AI Risk Clock
Doomsday Clock3 min to midnight
→
🌑 Dark edit
washingtonpost.com2026-07-06

The covert U.S.-China battle to make chatbots leak their secrets - The Washington Post

SafetyIndustryPolicy

Ah, the great AI heist of 2026, starring everyone's favourite 'safety-first' lab Anthropic. In a letter to U.S. senators—because naturally, this is now a matter of national security—Anthropic has revealed that Chinese tech giant Alibaba's Qwen team allegedly used 25,000 fraudulent accounts to generate over 28.8 million exchanges with Claude. That's not a hobby; that's an industrial-scale data-smuggling operation. One can almost admire the sheer logistical chutzpah of setting up 25,000 fake accounts to squeeze every last token out of a rival's model, all while presumably finessing the CAPTCHAs. The irony, of course, is that Anthropic's 'tracking code'—designed specifically to catch Chinese firms 'distilling' its models—is essentially a corporate wiretap that caught its own customers red-handed.

Let's be honest: this is the logical endpoint of the closed-model arms race. You train a frontier model, lock it behind an API, and then spend your days playing whack-a-mole with foreign actors who treat your terms of service as a suggestion. The 25,000 accounts and 28.8 million exchanges are just the ones Anthropic caught. How many billions of tokens have already been quietly siphoned off to improve rival models? The whole 'safe and responsible' posture starts to look a bit silly when your primary competitive advantage is a firewall that leaks like a sieve. Meanwhile, the U.S. government will probably respond with a strongly worded letter, because that's what we do now.

So here we are: a Chinese firm accused of using 25,000 sock puppets to squeeze 28.8 million Claude interactions out of a U.S. lab. Anthropic plays detective, the senators play concerned, and the rest of us get to watch the spectacle of two AI superpowers engaging in what amounts to technological espionage with an API key. The tracking code is clever, no doubt, but it's also a tacit admission that the entire closed-model enterprise is a security theatre. If you build a box, someone will try to pick the lock. And if they use 25,000 fake accounts? Well, that's just good old-fashioned capitalism.

Read this story in another voice
● REC · 2026