The AI Brief

Vol. I · No. 109 · Friday, September 11, 2026

Today's brief:

  • Anthropic's September threat intelligence report names Alibaba, Moonshot, and DeepSeek in illicit distillation campaigns that extracted 151 million Claude exchanges, establishing that stolen API access, not model weights, is now the primary AI supply-chain theft vector.
  • Alibaba extracted 151 million Claude exchanges in three months using fake accounts and stolen credentials, proving illicit distillation now runs at industrial scale and that rate limits alone cannot stop it.
  • Sam Altman told employees at a companywide meeting OpenAI is open to pacing its most advanced AI alongside other labs, the first time the CEO has said so internally, two days after his chief scientist published warnings about chain-of-thought monitoring failure.
  • OpenAI launched ChatGPT for Financial Services, combining GPT-6 Astra with licensed data from PitchBook, LSEG, S&P Capital IQ, and Moody's, co-developed with Morgan Stanley and Evercore, OpenAI's most direct move yet into the financial-analyst workflow.
  • Microsoft plans to expand its global data-center footprint from 12 gigawatts to more than 38 gigawatts by 2032, with AI-specific capacity growing from 2 GW today to roughly one-third of that total, a tripling that implies $175 billion or more in annual capital expenditure through the end of the decade.

Anthropic Names Alibaba, DeepSeek, Moonshot in Industrial-Scale Claude Distillation Campaign

Why it matters
For the first time, a frontier lab has publicly named and documented specific Chinese AI companies, Alibaba, Moonshot, DeepSeek, Xiaomi, Z.ai, and MiniMax, operating industrial-scale covert campaigns to extract Claude's capabilities via fraudulent API accounts, making stolen API keys the new primary AI intellectual-property theft channel, not model-weight exfiltration.
What's at stake
Every enterprise running AI via third-party API aggregators or resellers faces the same credential-theft and account-fraud surface Anthropic describes; the Alibaba campaign operated through 3,500 fake accounts with stolen credit cards, meaning detection requires usage-pattern and account-origin analysis that most operators do not run today.
Decode
Illicit distillation = using the outputs of a more capable AI model, at industrial scale, covertly, and without authorization, to train a second model, replicating capabilities without the compute cost. Anthropic defines it as requiring fraud: fake accounts, stolen credentials, and shared fixed prompts to generate training material. Distinguished from legitimate distillation, which is authorized and disclosed.
Detail

Anthropic's fourth threat intelligence report, published September 10 and covering December 2025 through August 2026, documents seven harm categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. Anthropic says it disrupted cyber operations in which AI moved beyond assisting human hackers to orchestrating reconnaissance, exploitation, and data theft, alongside alleged efforts by seven China-based AI labs to extract capabilities from Claude.

The company observed 151 million exchanges between May and July 2026 attributable to the Alibaba campaign, peaking at nearly three million exchanges per day, spread across 3,500 different accounts that shared a single fixed prompt used to extract chain-of-thought reasoning, evidence Anthropic uses to attribute them to a single effort to produce training material for Alibaba's Qwen model family. Anthropic said it detected and disrupted unauthorized large-scale efforts by China-based AI labs including Alibaba, Moonshot, and DeepSeek to train their models using Claude, which it describes as "illicit distillation", using outputs from a more capable AI model to train another and replicate its capabilities without authorization.

DeepSeek used tactics similar to Moonshot's, transferring exchanges to Claude without notifying its own customers; Anthropic observed more than 12 million distillation attacks attributable to DeepSeek over 14 days in July 2026. Moonshot AI, which produces the Kimi family of models, is alleged to have "silently forwarded customer requests to Claude, instead of processing them using Kimi." A broader finding across the cyber section: "AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators." A Russian espionage cluster tracked as GTG-20006 ran AI-assisted operations against Ukrainian, European, and diplomatic targets, with Anthropic identifying more than 20 distinct organizations targeted in reconnaissance and live operations. A core pattern throughout: the operating model of an agent running the attack has spread to every class of actor Anthropic investigated, and access to frontier models themselves, stolen API keys and session tokens, is now what criminals steal and resell.

