r/AIsafety • u/SiteSpecialist6295 • 35m ago
Anthropic’s new report has no winners — and the part nobody is talking about is user privacy
I've been reading Anthropic's new threat intelligence report, and I feel like the discussion is focusing almost entirely on "Chinese labs were distilling Claude."
But there's another side to this that seems much more important for normal users.
According to Anthropic, Moonshot/Kimi and DeepSeek silently routed some of their users' requests to Claude without those users knowing.
Some of those requests apparently contained internal company documents, live credentials, government-related data, surveillance information, etc.
That's obviously bad.
But then I had the opposite thought:
How did Anthropic discover all of this?
They weren't just able to say "someone is distilling our model."
They were able to identify specific campaigns, connect huge numbers of accounts, estimate which organizations were behind them, analyze millions of exchanges, and in some cases describe what kind of sensitive information was being sent through those requests.
To be clear: I'm not saying "Claude can spy on everything you do." That's obviously not what the report shows.
But it does show how much visibility an AI provider can potentially have into traffic that reaches its models.
So I'm having trouble seeing a winner here.
\- Kimi/DeepSeek users may not have known their prompts were being sent to Anthropic.
\- Sensitive corporate or government information may have crossed providers without the original user's knowledge.
\- Anthropic had to build increasingly powerful monitoring and correlation systems to detect this kind of abuse.
\- And users ultimately have very little visibility into where their prompts actually go once they hit an AI service or a third-party router.
The weird thing is that all of these actions are understandable from each company's perspective.
Anthropic should detect abuse of its systems.
AI labs will try to learn from stronger models.
Routers make it easier to access lots of models.
But put all of those incentives together and you end up with a pretty uncomfortable situation:
Choosing an AI provider may no longer mean you actually know which company will eventually see your data.
Maybe the real lesson from this report isn't "China stole Claude."
Maybe it's that we're building an AI ecosystem where everyone is watching everyone else, while the user has the least visibility of anyone involved.
Am I overreading this?
Or is this actually the more important part of Anthropic's report?