The tech giant has placed Anthropic’s Claude Code on a high-risk software list, CNBC reported Monday (July 6), citing sources familiar with the matter.
As the report notes, Alibaba’s decision follows allegations by Anthropic last month that the Chinese company had “brazenly” and “illicitly” tried to extract its AI capabilities. Anthropic also accused Alibaba of conducting “the largest known distillation attack” on it to date.
In distillation, the outputs of a strong model are used to train a less capable version. Companies that use this technique illicitly can acquire capabilities from other labs in much less time and at much less cost than they could developing those capabilities on their own.
Anthropic had in February accused a trio of Chinese tech companies, DeepSeek, MiniMax and Moonshot AI, of carrying out these attacks and called on “industry players, policymakers and the global AI community” to help prevent them.
The startup’s terms of service say that Chinese companies and other “adversarial nations” are forbidden from using its models, the CNBC report added.
Sources told CNBC that Alibaba employees were instructed to uninstall Anthropic models and agent products and use the Chinese company’s Qoder AI assistant.
As covered here last month, distillation attacks are simple: a campaign says large numbers of carefully constructed prompts to its target models and captures its responses, which become training data.
“The competing model learns to reason and respond in ways that replicate the original, without paying for the research behind it,” PYMNTS wrote.
“It is less like hacking a system and more like sitting next to the best student in class and copying every answer they write, at industrial scale.”
Detection is difficult, as a distillation query is identical to a legitimate one. A developer who needs Claude to help debug a function and a campaign extracting Claude’s coding behavior issue the same type of request.
The only indication is pattern: huge volumes, repetitive structures and prompts focused on the same narrow capabilities, coming from hundreds of coordinated accounts in sequence.
“As organizations increasingly integrate LLMs into their core operations, the proprietary logic and specialized training of these models have emerged as high-value targets,” Google’s Threat Intelligence Group warned in a February blog post.