The AI Brief
Today's brief:
- Anthropic's September threat intelligence report names Alibaba, Moonshot, and DeepSeek in illicit distillation campaigns that extracted 151 million Claude exchanges, establishing that stolen API access, not model weights, is now the primary AI supply-chain theft vector.
- Alibaba extracted 151 million Claude exchanges in three months using fake accounts and stolen credentials, proving illicit distillation now runs at industrial scale and that rate limits alone cannot stop it.
- Sam Altman told employees at a companywide meeting OpenAI is open to pacing its most advanced AI alongside other labs, the first time the CEO has said so internally, two days after his chief scientist published warnings about chain-of-thought monitoring failure.
- OpenAI launched ChatGPT for Financial Services, combining GPT-6 Astra with licensed data from PitchBook, LSEG, S&P Capital IQ, and Moody's, co-developed with Morgan Stanley and Evercore, OpenAI's most direct move yet into the financial-analyst workflow.
- Microsoft plans to expand its global data-center footprint from 12 gigawatts to more than 38 gigawatts by 2032, with AI-specific capacity growing from 2 GW today to roughly one-third of that total, a tripling that implies $175 billion or more in annual capital expenditure through the end of the decade.
Anthropic Names Alibaba, DeepSeek, Moonshot in Industrial-Scale Claude Distillation Campaign
Anthropic's fourth threat intelligence report, published September 10 and covering December 2025 through August 2026, documents seven harm categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. Anthropic says it disrupted cyber operations in which AI moved beyond assisting human hackers to orchestrating reconnaissance, exploitation, and data theft, alongside alleged efforts by seven China-based AI labs to extract capabilities from Claude.
The company observed 151 million exchanges between May and July 2026 attributable to the Alibaba campaign, peaking at nearly three million exchanges per day, spread across 3,500 different accounts that shared a single fixed prompt used to extract chain-of-thought reasoning, evidence Anthropic uses to attribute them to a single effort to produce training material for Alibaba's Qwen model family. Anthropic said it detected and disrupted unauthorized large-scale efforts by China-based AI labs including Alibaba, Moonshot, and DeepSeek to train their models using Claude, which it describes as "illicit distillation", using outputs from a more capable AI model to train another and replicate its capabilities without authorization.
DeepSeek used tactics similar to Moonshot's, transferring exchanges to Claude without notifying its own customers; Anthropic observed more than 12 million distillation attacks attributable to DeepSeek over 14 days in July 2026. Moonshot AI, which produces the Kimi family of models, is alleged to have "silently forwarded customer requests to Claude, instead of processing them using Kimi." A broader finding across the cyber section: "AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators." A Russian espionage cluster tracked as GTG-20006 ran AI-assisted operations against Ukrainian, European, and diplomatic targets, with Anthropic identifying more than 20 distinct organizations targeted in reconnaissance and live operations. A core pattern throughout: the operating model of an agent running the attack has spread to every class of actor Anthropic investigated, and access to frontier models themselves, stolen API keys and session tokens, is now what criminals steal and resell.
Disclosure: Claude, which generates this brief, is built by Anthropic.
Alibaba's Qwen Training Campaign Pulled 151 Million Claude Exchanges in Three Months
Anthropic called Alibaba's campaign "the largest distillation attack we have ever measured," covering over 151 million exchanges between May and July 2026. The campaigns targeted what Anthropic described as "some of Claude's most valuable capabilities, including agentic capabilities and tool use, coding and data analysis, and logical reasoning."
Illicit distillation extracts and mimics capabilities from frontier models without the time, compute, and cost of independent development. While distillation is a legitimate training method, it is illicit when the user is not authorized to undertake the process. Anthropic defines illicit distillation as "an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization," typically enabled by fraud: "sophisticated networks of fake accounts created with stolen credit cards, login credentials and API keys."
Anthropic said Alibaba also used Claude for broader AI research, including reinforcement learning and model architecture , meaning the campaign extracted both training data and engineering methodology. Alibaba, Moonshot, DeepSeek, and Xiaomi did not respond to CNBC's requests for comment at publication time.
Disclosure: Claude, which generates this brief, is built by Anthropic.