Disclosure: Claude, which generates this brief, is built by Anthropic.


151M
Claude exchanges extracted by Alibaba's distillation campaign in three months, the largest single illicit distillation operation Anthropic says it has ever measured

Alibaba's Qwen Training Campaign Pulled 151 Million Claude Exchanges in Three Months

Why it matters
The 151 million figure, nearly 3 million exchanges per day at peak, establishes that illicit distillation operates at a scale comparable to legitimate research API usage, making volume-based detection insufficient and requiring prompt-pattern and account-origin fingerprinting to catch campaigns running under API rate limits.
What's at stake
For most operators, this is context about a vendor-level enforcement problem. For any enterprise operating AI API resellers, white-label model aggregators, or multi-tenant inference layers, this is a direct control gap: the same fraud vectors, stolen credit cards, fake accounts, fixed system prompts, run through infrastructure those operators may touch.
Detail

Anthropic called Alibaba's campaign "the largest distillation attack we have ever measured," covering over 151 million exchanges between May and July 2026. The campaigns targeted what Anthropic described as "some of Claude's most valuable capabilities, including agentic capabilities and tool use, coding and data analysis, and logical reasoning."

Illicit distillation extracts and mimics capabilities from frontier models without the time, compute, and cost of independent development. While distillation is a legitimate training method, it is illicit when the user is not authorized to undertake the process. Anthropic defines illicit distillation as "an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization," typically enabled by fraud: "sophisticated networks of fake accounts created with stolen credit cards, login credentials and API keys."

Anthropic said Alibaba also used Claude for broader AI research, including reinforcement learning and model architecture , meaning the campaign extracted both training data and engineering methodology. Alibaba, Moonshot, DeepSeek, and Xiaomi did not respond to CNBC's requests for comment at publication time.

Disclosure: Claude, which generates this brief, is built by Anthropic.


Altman Tells Staff OpenAI Is Open to Pacing Its Most Advanced AI, Hopes Rivals Follow

Why it matters
Altman's remarks are the first time OpenAI's CEO has said the company is open to deliberately slowing frontier development inside a staff meeting, a signal qualitatively different from public hedging, and they land the same week OpenAI's chief scientist disclosed that chain-of-thought monitoring is degrading and a former Anthropic pretraining researcher called both companies' race "gambling with our lives."
What's at stake
Whether voluntary inter-lab pacing produces a binding agreement or evaporates into individual press statements depends on whether labs that declined the 2023 pause letter, xAI, Meta, Mistral, participate; Altman acknowledged publicly that some companies may not agree.
Detail

OpenAI is considering slowing down the development of cutting-edge artificial intelligence, and CEO Sam Altman is hoping other AI companies will do the same. In a companywide meeting this week, Altman told employees that OpenAI could potentially pace its AI development, perhaps in conjunction with several other AI labs, but that some may not agree to do so, according to multiple people familiar with the matter.

OpenAI said it has slowed parts of model development and paused certain internal AI training recently due to safety concerns. In July, Altman also said he had spoken with White House officials about the "need" to pace AI development. The remarks follow OpenAI chief scientist Jakub Pachocki's September 9 essay disclosing that chain-of-thought monitoring is progressively failing, covered in Vol. I, No. 107.

On September 9, Jacob Coxon, an AI researcher who had spent three years on pretraining at both OpenAI and Anthropic, quit and accused both former employers of "gambling with our lives" by racing toward superintelligent AI. Coxon's warning received more than 100 million views and was publicly supported by other Anthropic researchers, including Evan Hubinger and Samuel Marks. Separately, Senator Bernie Sanders and Representative Greg Casar introduced the Ban Artificial Superintelligence Act in September 2026, targeting a narrowly defined class of systems rather than AI broadly. The convergence of an internal CEO statement, a chief scientist's published warning, a high-profile researcher resignation, and a congressional bill in the same week is without precedent in this run of frontier development.


