Blog

Who Really Processes the Text You Send to AI

Anthropic says two rivals secretly routed customer prompts to Claude without disclosure. For your business, the risk is contractual.

September 12, 2026 · Agência Primeira Página

Who Really Processes the Text You Send to AI

You sign up for an AI tool, type your text, and get a response. The question almost no one asks is: which model actually read it?

On September 10, Anthropic published a 154-page threat intelligence report stating it had found two competing companies forwarding their own customers' requests to Claude, without telling those customers, and returning the answer as if it came from their own model.

For anyone who just wants to get work done, this isn't a fight between labs. It's a contractual question that's gone unanswered.

What the report claims

The document names five Chinese companies and totals close to 200 million interactions tied to what Anthropic calls illicit distillation: using one model's output to train another without authorization.

  • Alibaba: more than 151 million interactions with Claude between May and July 2026, peaking near 3 million per day, spread across more than 3,500 accounts that Anthropic classified as fraudulent. It's the largest campaign of its kind the company says it has ever measured.
  • Moonshot AI: about 300,000 requests from users of the Kimi assistant forwarded to Claude over a ten-day period, through 5,380 fraudulent accounts, with the response presented to the user as if it had come from Kimi.
  • DeepSeek: the same tactic, with more than 12 million cases observed over fourteen days in July 2026, without notifying customers.
  • Xiaomi and Zhipu also appear in the report, with smaller volumes.

The part that hits anyone who was just trying to work

The detail that shifts the whole conversation is this: some of the forwarded requests contained sensitive information, and Anthropic says it doesn't know whether Moonshot told customers their text was being sent elsewhere.

Translated to the desk of whoever signs the contract: a company paid for tool A, wrote what it needed to write, and the text was processed by company B, in another country, under different terms of service, without anyone having agreed to that. The customer did nothing wrong and had no way to notice.

It's the concrete version of the question we raised in draft in the AI chat: who else can see it. Before, the question was what the vendor does with your text. Now it comes earlier: who the vendor actually is.

Under Brazil's LGPD, the problem doesn't stay with the vendor

When your company decides what to do with customer data, it is the controller. The tool that processes it on the company's behalf is the operator. And the law is direct on two points.

Article 39 states that the operator processes data according to the instructions provided by the controller. Article 42 states that both controller and operator are liable for damage caused during processing. In other words: a handoff you never authorized isn't just your vendor breaching a contract — it's exposure for you, in front of your own customer, with your name on the contract they signed.

The same logic applies as in what we wrote about the TikTok fine: the authority goes after whoever has the relationship with the data subject, not whoever is three layers back in the technical chain.

What to demand in writing before signing

None of these five requests is exotic, and a serious vendor will answer without hesitation. If the answer dodges the question, that's already information.

  1. Which model processes it, from which company, and in which country. Name and version. "Our proprietary model" is not an answer.
  2. Is there a subcontractor? If so, ask for the list and a commitment to notify before any change. A silent subcontractor swap is exactly what the report describes.
  3. Does my content get used for training? Ask for the clause stating it doesn't, and whether you can opt out on your own.
  4. How long is the history kept, and where. Retention with a defined period and region, not "per our policy."
  5. What happens to my data at the end of the contract. Deletion timeline and proof.

Anyone who has already thought about leaving the vendor chain will find the cost reasoning in how much it costs to run an open model in your company. It's not for everyone, but running the model in-house settles the question of who processes it, once and for all.

The other side, which has to be said

Two honest caveats. First: the accuser is a direct competitor of the accused companies, which doesn't invalidate the numbers, but does make the source an interested party. Second: China's Ministry of Commerce rejected the report, stating there is no factual or legal basis for the accusation of industrial-scale distillation, calling the episode an attempt to hold back China's AI industry, and mentioning countermeasures.

None of this has been ruled on by any court, and the named companies haven't confirmed the practice. What backs today's takeaway doesn't depend on who's right: if you don't know, in writing, which model processes your text, you have a contract problem, regardless of this case.

Setting up support and automation with these answers defined in advance is part of the work in AI chatbot.

Sources

Anthropic's threat intelligence report, published September 10, 2026, 154 pages, along with coverage from TechCrunch, CNBC, and the South China Morning Post between September 10 and 12. China's Ministry of Commerce response was reported by the South China Morning Post. Articles 39 and 42 are from Brazil's General Data Protection Law (LGPD), no. 13,709 of 2018.

Frequently asked questions

What is AI model distillation?

It’s the practice of using one model’s answers to train another. A company sends millions of prompts to a rival’s model, saves the responses, and trains its own system on that material, arriving at a similar result without paying the cost of the original research. When this is done without authorization and through fraudulent accounts, the industry calls it illicit distillation.

How can I tell if my AI vendor is passing my data to another model?

Ask in writing which model processes your requests, which company built it, in which country it operates, and whether there are subcontractors anywhere in the chain. Also ask for a commitment to disclose any change of subcontractor before it happens. A vendor that answers with “it’s our proprietary model” and won’t detail the chain is leaving the question unanswered.

If the vendor passes data along without telling me, is that on them or on my company?

In your client’s eyes, the responsibility is yours too. Under Brazil’s LGPD, the processor must handle data strictly according to the controller’s instructions, and Article 42 holds both the controller and the processor liable for the damage. You can go after the vendor later through your contract, but it’s your company that has the relationship with the data subject.

Has using a foreign AI tool stopped being safe?

It’s not a question of where the tool comes from, but of whether the contract is verifiable. What this case shows is that the chain can have a layer the client never sees. A tool with a clear contract covering the model used, subcontractors, training practices, and data retention is still perfectly usable; what you can’t do is sign on without those answers.

Does running an open model in-house solve the problem?

It answers the question of who does the processing, since it all stays on your own infrastructure, but it brings costs of its own: hardware, operations, and upkeep. It makes sense when volume is high and steady, or when the data is sensitive enough to justify the expense. For small, irregular use, a well-written contract usually works out cheaper.

Have the accused companies confirmed the practice?

No. The companies named have not confirmed it, nothing has been proven in court, and China’s Ministry of Commerce rejected the report outright, stating there is no factual or legal basis for the accusation and calling the episode an attempt to hold back China’s AI industry. Since the accusation came from a direct competitor, it’s worth reading with caution.