广告
加载中

Anthropic称多家中国AI实验室盗用超亿条Claude对话训练模型

亿邦动力 2026-09-14 09:34
亿邦动力 2026/09/14 09:34

邦小白快读

EN
全文速览

你可重点了解本次AI行业侵权事件的核心信息,掌握AI产品使用中的个人信息保护实操要点。

1. 核心事件基本情况:2026年9月11日美国AI企业Anthropic发布威胁情报报告,披露2025年12月至2026年8月间阻断了多起来自中国AI实验室的未授权访问,这类未经许可使用Claude模型输出训练自有模型的行为被定义为“非法蒸馏”,涉及交互规模超亿次,报告同时提及阻断的风险活动还包括网络行动、诈骗欺诈、生物滥用等六类,阿里巴巴、Moonshot、DeepSeek、小米等多家国内头部AI企业被点名。

2. 涉事企业具体行为:阿里巴巴关联方2026年5至7月调用超1.51亿次Claude交互训练Qwen模型,峰值每日靠3500余个欺诈账号发起近300万次请求;推出Kimi的Moonshot偷转用户请求到Claude后回传,用户全程不知情,3个月调用超2300万次,还留存内容训练自有模型;DeepSeek采取同类操作,2026年7月仅14天就发起超1200万次请求。

3. 实操注意点:涉事企业转发的内容包含大量个人、企业敏感信息,你使用上述国内AI产品时,尽量不要提交隐私、机密类内容;截至报道发布所有涉事方均未回应,可持续关注事件进展。

本次非法蒸馏指控事件,可为AI领域品牌商在合规建设、用户信任维护、产品研发层面提供明确参考。

1. 品牌合规风险提示:未经授权使用其他厂商大模型输出训练自有模型的非法蒸馏行为,属于明确的侵权操作,还可能违反隐私法规、违背自身服务条款,部分涉事企业隐瞒用户转发请求到第三方模型的操作,存在侵犯用户知情权、泄露多方敏感信息的问题,会直接冲击品牌的自研人设与公众信任。从披露数据看,阿里关联方3个月调用超1.51亿次Claude内容,甚至用于强化学习、架构搭建等核心研发环节,这类行为一旦坐实会对品牌声誉造成极大打击。

2. 用户认知观察:本次事件暴露出AI用户对内容流向、服务真实提供方的敏感度极高,品牌在营销、服务过程中需明确告知用户服务主体、数据用途,刻意隐瞒极易引发信任危机。

3. 研发边界提示:靠偷取头部模型输出追赶技术差距的路径,虽短期能降本提效,但合规风险极高,品牌需平衡研发效率与合规边界,规避类似侵权问题。

本次AI行业侵权事件,能为AI相关赛道卖家提供风险预警、机会挖掘与事件应对的实操参考。

1. 明确经营风险:AI类产品及服务卖家如果采取未经授权调用第三方大模型、偷转用户请求训练自有产品的操作,会面临被模型方阻断访问、起诉侵权的风险。本次事件中涉事企业靠大量标注为新加坡、日本地址的欺诈账号绕过限制,这类操作不仅可能违反隐私法规,还会因侵犯用户知情权引发用户维权,涉及敏感信息泄露的还可能承担对应责任。

2. 挖掘市场机会:从涉事企业的操作规模看,高性能、低成本的大模型调用存在亿级规模的市场需求,此前DeepSeek就靠性能突出、成本低廉的特点快速获得市场关注,正版授权的大模型接口、合规训练数据集服务存在明确增长空间;主打数据不泄露、服务链路透明的AI产品也会更受用户青睐。

3. 事件应对要点:经营AI工具的卖家需尽快梳理自身模型调用链路,明确告知用户数据流向,提前对接正版模型授权,规避侵权风险。

本次国内AI企业被指非法蒸馏海外大模型的事件,可为布局AI相关产品、推进数字化转型的工厂提供方向参考与风险提示。

1. 产品生产设计方向提示:从本次披露的行业现状看,国内AI企业对高性能、低成本大模型能力的需求十分旺盛,甚至有企业不惜采取违规手段获取头部模型输出。工厂在布局智能硬件、嵌入式AI功能等相关产品时,要优先选择合规授权的大模型作为技术底座,避免因上游模型的知识产权纠纷影响自身产品上市与品牌口碑。

