Anthropic and Alibaba: The dispute places security and intellectual property at the center of the debate

The artificial intelligence industry is going through one of the fastest-growing and most competitive stages in its history. The emergence of increasingly advanced language models has triggered a technological race among American, European, and Asian companies to develop systems capable of understanding, generating, and analyzing information with an unprecedented level of sophistication. However, this progress has also brought new conflicts related to the protection of intellectual property, model security, and the way different organizations obtain technical knowledge to improve their own systems.

One of the most relevant cases emerged when Anthropic, a U.S. artificial intelligence company, stated that it had detected an operation through which capabilities of its Claude model would have been illicitly extracted to benefit the development of systems belonging to Alibaba’s Qwen laboratory. The company claims that the observed activity did not correspond to normal use of an application programming interface (API), but rather to an organized process that sought to collect large amounts of responses generated by Claude with the aim of reproducing part of its behavior in another language model.

The complaint reflects a growing concern within the sector: although artificial intelligence models are extremely complex and expensive to train, there are techniques that allow their capabilities to be approximated using only their public responses. This phenomenon has led developing companies to strengthen their security mechanisms while the debate over the legal and ethical limits of these practices continues to evolve.

An increasingly intense technological competition

During recent years, generative artificial intelligence has ceased to be a field reserved for research laboratories and has become one of the most competitive markets in the world. Companies such as OpenAI, Google, Anthropic, Meta, Microsoft, Alibaba, Baidu, and other organizations invest billions of dollars in computing infrastructure, data centers, and the acquisition of graphics processing units capable of training models with hundreds of billions of parameters. In this context, both Anthropic and Alibaba have established themselves as two of the most relevant players in the development of next-generation artificial intelligence models.

ITD Consulting: Anthropic y Alibaba impulsan IA, seguridad y propiedad intelectual

During recent years, generative artificial intelligence has ceased to be a field reserved for research laboratories and has become one of the most competitive markets in the world. Companies such as OpenAI, Google, Anthropic, Meta, Microsoft, Alibaba, Baidu, and other organizations invest billions of dollars in computing infrastructure, data centers, and the acquisition of graphics processing units capable of training models with hundreds of billions of parameters. In this context, both Anthropic and Alibaba have established themselves as two of the most relevant players in the development of next-generation artificial intelligence models.

Training a next-generation model represents an enormous technical and economic challenge. The process requires huge volumes of data, thousands of specialized accelerators running for weeks or months, and highly qualified research teams. Due to these high costs, companies such as Anthropic and Alibaba carefully protect both their models and the techniques used to develop them, as they represent some of their most valuable technological assets.

Precisely for this reason, the possibility that a competitor could obtain part of those capabilities through indirect techniques is a significant concern for the entire industry. Both Anthropic and Alibaba, like other major AI developers, consider it essential to protect their models against possible attempts to extract capabilities, since competition in this sector increasingly depends on innovation and system security.

What is model distillation?

At the center of the conflict between Anthropic and Alibaba is a concept known as “model distillation.” This is a widely used technique in artificial intelligence research that, under normal conditions, has completely legitimate applications for both Anthropic, Alibaba, and other language model developers.

The idea consists of using a very advanced model—known as a “teacher model”—to train another smaller system called a “student model.” Instead of learning only from original data, the student model also learns by observing the responses produced by the teacher model. This methodology is used by numerous companies, although in the case of Anthropic and Alibaba the debate revolves around whether this procedure was used in compliance with Anthropic’s terms of use.

This process makes it possible to retain part of the knowledge acquired by the larger system while significantly reducing the computational requirements needed to run the resulting model. Thanks to this, it is possible to develop faster, cheaper, and more efficient assistants, which is why companies such as Anthropic and Alibaba continuously research new techniques to optimize their artificial intelligence models.

Many companies use distillation to optimize models they own or to work with open-source models that explicitly allow this type of training. However, when it comes to commercial models developed by companies such as Anthropic or Alibaba, usage conditions often establish specific restrictions on such practices.

The problem arises when the teacher model belongs to another organization and its use contradicts the terms of service established by the developer. In that scenario, legal questions emerge as to whether the process constitutes simply intensive use of an API or represents a form of improper appropriation of the intellectual work carried out by another company—precisely the type of issue that has placed Anthropic and Alibaba at the center of the AI debate.

The accusations made by Anthropic against Alibaba

According to Anthropic, its monitoring systems detected a pattern of activity very different from the usual behavior of business clients or individual developers. These observations led Anthropic to suspect a possible organized campaign related to the use of its models.

The company stated that thousands of independent accounts may have been used to send automated queries intended to obtain an extraordinarily high volume of responses from the Claude model. According to Anthropic, these queries were related to an operation aimed at extracting model capabilities, allegations that subsequently placed Alibaba at the center of the controversy.

