AI Briefing: June 26, 2026 — The Third Trigger: Two Days Before the Fable 5 Shutdown, Anthropic Told Congress Alibaba Had Harvested 28.8 Million Claude Conversations

THE NUMBERS BEHIND "LARGEST KNOWN": WHAT THE LETTER ALLEGES

The letter's account, as described by people who have seen it, is specific in a way that distinguishes it from a general accusation of unfair competition. Between April 22 and June 5, operators Anthropic links to Alibaba's Qwen research lab created and operated approximately 25,000 accounts designed to evade the rate limits and abuse detection that would normally flag automated scraping. Through those accounts, the operators ran 28.8 million exchanges with Claude, skewed heavily toward two categories: multi-step software engineering tasks and agentic reasoning chains — the kind of structured, high-value outputs that are expensive for any lab to generate through reinforcement learning and cheap to copy once a stronger model has already produced enough of them. Anthropic says it has since banned every account it identified as part of the campaign. The company's framing in the letter is not subtle: it describes the operation as Alibaba "brazenly" and "illicitly" extracting the capabilities Anthropic spent years and, by its own account, billions of dollars developing.

What makes the figure land as hard as it has is the comparison Anthropic itself supplies. The 28.8 million exchanges recorded in this single campaign exceed the combined total Anthropic disclosed in February, when it named DeepSeek, MiniMax, and Moonshot AI in a joint accounting of roughly 24,000 fraudulent accounts and more than 16 million exchanges across all three labs together. One operation, in other words, generated more traffic than three of China's most prominent AI labs combined did in the disclosure that, four months ago, was itself described as unprecedented in scale.

THE TWO DATES NOBODY HAD CONNECTED, UNTIL NOW

Read against this site's own coverage, the most consequential detail in this week's reporting is not the headline number — it is the date on the letter. June 10 is two days before June 12, the date Commerce Secretary Howard Lutnick sent Anthropic CEO Dario Amodei the letter imposing export controls on Fable 5 and Mythos 5 "by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees," the directive that triggered the twelve-day global blackout this site tracked from shutdown through the June 22 "NSA Tell" reporting to the June 24 restoration. The administration's public account of that shutdown has never mentioned Alibaba, distillation, or this letter. White House adviser David Sacks described the trigger publicly as a "narrow" jailbreak Anthropic could patch; this site's June 22 reporting separately named an Amazon-flagged guardrail bypass escalated to Treasury and a quietly revoked SK Telecom credential as the shutdown's two operative causes. None of that reporting, at the time, knew Anthropic had also sent Congress a warning about a Chinese lab harvesting 28.8 million Claude conversations forty-eight hours earlier.

To be precise about what is and is not established: nobody, including Anthropic, has claimed the June 10 letter caused the June 12 directive, and a White House Office of Science and Technology Policy memo pledging to help labs detect and mitigate distillation attempts had already been circulating since April, meaning the policy concern predates this specific letter by months. What the timing does establish is that the export-control shutdown this site has spent two weeks describing as a story with two named triggers happened in a week when Anthropic was independently telling the same parts of the government that a Chinese lab had just run the largest extraction campaign against Claude on record. Whether that is coincidence, context, or cause is a distinction the public record still cannot settle — and it is exactly the kind of distinction this site flagged on June 22 when it separated what Sen. Mark Warner actually said about Mythos from what the internet turned it into. The honest version of this story is that a third data point has joined a timeline that already had two, not that it has replaced either of them.

WHY DISTILLATION IS THE THING FABLE 5'S CLASSIFIER WAS BUILT TO STOP

This site's June 10 coverage of the Fable 5 launch described, without yet knowing this campaign existed, the specific design choice Anthropic made to address it: a classification layer that intercepts queries in defined high-risk domains — cybersecurity, biology and chemistry synthesis, and what Anthropic called "distillation," attempts to use the model's outputs to train or replicate a competing model at Mythos-class capability — and routes them to a weaker model before they can leave the system intact. Fable 5 launched June 9. The Alibaba campaign this letter describes ran from April 22 through June 5, ending four days before the launch and entirely on the Claude models Fable 5's classifier did not yet exist to protect. Read together, the sequence reads less like two unrelated stories than like cause and effect on a different axis than the export-control one: a months-long extraction campaign against Anthropic's pre-Fable-5 models, concluding just before the company shipped a model with a purpose-built defense against exactly that behavior, followed two days after the letter describing it reached Congress by a government order that took the model in question offline entirely.

Distillation matters as a security question, not just a competitive one, for a reason Anthropic's letter spells out: a model built by training on a stronger model's outputs inherits whatever capability the source model has, without necessarily inheriting the safety mitigations the source lab spent comparable effort building. A frontier lab's refusal training, its classifier layers, its red-teaming — none of that transfers through distillation unless the distilling lab chooses to replicate it independently. That is the substance behind Anthropic's request that Washington clarify antitrust guidance so labs can share distillation intelligence with each other, and behind its renewed call for chip export controls: the company's argument is that a model distilled from Claude's outputs can match Claude's raw capability while skipping the years of safety work that, in Anthropic's account, makes Claude expensive to build in the first place.

THE FALLOUT: A 16-MONTH LOW, AN NDAA AMENDMENT, AND SILENCE FROM ALIBABA

Markets reacted within hours of the story breaking. Alibaba's Hong Kong-listed shares fell as much as 4.4% to HK$95, their lowest level since February 2025, while the US-listed ADR slid a comparable amount in New York — a sixteen-month low driven entirely by a story about how Alibaba's AI lab behaves, not by anything in the company's underlying retail or cloud business. Alibaba has not publicly addressed the distillation allegations; reporters seeking comment from the company received no response by the time this article was published. The silence is conspicuous given that Alibaba has been willing to fight other US actions this same week — the company separately sued the Defense Department to be removed from the Pentagon's list of alleged Chinese military-linked companies, a designation it calls baseless and unrelated to this specific dispute, but evidence that Alibaba is not simply absorbing US pressure on every front without pushing back.

On Capitol Hill, the response has moved past statements and into draft legislation. Senators Bill Hagerty and Andy Kim are preparing an amendment to this year's must-pass defense authorization bill that would sanction or blacklist Chinese firms found to be improperly accessing the outputs of US AI models — language aimed squarely at the kind of campaign Anthropic's letter describes, and a sign that the distillation issue, simmering since February's three-lab disclosure, now has bipartisan legislative momentum independent of whatever happens with Fable 5's export-control terms.

WHAT THIS MEANS FOR ENTERPRISES BUILDING ON FRONTIER APIS

None of this changes what Claude can do today, and the practical risk to an enterprise customer's own Anthropic-built workflows from a competitor's distillation campaign is close to zero — the harm, if Anthropic's account is accurate, falls on Anthropic's competitive position and on the safety properties of whatever model Alibaba trains from the harvested outputs, not on any individual customer's data or deployment. What this week's disclosure should change is how buyers read the export-control saga this site has covered since June 12. A story that looked, ten days ago, like a binary fight over one jailbreak now looks like the visible part of a broader pattern: frontier labs treating model outputs themselves as a strategic asset worth defending through bans, letters to Congress, and — whether by coincidence or design — government action that can take a model offline worldwide with two days' notice. A procurement team weighing a multi-year commitment to any frontier API is now implicitly betting not just on a lab's research continuity, the question this site raised on June 25 after Google's latest researcher exodus, but on whether that lab's relationship with its own government stays stable enough that access does not become a bargaining chip in a dispute the customer never sees coming. Three weeks into this saga, that is no longer a hypothetical risk. It is the pattern.