2. 数字化转型风险提示:工厂引入AI工具优化生产、搭建数字化系统时,要严格甄别AI服务商的合规性,本次事件中部分服务商偷偷将用户请求转发至第三方模型,可能导致工厂提交的生产参数、商业机密等敏感信息外泄,工厂与AI服务商合作时要明确约定数据流向与保密条款。

3. 商业机会参考:合规模型训练配套硬件、数据安全防护类硬件、本土化AI落地相关设备存在明确市场缺口,工厂可结合自身产能针对性布局。

本次Anthropic发布的非法蒸馏威胁情报,清晰呈现了AI行业的现存痛点,可为AI领域服务商指明业务拓展方向。

1. 行业趋势判断:当前AI行业处于快速迭代期,大量企业有追赶顶尖模型能力、降低训练成本的需求,但未授权蒸馏已经被头部模型厂商定义为侵权行为,会被技术手段阻断,行业合规化是明确发展趋势,靠爬取第三方模型输出训练自有模型的灰色路径已经难以为继。

2. 客户痛点梳理:从本次披露的涉事规模看,仅阿里、Moonshot、DeepSeek三家被点名企业的蒸馏交互量就超1.86亿次,反映出AI企业核心痛点包括三点,一是高性能大模型调用成本高,二是合规训练数据集资源不足,三是异常访问风控能力有待提升;同时B端客户存在AI服务链路数据易被转发泄露的痛点,本次涉事转发内容就包含大量跨国企业的敏感信息。

3. 解决方案方向:服务商可针对性推出正版大模型授权对接、合规训练数据集供给、AI链路数据加密溯源三类服务,匹配市场需求。

本次Anthropic披露的大规模非法蒸馏事件,可为各类平台商完善风控规则、规避运营风险提供实操参考。

1. 风控优化方向:本次涉事企业为绕过访问限制,注册了大量标注为新加坡、日本地址的欺诈账号,峰值阶段单日就有超3500个账号发起近300万次异常交互,说明违规主体会通过批量注册虚假地域账号的方式突破风控,平台需优化账号注册校验、异常访问识别规则,参考Anthropic的风险检测机制,及时阻断批量异常请求。

2. 运营管理要点:平台提供AI服务、对接第三方AI能力时,必须履行用户告知义务,本次事件中Moonshot、DeepSeek均未告知用户就转发请求,不仅侵犯知情权,还存在敏感信息泄露风险。平台接入第三方能力时,需在服务页面、协议中明确提示,同时增加敏感信息过滤机制。

3. 风险规避提示:平台招商引入AI类服务商时,要严格审核其模型知识产权合规性,避免引入存在侵权问题的服务商引发连带风险,平台自身训练AI模型也要规避未授权使用第三方输出的行为,防范侵权指控。

本次Anthropic发布的针对中国AI实验室的非法蒸馏指控报告,为AI产业研究、治理规则研究提供了典型新案例与研究方向。

1. 产业新动向观察:全球大模型产业已进入技术扩散阶段,头部企业与追赶者的技术壁垒正通过模型蒸馏的方式被突破,国内头部AI企业包括阿里、Moonshot、DeepSeek、小米等,不仅通过蒸馏获取头部模型能力用于模型训练,还将其应用到强化学习、模型架构搭建等核心研发环节,甚至有企业直接转发用户请求到头部模型,伪装成自有服务对外提供,此前DeepSeek就靠高性能低成本的特点快速抢占市场,这类操作是背后的重要支撑因素。

2. 产业新问题梳理:未授权蒸馏带来三类新问题,一是大模型知识产权边界模糊,使用模型输出训练其他模型的侵权认定标准尚未明确;二是数据安全风险突出,转发内容包含个人、企业、相关主体的敏感信息,极易引发隐私合规问题;三是存在不公平竞争风险,靠违规蒸馏获得成本性能优势的企业,会挤压合规研发企业的生存空间。

3. 政策启示:后续需加快明确大模型知识产权保护、AI服务用户知情权保障、训练数据合规性的相关规则,引导行业规范发展;截至报道发布所有涉事方均未回应,也反映出当前跨境AI知识产权纠纷的处置机制尚不完善。

返回默认

声明:快读内容全程由AI生成,请注意甄别信息。如您发现问题,请发送邮件至 run@ebrun.com 。

我是 品牌商 卖家 工厂 服务商 平台商 研究者 帮我再读一遍。

Quick Summary

This guide covers the key facts of the recent high-profile AI intellectual property dispute, plus practical tips to protect your personal information when using AI products.