From Anthropic’s perspective, the massive use of multiple accounts would have been intended to avoid the limits established to prevent precisely this type of activity. By distributing queries across numerous apparently independent users, the system could generate millions of responses without easily triggering the traditional detection mechanisms implemented by Anthropic.

Anthropic maintains that the purpose of this systematic collection was to build a sufficiently large dataset to train another model using the responses produced by Claude. Although Anthropic did not publicly state that the full model had been copied, it did express concern about the possible extraction of capabilities through distillation techniques.

Although Anthropic made its suspicions public, it did not openly present all the technical evidence used to reach that conclusion. This aspect is understandable from the standpoint of cybersecurity, since revealing detection methods could make it easier for future similar operations to go unnoticed, both against Anthropic and other AI developers, including Alibaba.

The company indicated that it continuously investigates activities aimed at extracting capabilities from its models and that it dedicates significant resources to improving its protection systems against such threats. For Anthropic, strengthening the security of Claude has become a priority due to the growing interest its models generate within the industry.

Why are model outputs so valuable for Anthropic and Alibaba?

Unlike traditional computer programs, a large language model stores its knowledge distributed across billions of mathematical parameters. Directly copying a model developed by Anthropic, Alibaba, or another company is extremely difficult without internal access.

However, the responses generated during millions of conversations contain highly valuable information about the system’s behavior. Precisely for this reason, both Anthropic and Alibaba consider the outputs produced by their models to be a technological asset of enormous value.

Each explanation, summary, code snippet, or line of reasoning provides clues about how the model interprets language, organizes concepts, answers ambiguous questions, or solves complex problems. In advanced models such as Claude from Anthropic or Qwen from Alibaba, these responses reflect part of the knowledge acquired during training.

ITD Consulting: Anthropic y Alibaba y la disputa por IA, innovación y seguridad!

If a researcher obtains enough carefully designed examples, they can use them as training data to build a new system that imitates part of the observed behavior. This is precisely one of the main reasons why Anthropic considers it necessary to limit certain forms of use of its models and why companies like Alibaba also implement protection mechanisms on their own platforms.

Although the new model will never be an exact copy of the original, it can still approximate certain capabilities through this indirect learning process. For this reason, both Anthropic and Alibaba devote significant resources to researching how to prevent the massive extraction of knowledge through their services.

This possibility has led many developers to introduce limitations on the number of allowed queries, advanced systems for detecting automation, and mechanisms designed to identify patterns consistent with attempts at large-scale knowledge extraction. Companies such as Anthropic and Alibaba consider these measures to be increasingly important as competition in the development of artificial intelligence models grows.

Alibaba’s response and the difficulty of proving illicit extraction

After the allegations became known, Alibaba did not acknowledge having carried out a capability extraction campaign against Claude, the model developed by Anthropic. The company avoided confirming Anthropic’s claims, while the accusations were made public through a letter sent by Anthropic to members of the United States Senate ahead of a hearing on artificial intelligence. In that communication, Anthropic stated that operators linked to Alibaba’s Qwen laboratory had carried out around 28.8 million interactions with Claude using approximately 25,000 fraudulent accounts between late April and early June 2026.

Although the figures provided by Anthropic drew industry attention and placed Alibaba at the center of the debate, technically proving such an operation is not straightforward. A high number of queries to a model developed by Anthropic, Alibaba, or any other company does not, by itself, constitute proof of improper copying. Companies must analyze numerous indicators, such as repetitive question patterns, query automation, the use of proxy networks to conceal traffic origin, mass account creation, and temporal coincidences with the development of new models.

In other words, the challenge lies in distinguishing between intensive but legitimate use of a platform and an operation specifically designed to reconstruct part of the original model’s behavior. This type of analysis is especially relevant in cases such as the one involving Anthropic and Alibaba, where the interpretation of technical evidence can be decisive.

The Qwen laboratory and Alibaba’s growth in Chinese artificial intelligence

Qwen is the family of artificial intelligence models developed by Alibaba Cloud. Since its launch, Alibaba’s models have evolved rapidly and have become some of the most competitive systems developed in China, placing Alibaba among the leading companies in the sector.

In recent years, companies such as Alibaba, Baidu, Tencent, ByteDance, Moonshot AI, MiniMax, and DeepSeek have significantly increased their investments in artificial intelligence. In many cases, these developments have been driven both by commercial competition and by the strategic interest of the Chinese government in reducing dependence on foreign technology providers. Within this context, Alibaba has strengthened its commitment to developing its own models capable of competing with solutions created by companies such as Anthropic.

The progress of Chinese models has surprised many analysts. While just a few years ago there was a significant gap compared to leading U.S. laboratories, several systems developed by Alibaba and other Chinese companies now offer comparable performance in multiple tasks, especially in programming, mathematical reasoning, and language understanding. This evolution has intensified direct competition between companies such as Anthropic and Alibaba in the global artificial intelligence market.

