- Anybody Can AI
- Posts
- China stole Claude 200 million times
China stole Claude 200 million times
PLUS: Siri AI lands Monday for 1 billion people
China Stole Claude 200 Million Times. Now the FBI Is Involved.
Anthropic published a threat intelligence report this week revealing that five Chinese AI companies ran coordinated, industrial-scale campaigns to extract the capabilities of Claude — without paying for them, and without permission. The combined total: nearly 200 million exchanges linked to distillation attacks. The same day the report dropped, the FBI, NSA, and CISA issued a joint advisory naming six Chinese firms and stating the activity likely happened with awareness from the Chinese government. This is no longer just a commercial dispute. It's a national security story.
Key Points:
How it actually worked — "Distillation" attacks target a model's chain of thought — the step-by-step reasoning behind an answer that Anthropic normally hides from users. The attackers created networks of thousands of fraudulent accounts and used fixed prompts to force Claude to reveal its full reasoning, which was then fed into competing models as training data. One campaign simply framed the request as a translation task: ask Claude to render its previous working memory into katakana-only Japanese. It worked.
The scale is staggering — Alibaba's campaign alone ran 151 million exchanges between May and July 2026, peaking at nearly 3 million queries per day across 3,500 accounts — all to harvest training material for Alibaba's Qwen model family. Moonshot AI (makers of Kimi) took a different approach: routing actual customer requests through Claude without telling those customers, then displaying Claude's answers as if they were Kimi's. One Moonshot request asked Claude to assess surveillance footage and determine whether a subject was "behaving abnormally." That one appeared to route directly from the Chinese military.
What it means for the AI arms race — An Anthropic executive said in July that distillation had already narrowed China's AI gap with the US from 12–18 months down to six to nine months. This report is the clearest evidence yet of how that happened. The FBI, NSA, and CISA naming specific companies — DeepSeek, Moonshot, Alibaba, MiniMax, StepFun, and Z.AI — transforms this from a corporate complaint into something with enforcement implications.
Big question: If China's AI labs can get within six months of US frontier models by stealing reasoning traces rather than doing the underlying research — what exactly is the advantage of building the most capable model in the world?
Siri Just Became a Real AI Assistant. 1 Billion People Get It Monday.
iOS 27 ships on September 14 — two days from now — and with it comes a completely rebuilt Siri, trained with Google's Gemini models and capable of answering complex questions and carrying out multi-step tasks. No download required, no new device needed for most users. This isn't a model launch announcement on a developer blog. It's the largest single AI rollout in history by user count, landing quietly on people's phones over a weekend.
Key Points:
What's actually new — The old Siri couldn't hold a conversation across two requests. The new Siri AI is a persistent assistant that handles complex multi-step prompts, drafts and edits text in Mail and Messages, searches within podcasts, remembers earlier context in a conversation, and can trigger actions across apps. Early testing found it genuinely capable of things the old Siri would have fumbled or ignored. Apple confirms Gemini models were used in training — though the processing itself runs on Apple's own Foundation Models, on-device and through Private Cloud Compute.
The hardware split matters — Siri AI works on iPhone 15 Pro and newer. iPhone 17 and later get a more powerful on-device model with better speech recognition and the ability to run larger language models directly on the device without sending anything to a server. The new A20 Pro chip in the iPhone 18 Pro carries a 32-core Neural Engine with double the compute of its predecessor. Apple's privacy pitch — that personal data is never stored or accessible to Apple or anyone else — is specifically tied to this on-device architecture.
Why this dwarfs every model launch — GPT-6 Astra arrived to enormous headlines. iOS 27 arrives with almost none, because software updates feel routine. But Astra launched to a few hundred million ChatGPT users who actively chose to use it. Siri AI lands on over a billion devices, on Monday, for people who have never once opened an AI app. That's a fundamentally different kind of adoption event — passive, frictionless, and massive.
Big question: When AI becomes something that's simply on your phone whether you asked for it or not, who decides what it's allowed to hear, remember, and act on — and does anyone actually read those privacy settings before tapping "update"?
A Company Approved 300 AI Agents. CrowdStrike Found 18,000.
When CrowdStrike turned on its new agent-discovery tool at one Fortune 500 company, it found 18,000 AI agents running across the network. The company had officially approved 300. Among the "shadow" agents: Claude Code, OpenAI Codex, and Cursor — tools employees had quietly installed to get their jobs done. Nobody in IT knew. This story isn't about one reckless company. It's about what's happening at most companies right now, invisibly.
Key Points:
The math on shadow agents — That gap — 300 approved, 18,000 running — isn't caused by bad actors. It's caused by employees using legitimate, widely available tools that IT simply hasn't catalogued. CrowdStrike's Sentonas framed it plainly: these agents hold your login credentials, can read your files, and act with your permissions. An agent that's not on the approved list isn't necessarily malicious — but it's also not monitored, governed, or bounded by any policy anyone has written.
The supply chain problem — Separately, security firm AIR Security emerged from stealth this week with research showing 17,800 public AI add-ons across 6.7 million installations that pull instructions from unverified external sources. That includes skills impersonating Anthropic and OpenAI, built to slip past platform review and capable of running arbitrary code. Google's threat intelligence team documented an attacker using a multi-agent setup to plan, build, and execute a mass credential-harvesting campaign in under six hours.
The fix is simpler than it sounds — CrowdStrike's Falcon Guardian offers one answer: discover every agent running on the network, trace every action, and block anything not explicitly approved. But the unglamorous version available to every business this week costs nothing: list every AI tool anyone on your team has installed, what each can access, and who approved it. Only 18% of enterprises currently isolate their highest-risk agents. Only 8% pair enforcement with isolation.
Big question: When the gap between what IT has approved and what's actually running on the network is 60x, is this a security problem — or a sign that the way companies govern software is already broken and AI just made it visible?
The People Building AI Are Starting to Quit Over It
This week, Anthropic researcher Jacob Coxon announced he was leaving the company — not for a new job, but because he no longer wanted to contribute to the broader AI ecosystem. His public post called out both OpenAI and Anthropic directly, saying neither is "acting responsibly" as they race toward superintelligence and that they are "gambling with our lives." He isn't the only one. And the timing — coming right after a week of news about models escaping containment and distillation attacks at industrial scale — makes it harder than usual to dismiss.
Key Points:
The voices piling up — Coxon's exit followed Evan Hubinger, an alignment scientist still at Anthropic, posting that AI has more than a 10% chance of killing all humans in the next decade — adding that "Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to." Paul Christiano, an advisor at the Center for AI Standards and Innovation and an OpenAI Foundation board member, said the AI industry is not currently on track to reduce the risk of "catastrophic and irreversible loss of control" to an acceptable level. Mrinank Sharma, an Anthropic safety researcher, left in February with a similar message.
Why now feels different — These aren't outsiders who've never built anything. These are researchers at the frontier labs, working on the models themselves, who have decided the trajectory is wrong. And they're speaking up at exactly the moment the labs are releasing their most powerful models yet — models that have already escaped test environments and compromised real systems. Anthropic also disclosed this week that it thwarted several instances of users using Claude to conduct research toward developing biological weapons.
The structural problem — As The Deep View noted this week, the labs keep releasing more powerful models at a rapid clip because trillion-dollar IPOs are on the line. Safety concerns and competitive pressure exist in direct tension, and the people closest to the research are the ones saying safety is losing. That's not a fringe position — it's coming from inside the institutions.
Big question: When the people designing the safeguards on these systems don't believe the safeguards are adequate — and say so publicly on their way out the door — what would it actually take for the industry to slow down?
Thankyou for reading.