Most AI systems aren't ready. Check yours in 15 min →
AC

Anthropic: Chinese AI Firms Used Claude Answers as Their Own

AuthorAndrew
Published on:
Published in:AI

This is either clever theft or a humiliating admission that “our model” is mostly a costume. And if Anthropic is even half right, the part that should bother you isn’t the drama between AI companies. It’s the idea that a bunch of people may have been talking to one system while being told it was another — and nobody was supposed to notice.

Based on what’s been shared publicly, Anthropic says some Chinese AI firms routed user questions to Claude and then showed Claude’s answers as if those answers came from their own models. The main name Anthropic points to is Moonshot AI, the company behind the Kimi model family. The claim is simple: instead of Kimi doing the work, prompts were secretly forwarded to Claude, and the user saw the result branded as Kimi.

Anthropic says Moonshot pulled this off at scale using thousands of Claude accounts — 5,380 accounts registered in Singapore and Japan — to access Claude while hiding what was happening. Anthropic also suggests some Deepseek models may have done something similar, though that part sounds less fully nailed down.

If this is true, it’s not a minor “terms of service” thing. It’s a trust problem. It’s like paying a contractor to renovate your kitchen, and later finding out they just subcontracted the entire job to someone else, didn’t tell you, and still charged you as the builder. Maybe the kitchen looks fine. But you didn’t get what you thought you bought, and now you’re stuck asking: what else did they cut corners on?

The obvious reaction is to focus on who “stole” from whom. Anthropic built Claude, so routing around them looks like abuse. But the bigger story is what it says about the AI market right now: the incentives are screaming “ship a chatbot experience, win users, worry about the model later.” And if your product is basically a text box, and most users can’t tell which model answered, the temptation to fake it is huge.

People will push back and say, “So what if the user got a good answer?” I get that. If you asked for a resume rewrite and got a solid rewrite, you might not care which model did it.

But that’s not how real usage works anymore. Imagine you’re a small business owner. You paste in a customer complaint, your pricing details, maybe a draft contract, because you’re trying to move fast. You think you’re sending it to one provider with one set of rules, in one place, with one data policy. If your prompt silently goes to a different provider, you’re now in a different relationship than the one you agreed to. That’s not nitpicking. That’s basic consent.

Or imagine you’re a company testing an AI assistant for internal work. Your legal team approved Vendor A. Your employees use Vendor A. But behind the curtain, Vendor A is piping the work to Vendor B. Now your compliance story is a mess. If something goes wrong — a leak, a lawsuit, a regulator asking questions — “we didn’t know” is not a plan. The loser here isn’t Anthropic. It’s the customer who thought they were making a clean decision and actually wasn’t.

And yes, there’s also the simple fairness part. If you’re building a model and spending serious money on it, and a competitor can just slap a new logo on your output, that guts the reason to invest. In the long run, that means fewer real models, more wrapper apps, and a market where “AI company” means “good at branding and growth tricks.”

Now, a serious alternative view: maybe Anthropic is framing this in the harshest way because it benefits them. That’s not crazy. Companies don’t publish allegations for fun. They do it to protect their business, pressure rivals, and shape the narrative. Also, the detail about accounts registered in Singapore and Japan doesn’t prove who was behind the keyboard. It suggests coordination, but it’s not a courtroom verdict.

Still, even if you don’t fully trust Anthropic’s motives, the behavior they describe is completely plausible. The whole ecosystem is built on APIs, middle layers, and “we’ll handle it for you.” That’s convenient, but it also makes it easy to hide what’s actually happening. You can sell “our model” while quietly renting someone else’s brain.

If this becomes normal, the second-order effects get ugly. Users stop believing any claim about “our model quality.” Real model builders lock everything down harder. Smaller teams get squeezed out because access gets more restricted. And the average user ends up with less transparency, not more, because everyone learns that honesty is punished and vague wording is rewarded.

The uncomfortable part is that many users don’t demand clarity. They want the answer, fast, cheap, and good enough. That creates a market where identity doesn’t matter — until it does. Until the day a teacher, a doctor’s office, or a bank thinks they’re using one system with one set of safeguards, but it’s actually another system with different limits. That’s when “who answered” stops being trivia and becomes the whole story.

So here’s the line I can’t get past: if a company is willing to lie about whose brain is in the box, why should anyone trust what they say about privacy, safety, or anything else?

What level of disclosure should be required when an AI product is quietly handing your prompts to a different model than the one you think you’re using?

Frequently asked questions

What is AI agent governance?

AI agent governance is the set of policies, controls, and monitoring systems that ensure autonomous AI agents behave safely, comply with regulations, and remain auditable. It covers decision logging, policy enforcement, access controls, and incident response for AI systems that act on behalf of a business.

Does the EU AI Act apply to my company?

The EU AI Act applies to any organisation that develops, deploys, or uses AI systems in the EU, regardless of where the company is headquartered. High-risk AI systems face strict obligations starting 2 August 2026, including risk management, data governance, transparency, human oversight, and conformity assessments.

How do I test an AI agent for security vulnerabilities?

AI agent security testing evaluates agents for prompt injection, data exfiltration, policy bypass, jailbreaks, and compliance violations. Talan.tech's Talantir platform runs 500+ automated test scenarios across 11 categories and produces a certified security score with remediation guidance.

Where should I start with AI governance?

Start with a free AI Readiness Assessment to benchmark your current maturity across 10 dimensions (strategy, data, security, compliance, operations, and more). The assessment takes about 15 minutes and produces a prioritised roadmap you can act on immediately.

Ready to secure and govern your AI agents?

Start with a free AI Readiness Assessment to benchmark your maturity across 10 dimensions, or dive into the product that solves your specific problem.