The growth of Alibaba and other Chinese developers has also increased international competition and heightened interest in protecting technological assets considered strategic. Both Anthropic and Alibaba are currently among the most relevant actors in the race to develop increasingly advanced artificial intelligence models, which explains the significant impact of the allegations made by Anthropic against Alibaba.

Security, intellectual property, and usage contracts

The conflict between Anthropic and Alibaba also highlights an ongoing legal debate in the field of artificial intelligence. In most commercial AI services offered by companies such as Anthropic, Alibaba, and other major developers in the sector, users accept terms of service that explicitly restrict activities such as reverse engineering, large-scale automation, or training competing models using outputs obtained through the API. Both Anthropic and Alibaba include such restrictions on their platforms to protect their models and prevent unauthorized use.

From a contractual standpoint, failure to comply with the conditions established by Anthropic, Alibaba, or other companies may lead to legal action, even when intellectual property law does not yet provide a specific response for such situations. In this context, both Anthropic and Alibaba operate within a legal framework that is still adapting to the speed of technological development.

However, artificial intelligence is advancing faster than regulation. Many countries still lack clear rules on the extent to which the behavior of models developed by companies such as Anthropic or Alibaba can be considered a protected asset against attempts at indirect replication or unauthorized distillation.

This uncertainty explains why many companies, including Anthropic and Alibaba, are investing not only in specialized legal teams but also in technical systems capable of preventing automated data extraction and the misuse of their models.

A conflict framed within the U.S.–China technological rivalry

Beyond the business dispute between Anthropic and Alibaba, the allegations must be understood within the current geopolitical context. The United States considers artificial intelligence a strategic technology comparable to nuclear energy, semiconductors, or quantum computing. As a result, in recent years it has tightened export controls on advanced chips and certain technologies related to large-scale model training, indirectly affecting the ecosystem in which companies such as Anthropic operate.

China, for its part, has promoted major national programs to accelerate the development of domestic capabilities, in which companies like Alibaba play a central role, aiming to reduce dependence on Western providers and strengthen its position in the global AI competition. This scenario has turned artificial intelligence into one of the main areas of international technological competition, where actors such as Anthropic and Alibaba represent two important poles of global model development.

In its communication to U.S. lawmakers, Anthropic advocated for greater cooperation between the public sector and private companies to identify model extraction campaigns and share threat intelligence. According to Anthropic, such practices could affect both economic competitiveness and national security if they enable the accelerated development of advanced systems by foreign actors, potentially including competitors such as Alibaba.

ITD Consulting: Anthropic y Alibaba y el debate de propiedad intelectual en IA y

The confrontation between Anthropic and Alibaba reflects a new stage in the evolution of artificial intelligence. While in the early years the main focus for both Anthropic and Alibaba was on building increasingly powerful models, attention has now also shifted to how to protect those capabilities from extraction, copying, or indirect replication that could undermine the competitive advantage of companies like Anthropic and Alibaba.

Beyond the specific outcome of the allegations between Anthropic and Alibaba, the case shows that the value of a language model no longer lies solely in its source code or the infrastructure used to train it. For both Anthropic and Alibaba, the behavior of their systems, their outputs, and the accumulated experience from their development have become fundamental strategic assets for maintaining their position in an increasingly competitive market.

The industry, led by actors such as Anthropic and Alibaba, will need to find a balance between encouraging open research, enabling innovation, and protecting the investment made by those developing frontier models. That balance will be decisive in shaping how the artificial intelligence ecosystem evolves over the next decade and what legal and technical mechanisms will be required to ensure competition based on innovation rather than the improper appropriation of capabilities developed by others, especially in an environment where companies like Anthropic and Alibaba continue to accelerate their progress.

In this context of rapid technological transformation, it is essential for organizations to have specialized advisory support to adapt to the new challenges of artificial intelligence, cybersecurity, and digital transformation. If your company is looking for guidance to implement AI solutions, strengthen its technological infrastructure, or protect its digital assets, you can rely on ITD Consulting. For personalized information or to explore services in artificial intelligence, digital transformation, and cybersecurity, you can write directly to [email protected].

Do you want to SAVE?
Switch to us!

✔️ Corporate Email M365. 50GB per user
✔️ 1 TB of cloud space per user

en_USEN

¿Quieres AHORRAR? ¡Cámbiate con nosotros!

🤩 🗣 ¡Cámbiate con nosotros y ahorra!

Si aún no trabajas con Microsoft 365, comienza o MIGRA desde Gsuite, Cpanel, otros, tendrás 50% descuento: 

✔️Correo Corporativo M365. 50gb por usuario.

✔️ 1 TB of cloud space per user 

✔️Respaldo documentos.

Ventajas: – Trabajar en colaboración Teams sobre el mismo archivo de Office Online en tiempo real y muchas otras ventajas.

¡Compártenos tus datos de contacto y nos comunicaremos contigo!