1. Core event overview: On September 11, 2026, U.S. AI firm Anthropic released a threat intelligence report disclosing that it had blocked multiple waves of unauthorized access from Chinese AI labs between December 2025 and August 2026. The unlicensed use of Claude model outputs to train competing in-house models, defined as "illicit distillation," involved more than 100 million interactions. The report also identified six additional categories of blocked high-risk activity, including cyber operations, fraud, and biological misuse, and named leading Chinese AI players including Alibaba, Moonshot, DeepSeek, and Xiaomi.

2. Specific conduct of named firms: An Alibaba-affiliated entity made more than 151 million Claude API calls between May and July 2026 to train its Qwen model, at one point using over 3,500 fraudulent accounts to generate nearly 3 million requests per day at peak volume. Moonshot, developer of the Kimi chatbot, secretly routed user queries to Claude and returned results to users without their knowledge, logging more than 23 million calls over three months and retaining content to train its own model. DeepSeek used the same tactic, generating over 12 million requests in just 14 days in July 2026.

3. Practical user guidance: Content routed by the named firms included large volumes of personal and business sensitive information. When using the affected Chinese AI products, avoid submitting private or confidential material. As of the report’s release, none of the implicated companies have issued public responses; users may follow developments as the situation evolves.

The recent illicit model distillation allegations offer clear takeaways for AI-focused brands across compliance, user trust, and product development.

1. Compliance risk warning: Unauthorized use of third-party large language model (LLM) outputs to train in-house models constitutes clear IP infringement, and may also violate privacy regulations and contradict a company’s own terms of service. Several implicated firms hid from users that their queries were being routed to third-party models, violating user知情权 (right to know) and exposing sensitive information across multiple stakeholders—risks that directly erode a brand’s reputation for independent R&D and public trust. Per disclosed figures, an Alibaba-affiliated party made over 151 million Claude calls across three months, using outputs for core R&D workflows including reinforcement learning and model architecture design. If confirmed, such conduct would cause severe reputational damage.

2. User sentiment insight: The incident highlights that AI users are highly sensitive to how their content is handled and who actually provides the services they use. Brands must clearly disclose service providers and data use purposes in marketing and service delivery; deliberate concealment carries a high risk of triggering a trust crisis.

3. R&D boundary guidance: While stealing outputs from leading models to close technical gaps can reduce costs and accelerate development in the short term, it carries extreme compliance risk. Brands must balance R&D efficiency with clear compliance guardrails to avoid similar IP disputes.

The recent AI IP infringement incident provides actionable risk warnings, opportunity identification, and response guidance for sellers operating in AI-related segments.

1. Clear operational risks: Sellers of AI products and services that access third-party LLMs without authorization or secretly route user queries to train their own products face access blocks and IP infringement lawsuits from model owners. Firms in this incident used large volumes of fraudulent accounts registered with addresses in Singapore and Japan to bypass restrictions. Such tactics may not only violate privacy regulations but also trigger user claims over violated知情权 (right to know), with additional liability for sensitive data leaks.

2. Market opportunity identification: The scale of the implicated activity signals nine-figure demand for high-performance, low-cost LLM access. DeepSeek previously gained rapid market traction on the strength of its strong performance and low pricing, pointing to clear growth potential for licensed LLM APIs and compliant training data services. AI products positioned around zero data leakage and transparent service chains will also see stronger user preference.

3. Incident response priorities: Sellers of AI tools should audit their model supply chains immediately, clearly disclose data flows to users, and secure official model licenses in advance to mitigate infringement risk.

The allegations that Chinese AI firms engaged in illicit distillation of overseas LLMs offer strategic guidance and risk warnings for manufacturers developing AI-enabled products and pursuing digital transformation.