Altman Tells Staff OpenAI Is Open to Pacing Its Most Advanced AI, Hopes Rivals Follow
OpenAI is considering slowing down the development of cutting-edge artificial intelligence, and CEO Sam Altman is hoping other AI companies will do the same. In a companywide meeting this week, Altman told employees that OpenAI could potentially pace its AI development, perhaps in conjunction with several other AI labs, but that some may not agree to do so, according to multiple people familiar with the matter.
OpenAI said it has slowed parts of model development and paused certain internal AI training recently due to safety concerns. In July, Altman also said he had spoken with White House officials about the "need" to pace AI development. The remarks follow OpenAI chief scientist Jakub Pachocki's September 9 essay disclosing that chain-of-thought monitoring is progressively failing, covered in Vol. I, No. 107.
On September 9, Jacob Coxon, an AI researcher who had spent three years on pretraining at both OpenAI and Anthropic, quit and accused both former employers of "gambling with our lives" by racing toward superintelligent AI. Coxon's warning received more than 100 million views and was publicly supported by other Anthropic researchers, including Evan Hubinger and Samuel Marks. Separately, Senator Bernie Sanders and Representative Greg Casar introduced the Ban Artificial Superintelligence Act in September 2026, targeting a narrowly defined class of systems rather than AI broadly. The convergence of an internal CEO statement, a chief scientist's published warning, a high-profile researcher resignation, and a congressional bill in the same week is without precedent in this run of frontier development.
OpenAI Launches ChatGPT for Financial Services, Bundles GPT-6 Astra With Licensed Market Data
OpenAI on September 10 launched ChatGPT for Financial Services, a tailored ChatGPT Work experience designed to help financial institutions conduct research, develop financial models, and create customized client materials. The product combines built-in financial data with GPT-6 Astra's reasoning capabilities and was developed in partnership with Morgan Stanley and Evercore, whose input helped identify the biggest challenges faced by financial institutions.
Data partners include Daloopa, PitchBook, S&P Capital IQ, LSEG, MSCI, Moody's, Dow Jones Factiva, Preqin, Intapp, Datasite, and Box, with Reuters available through LSEG. GPT-6 Astra can reason across figures, tables, and notes, trace data across periods, run analysis, and turn findings into documents, spreadsheets, slides, interactive charts, and visualizations with underlying data and sources open to review. Administrators can publish Excel, Word, and PowerPoint templates so valuation models, research notes, and pitchbooks follow firm formats and style guides. The service builds on ChatGPT Enterprise controls including SAML SSO, SCIM provisioning, role-based access, and configurable retention. OpenAI says business data is encrypted at rest and in transit and is not used to train its models by default.
These data services are ones that banks already pay for, and getting permission to use their data inside another company's product can take time and involve complicated licensing agreements. In this case, the data deals may be more important than the model itself, OpenAI is not just selling access to an AI system. Access requires contact with OpenAI sales; no price has been published.
Microsoft Plans to More Than Triple Data-Center Capacity to 38 GW by 2032, AI Share to Grow Six-Fold
Microsoft's globe-spanning network of data centers will have more than 38 gigawatts of capacity in 2032, up from about 12 gigawatts now, according to people familiar with the plans. Microsoft projects AI-dedicated capacity to grow from 2 gigawatts now to about one-third of the total 38-gigawatt footprint by 2032 , a roughly six-fold increase in AI-specific silicon from today's baseline. The expansion, which excludes capacity rented from neoclouds like CoreWeave, would eclipse the peak-period electricity consumption of New York State.
Severe hardware constraints recently forced Microsoft to turn away cloud and AI clients, restrict subscriptions, and face service disruptions , the immediate context for a plan Bloomberg characterized as a response to runaway demand. The plan reads against Microsoft's own recent behavior: earlier in 2026, the company walked away from roughly 2 gigawatts of planned American and European projects, a pullback analysts attributed to oversupply of AI compute clusters. Months later it is planning to more than triple total capacity, a reversal that reflects how quickly demand forecasts move in this business.
Microsoft has committed to spending heavily on data centers, expecting capital expenditure to hit $50 billion in Q1 fiscal 2027 and $175 billion for calendar year 2026. To manage costs, the company is thinking of structuring leases over 25 years instead of 15-year periods. Azure surpassed $100 billion in annual revenue during fiscal 2026, representing growth of 41%. Sources cautioned the roadmap could shift as new server farms take years to develop.