theft**

US chip export controls toward China rest on a single logic: limit China's access to advanced GPUs required to train frontier AI models, and China's AI capabilities will fall behind American labs. The September distillation data documents the structural hole in that logic.

Illicit distillation attacks require no advanced hardware. Operators create networks of fraudulent accounts using stolen credit cards, compromised API keys, and credentials purchased from dark-web brokers. Proxy services—commercial VPN nodes and residential IP relay networks—mask the geographic origin of API calls. Per the joint NSA/CISA/FBI advisory, the campaigns ran through "native APIs, cloud platforms, and third-party aggregators." Once the network is in place, operators use engineered prompts to elicit chain-of-thought reasoning traces from Claude—not just final answers, but the intermediate reasoning steps underlying those answers. Those traces become training data.

Chain-of-thought traces are more valuable than output-only distillation because they transfer reasoning patterns rather than surface-level responses. A student model trained on chain-of-thought traces learns not just what a frontier model concludes, but how it works through problems—the capability difference that justifies frontier models' billion-dollar development costs. Zhipu, tracked as GTG-16006, added a refinement step: replaying Claude's own reasoning traces back through Claude to improve the quality of captured training data, as Anthropic's report documents.

The economics are staggering. Anthropic's head of policy Sarah Heck told the Senate Banking Committee in June that the practice was "effectively converting billions of dollars in American investment and R&D into a massive subsidy for our geopolitical competitors." Accessing Claude through fraudulent API accounts costs a fraction of the compute investment required to train a comparable model from scratch. No chip transfer occurs. The capability transfers instead—and US export controls have no mechanism to stop it.

**Alibaba: 151 Million Exchanges, the Largest Attack Documented**

The single most extensive campaign was attributed to operators linked to Alibaba's Qwen division, tracked as GTG-16005. Between May and July 2026—the same period when the Trump administration and Anthropic were publicly framing distillation as a national security emergency—those operators ran more than 151 million Claude exchanges, peaking at close to three million interactions in a single day.

The campaign deployed more than 3,500 fraudulent accounts that Anthropic had flagged. What enabled attribution to a coordinated operation was a shared, fixed prompt used consistently across all accounts—engineered specifically to force chain-of-thought reasoning output, turning every interaction into a structured training data harvest. Anthropic said those transcripts trained Alibaba's Qwen family of models. Alibaba has not issued a formal public denial.

The context sharpens Alibaba's own public claims: Qwen3.7-Max benchmarks comparably to Claude Opus 4.6 on software engineering evaluations.

The Alibaba campaign exceeded all prior distillation records by a wide margin. Anthropic's June 2026 Senate letter, which named Alibaba as running "the largest known distillation attack," documented 28.8 million exchanges through approximately 25,000 fake accounts. The September report more than quintupled that figure.

**Moonshot and DeepSeek: Customer Data Routed Without Consent**

Beyond generating fraudulent traffic, two of the seven labs crossed an additional line: they routed real conversations from their own paying customers through Claude without those customers' knowledge or consent, then displayed Claude's responses as their own products. Portions of those intercepted exchanges were simultaneously captured as training data.

For Moonshot AI, tracked as GTG-16002, Anthropic documented more than 23 million exchanges between May and July 2026. In one 10-day burst, approximately 5,380 fraudulent accounts relayed nearly 300,000 customer requests through proxy services. The forwarded sessions "contained names, email addresses, and corporate material belonging to hundreds of people, in more than a dozen languages," Anthropic reported, noting that many queries arrived via "AI model routers popular in the United States and Europe." This means US and European enterprise users who believed their queries were reaching Anthropic—or a trusted third-party AI router—may have had their conversations captured by a company subject to China's National Intelligence Law with no recourse.

Anthropic noted a particularly alarming detail: some requests appearing to originate from Moonshot's Kimi platform came from IP addresses associated with the Chinese military, including one asking Claude to assess closed-circuit surveillance footage to determine whether a subject was "behaving abnormally."

For DeepSeek, tracked as GTG-16001, Anthropic documented more than 12.1 million exchanges over just 14 days in July 2026 through the same proxy-and-capture approach. Anthropic said both practices are "likely inconsistent with privacy laws and the labs' own terms of service."

This privacy dimension is not incidental. Every Chinese company subject to China's National Intelligence Law—which Article 7 requires to "support, assist, and cooperate with national intelligence work"—has an unconditional legal obligation to hand this data to the Chinese government on demand, regardless of server location, stated privacy policy, or Western subsidiary structure.

**What Did US Policy Responses Actually Accomplish?**

The question the September report's data forces is blunt: did any of the policy responses deployed between February and September 2026 work?

The White House OSTP memo NSTM-4, issued April 23, 2026, designated foreign distillation campaigns a national security threat and directed federal agencies to share intelligence with US AI developers. It included no new sanctions, no entity list additions, and no API-access restrictions. The Commerce Department's June 12 directive restricted Anthropic's Fable 5 and Mythos 5 models from all foreign nationals worldwide—but the September report confirms that all seven distillation campaigns targeted "generally available models," specifically Claude Haiku, Sonnet, and Opus, with one exception. Restricting access to Anthropic's most advanced models did not stop campaigns against its widely deployed commercial models.

The Deterring American AI Model Theft Act, which the House Foreign Affairs

원문 보기
중국 AI 연구소들이 Claude API 대화 1억 9,000만 건을 추출해,… · Slicast