1. Product design and manufacturing guidance: Disclosed industry details show extremely strong demand among Chinese AI firms for high-performance, low-cost LLM capabilities, to the point that some firms resorted to rule-breaking tactics to access leading model outputs. When developing smart hardware or embedded AI features, manufacturers should prioritize licensed, compliant LLMs as their technical base to avoid IP disputes affecting product launches and brand reputation.

2. Digital transformation risk warning: When adopting AI tools to optimize production or build digital systems, manufacturers must rigorously vet AI service providers for compliance. In this incident, some providers secretly routed user queries to third-party models, creating risks of leakage for sensitive information such as production parameters and commercial secrets. Contracts with AI vendors should clearly define data flow terms and confidentiality obligations.

3. Commercial opportunity reference: Clear market gaps exist for hardware supporting compliant model training, data security protection hardware, and equipment for localized AI deployment. Manufacturers may target these segments based on their existing production capacity.

Anthropic’s illicit distillation threat intelligence report clearly outlines existing pain points in the AI industry, pointing to clear business expansion directions for AI service providers.

1. Industry trend assessment: The AI sector remains in a period of rapid iteration, with widespread demand among firms to catch up to leading model capabilities and reduce training costs. However, unauthorized distillation has been explicitly classified as IP infringement by top model vendors, who are actively blocking such activity via technical measures. Industry compliance is a clear long-term trend; the gray-area practice of scraping third-party model outputs to train in-house models is no longer viable.

2. Client pain point mapping: Per disclosed volumes, the three named firms alone—Alibaba, Moonshot, and DeepSeek—generated over 186 million distillation-related interactions, pointing to three core pain points for AI enterprises: high costs for high-performance LLM access, insufficient supply of compliant training data, and gaps in anomalous access risk control. B2B clients also face risks of data being routed and leaked across the AI service chain; content forwarded in this incident included large volumes of sensitive information from multinational corporations.

3. Solution direction: Providers can develop targeted offerings across three categories to match market demand: official LLM license integration, compliant training data supply, and end-to-end AI chain data encryption and traceability services.

The large-scale illicit distillation incident disclosed by Anthropic offers actionable guidance for platform operators to refine risk control rules and mitigate operational risks.

1. Risk control optimization priorities: To bypass access restrictions, implicated firms registered large volumes of fraudulent accounts with listed addresses in Singapore and Japan, generating nearly 3 million anomalous interactions per day across more than 3,500 accounts at peak volume. This demonstrates that bad actors use bulk registration of geofaked accounts to evade controls. Platforms should strengthen account registration verification and anomalous traffic detection rules, referencing Anthropic’s risk detection mechanisms to block bulk abnormal requests in real time.

2. Operational management requirements: When providing AI services or integrating third-party AI capabilities, platforms must fulfill user disclosure obligations. In this incident, Moonshot and DeepSeek routed user queries without notice, not only violating user知情权 (right to know) but also creating sensitive information leakage risks. When integrating third-party capabilities, platforms should provide clear disclosures on service pages and in user agreements, and add sensitive information filtering mechanisms.

3. Risk mitigation guidance: When onboarding AI service providers, platforms must rigorously audit their model IP compliance to avoid associated liability from infringing vendors. Platforms training their own AI models must also avoid unauthorized use of third-party outputs to guard against infringement claims.

Anthropic’s illicit distillation report targeting Chinese AI labs provides a salient new case study and research directions for AI industry and governance research.

1. Emerging industry trend observation: The global LLM industry has entered a technology diffusion phase, where technical barriers between leading firms and challengers are being eroded via model distillation. Leading Chinese AI players including Alibaba, Moonshot, DeepSeek, and Xiaomi have not only used distillation to acquire leading model capabilities for model training, but also applied distillation outputs to core R&D processes including reinforcement learning and model architecture design. Some firms directly route user queries to leading models and pass off results as their own proprietary service; DeepSeek’s rapid market share gains, driven by its strong performance and low cost, were substantially supported by such tactics.

2. Emerging industry issue mapping: Unauthorized distillation creates three new categories of risk. First, LLM intellectual property boundaries remain ambiguous, with no clear standard for determining infringement when model outputs are used to train competing models. Second, data security risks are acute: routed content includes sensitive personal, corporate, and stakeholder information, creating significant privacy compliance exposure. Third, unfair competition risks exist: firms that gain cost and performance advantages via illicit distillation crowd out market space for companies that invest in compliant R&D.

