28.8 Million Conversations, 25,000 Fake Accounts: Anthropic's Alibaba Distillation Allegation and the New Model-IP Battlefield
Summary
Anthropic has accused operators affiliated with Alibaba and its Qwen AI lab of conducting a large-scale model distillation campaign against its Mythos Preview frontier model. Between April 22 and June 5, 2026, these operators allegedly engaged in 28.8 million exchanges through approximately 25,000 fraudulent accounts, targeting Mythos Preview's capabilities in software engineering, agentic reasoning, and cybersecurity. Anthropic described this as its largest publicly disclosed distillation effort, part of a pattern that includes earlier campaigns attributed to DeepSeek, Moonshot, and MiniMax. This incident highlights how intellectual property protection for advanced AI models, particularly those with dual-use capabilities like Mythos, is increasingly being treated as a national security concern, with disputes escalating to legislative bodies rather than solely through civil litigation.
Key takeaway
For Directors of AI/ML and compliance professionals managing AI strategy, recognize that model intellectual property disputes are now national security concerns, not just civil litigation. You must scrutinize your AI providers' terms regarding output reuse and anti-distillation, and instrument your own services to detect systematic extraction attempts. Factor geopolitical shifts and potential export controls into your vendor-risk and continuity planning, as these can rapidly alter model availability and usage permissions.
Key insights
Model intellectual property is increasingly vulnerable to adversarial distillation via product usage, elevating IP protection to a national security concern.
Principles
- Adversarial distillation exploits competitor model outputs for training.
- Model IP protection is now a national security matter.
- Terms of service are front-line IP controls.
Method
Adversarial distillation involves repeatedly querying a competitor's advanced model, harvesting its responses, and using them as training data for a rival system, often at scale via fraudulent accounts to evade detection.
In practice
- Review provider terms for output reuse and anti-distillation.
- Implement detection for distributed, high-volume querying patterns.
- Monitor geopolitical shifts affecting model IP and availability.
Topics
- Model Distillation
- Intellectual Property
- National Security
- Export Controls
- Vendor Risk Management
- AI Governance
Best for: CTO, VP of Engineering/Data, Executive, Legal Professional, Director of AI/ML, Consultant
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Global Privacy Laws & Compliance Frameworks | ComplianceHub.Wiki.