OpenAI Launches ChatGPT for Financial Services, Bundles GPT-6 Astra With Licensed Market Data

Why it matters
By pre-clearing data licensing with S&P Capital IQ, LSEG, Moody's, PitchBook, Preqin, Dow Jones Factiva, and seven other premium providers, OpenAI has built a product where the data deals are structurally harder to replicate than the model itself, turning a frontier reasoning layer into a governed, audit-trailed financial workspace that Bloomberg Terminal and Refinitiv have not yet matched.
What's at stake
For most operators, this is competitive context. For investment banks, asset managers, and fintech vendors that already pay for LSEG or S&P Capital IQ subscriptions, the pricing question is whether OpenAI's bundle undercuts the cost of assembling equivalent data access independently, a number OpenAI has not published.
Detail

OpenAI on September 10 launched ChatGPT for Financial Services, a tailored ChatGPT Work experience designed to help financial institutions conduct research, develop financial models, and create customized client materials. The product combines built-in financial data with GPT-6 Astra's reasoning capabilities and was developed in partnership with Morgan Stanley and Evercore, whose input helped identify the biggest challenges faced by financial institutions.

Data partners include Daloopa, PitchBook, S&P Capital IQ, LSEG, MSCI, Moody's, Dow Jones Factiva, Preqin, Intapp, Datasite, and Box, with Reuters available through LSEG. GPT-6 Astra can reason across figures, tables, and notes, trace data across periods, run analysis, and turn findings into documents, spreadsheets, slides, interactive charts, and visualizations with underlying data and sources open to review. Administrators can publish Excel, Word, and PowerPoint templates so valuation models, research notes, and pitchbooks follow firm formats and style guides. The service builds on ChatGPT Enterprise controls including SAML SSO, SCIM provisioning, role-based access, and configurable retention. OpenAI says business data is encrypted at rest and in transit and is not used to train its models by default.

These data services are ones that banks already pay for, and getting permission to use their data inside another company's product can take time and involve complicated licensing agreements. In this case, the data deals may be more important than the model itself, OpenAI is not just selling access to an AI system. Access requires contact with OpenAI sales; no price has been published.


Microsoft Plans to More Than Triple Data-Center Capacity to 38 GW by 2032, AI Share to Grow Six-Fold

Why it matters
A 38 GW target, which Bloomberg notes would exceed New York State's peak electricity consumption, requires Microsoft to sustain $175 billion or more in annual capital expenditure through the end of the decade, a pace that locks in GPU supply commitments, power purchase agreements, and long-term lease structures that will constrain Azure pricing and availability for every enterprise building on it.
What's at stake
For most operators, this is infrastructure context, Azure capacity will loosen through 2028 as new builds come online. For operators currently on Azure waitlists or facing service throttling on GitHub or enterprise tiers, the 2027 delivery pipeline is the relevant data point, not the 2032 headline.
Detail

Microsoft's globe-spanning network of data centers will have more than 38 gigawatts of capacity in 2032, up from about 12 gigawatts now, according to people familiar with the plans. Microsoft projects AI-dedicated capacity to grow from 2 gigawatts now to about one-third of the total 38-gigawatt footprint by 2032 , a roughly six-fold increase in AI-specific silicon from today's baseline. The expansion, which excludes capacity rented from neoclouds like CoreWeave, would eclipse the peak-period electricity consumption of New York State.

Severe hardware constraints recently forced Microsoft to turn away cloud and AI clients, restrict subscriptions, and face service disruptions , the immediate context for a plan Bloomberg characterized as a response to runaway demand. The plan reads against Microsoft's own recent behavior: earlier in 2026, the company walked away from roughly 2 gigawatts of planned American and European projects, a pullback analysts attributed to oversupply of AI compute clusters. Months later it is planning to more than triple total capacity, a reversal that reflects how quickly demand forecasts move in this business.

Microsoft has committed to spending heavily on data centers, expecting capital expenditure to hit $50 billion in Q1 fiscal 2027 and $175 billion for calendar year 2026. To manage costs, the company is thinking of structuring leases over 25 years instead of 15-year periods. Azure surpassed $100 billion in annual revenue during fiscal 2026, representing growth of 41%. Sources cautioned the roadmap could shift as new server farms take years to develop.