3. Policy implications: Regulators should accelerate clarification of rules governing LLM IP protection, AI user知情权 (right to know) guarantees, and training data compliance to guide standardized industry development. The fact that no implicated firm had issued a public response as of the report’s release also reflects gaps in existing cross-border AI IP dispute resolution mechanisms.

Disclaimer: The "Quick Summary" content is entirely generated by AI. Please exercise discretion when interpreting the information. For issues or corrections, please email run@ebrun.com .

I am a Brand Seller Factory Service Provider Marketplace Seller Researcher Read it again.

美国人工智能公司Anthropic于2026年9月11日发布威胁情报报告,披露其已检测并阻断多起来自中国AI实验室的大规模未授权行动,相关机构使用Claude模型输出内容训练自有模型。这类行为被其定义为“非法蒸馏”,即未经授权借助性能更强的AI模型输出训练其他模型,复刻前者的部分能力。

报告覆盖2025年12月至2026年8月间Anthropic阻断的七类风险活动,除模型蒸馏外,还涉及网络行动、影响力行动、监控、诈骗欺诈、生物滥用、常规武器开发等领域,另有其他多家中国头部AI企业被点名。部分被获取的交互内容包含个人用户、大型跨国企业、国家关联主体的敏感信息,相关操作可能违反隐私法规及涉事实验室自身的服务条款。

其中规模最大的蒸馏活动与阿里巴巴相关。2026年5月至7月间,与阿里关联的运营方使用Claude输出内容训练旗下Qwen系列模型,涉及的Claude交互总量超1.51亿次,活动峰值阶段每日有超3500个欺诈账号发起近300万次交互。阿里同时将Claude用于强化学习、模型架构搭建等更广范围的AI研究。

推出Kimi系列模型的北京AI企业Moonshot,会悄悄将部分用户发送给Kimi的请求转发至Claude,再把Claude生成的回复返回给用户,用户全程以为自己使用的是Kimi模型。2026年5月至7月间,归属于Moonshot的相关交互超2300万次。其中一段10天周期内,Moonshot就向Claude转发了近30万条用户请求,绝大多数流向Claude Opus模型,这些请求通过5380个欺诈账号完成路由,账号显示位置大多集中在新加坡和日本。Moonshot留存了至少部分交互内容,提取Claude的推理文本作为自有模型的训练数据,部分转发的用户请求包含敏感信息,Anthropic暂未确认Moonshot是否就转发行为告知对应用户。

去年因性能突出、使用成本低廉获得市场关注的DeepSeek,采取了与Moonshot类似的操作,在未告知自身用户的前提下将交互内容转发至Claude。2026年7月的14天内,Anthropic观测到归属于DeepSeek的蒸馏攻击超1200万次。

截至相关报道发布,阿里巴巴、Moonshot、DeepSeek、小米及Anthropic均未就相关问询作出即时回应。

本文首发于 亿邦动力 官方网站

文章来源:亿邦动力

广告
微信
朋友圈

FAQ回顾

什么是AI模型训练领域的非法蒸馏行为?

非法蒸馏指未经授权借助性能更强的AI模型输出训练其他模型,复刻前者部分能力的行为。这类行为可能获取包含个人用户、大型跨国企业、国家关联主体的敏感交互内容,涉嫌违反隐私法规及涉事机构自身的服务条款。

大模型厂商未经授权将用户请求转发给第三方模型有什么风险?

这类操作未告知用户真实的服务提供方,涉嫌侵犯用户知情权,还可能留存用户交互的敏感信息用于自有模型训练,存在隐私泄露、违反隐私法规及服务条款的风险,Moonshot、DeepSeek均被指出存在相关行为。

Anthropic披露的阿里关联方针对Claude的蒸馏活动规模有多大?

2026年5月至7月间,阿里关联运营方使用Claude输出内容训练旗下Qwen系列模型,涉及Claude交互总量超1.51亿次,活动峰值阶段每日有超3500个欺诈账号发起近300万次交互,还将Claude用于强化学习、模型架构搭建等AI研究。

这么好看,分享一下?

朋友圈 分享

APP内打开

+1
+1
微信好友 朋友圈 新浪微博 QQ空间
关闭
收藏成功
发送
/140 0