Anthropic Targets Illicit AI Distillation as Foreign Entities Access Claude via Dark Web
September 4, 2026
Based on reporting from CNBC → — simplified & explained by VAIIYA.
Anthropic has raised public alarms over what it describes as an illicit, dark-web-fueled ecosystem designed to extract capabilities from its flagship artificial intelligence models, particularly Claude.
According to Jacob Klein, Anthropic’s head of threat intelligence, foreign competitors and bad actors are relying on fraudulent accounts, stolen credit cards, and dark web marketplaces to bypass geographic restrictions and security controls. The primary objective is model "distillation"—a practice where developers query a superior AI system to collect training data for cheaper, competing offerings.
The Mechanics of Illicit Distillation
While model distillation can be conducted legally through authorized licensing, Anthropic asserts that current practices by several overseas developers amount to systematic intellectual property theft.
By creating tens or hundreds of thousands of fake accounts, illicit operators repeatedly query Claude at scale. The extracted outputs are then used to train smaller "student" models at a tiny fraction of the cost required to develop frontier systems from scratch.
This automated extraction presents a major detection challenge. Travis Lanham, chief technology officer at cybersecurity firm Armadin, noted that because major AI labs handle billions of user queries daily, millions of unauthorized requests can easily blend into routine platform traffic.
Targeting Chinese Startups and Sanctioned Regions
Anthropic has singled out several prominent Chinese developers, alleging they distilled capabilities directly from Claude. Among them is Moonshot AI, whose Kimi K3 model gained traction in Silicon Valley due to its lower cost and frontier-level performance. Anthropic claims Kimi K3 was illegally trained on the newest version of Claude.
Other Chinese entities named in Anthropic’s disclosures include DeepSeek, MiniMax, and tech giant Alibaba, creator of the Qwen model suite.
Beyond commercial entities in China, cybersecurity experts report that users in sanctioned nations—including Russia, Iran, and North Korea—are turning to dark web credentials to circumvent access restrictions placed on Claude, OpenAI's ChatGPT, and Google's Gemini.
National Security and Corporate Stakes
The practice raises significant national security concerns, according to Anthropic. When third parties copy models through illicit distillation, they strip away built-in safety guardrails, raising risks related to cyber espionage, surveillance, and biological weapons research.
The U.S. government has also signaled growing concern. An April memo from the Trump administration described unauthorized distillation that undermines American research as unacceptable, noting that officials would explore measures to hold foreign actors accountable.
These disclosures come at a crucial moment for Anthropic. The five-year-old AI startup has seen its private valuation climb toward $1 trillion and is reportedly preparing for an initial public offering as early as October.