
Former OpenAI and Anthropic researcher Jacob Coxon has claimed that Chinese spies are already working inside both US artificial intelligence companies, despite offering no evidence to support the allegation.
Speaking on the PBD Podcast released on 6 October 2026, Coxon said he was '90%' certain of their presence and warned that espionage could help China close the technological gap with the United States.
Coxon did not identify any suspected spies and acknowledged that he had never encountered anyone he personally believed was an intelligence operative. A source familiar with Anthropic told Business Insider there was no evidence supporting his allegation. The source said Anthropic maintained rigorous personnel vetting, strict access controls and insider-risk monitoring. Coxon and representatives for OpenAI did not respond to Business Insider's requests for comment.
Both companies have separately reported attempts by Chinese AI developers to extract capabilities from their models. However, those incidents do not establish that Chinese intelligence operatives have infiltrated either organisation.
Coxon Claims Chinese Spies Are Already Inside US AI Labs
Coxon, who previously worked at OpenAI and Anthropic, made the allegation during an interview with Patrick Bet-David. He argued that China's ability to obtain American AI advances could undermine efforts to maintain a technological lead, even if US companies slowed development.
Asked how confident he was that spies were already inside the companies, Coxon replied: '90%.' He subsequently described their presence as 'almost certain' and said the possibility had been discussed at OpenAI, sometimes jokingly.
However, when Bet-David asked whether he had encountered anyone suspicious, Coxon answered: 'No.' He said he did not want to stereotype people based on Chinese nationality and declined to identify any suspected operative.
Coxon also questioned whether frontier AI laboratories conducted sufficiently rigorous background checks, arguing that advanced AI could have significant national-security implications. He presented no independently verifiable evidence that either company's vetting was inadequate. Anthropic, meanwhile, says it treats foreign intelligence threats seriously and maintains strict internal security measures.
Anthropic Reports Millions of Unauthorised AI Exchanges
The espionage allegation comes amid documented attempts to extract capabilities from advanced American AI systems, although those incidents are separate from Coxon's claims about spies inside the companies.
On 23 February 2026, Anthropic reported what it described as industrial-scale distillation campaigns involving Chinese AI developers DeepSeek, Moonshot AI and MiniMax. The company said the laboratories generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.
Distillation involves training or improving one AI model using another model's outputs. Although the technique is widely used legitimately, Anthropic alleged that these campaigns violated its terms of service and regional access restrictions.
In its September 2026 threat-intelligence report, Anthropic detailed further activity. It attributed more than 23 million exchanges between May and July to Moonshot and more than 12.1 million exchanges over 14 days in July to DeepSeek. These findings concern alleged unauthorised model extraction, not confirmed intelligence infiltration.
OpenAI Disrupts Separate Model-Extraction Campaign
OpenAI disclosed a separate security incident on 30 September, saying it had disrupted a coordinated campaign designed to extract protected reasoning from its models.
According to the company's security report, the earliest observed activity began on 1 July. OpenAI later identified related suspicious prompt patterns across a cluster of more than 15,000 users and said it had fully disrupted the activity by 28 July.
The company attributed a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi. However, OpenAI acknowledged that it could not determine whether every operator involved originated from the same actor.
OpenAI said the operators had not broken its encryption, compromised a database or gained direct access to stored user conversations. Instead, they manipulated model interactions so protected reasoning could be reproduced in forms visible to the requester. OpenAI classified the activity as adversarial distillation rather than a conventional data breach.
Congress Seeks Answers on AI Model Security
Concerns about protecting advanced American AI technology have also reached Congress.
In letters dated 30 September, US Representative Ro Khanna asked OpenAI, Anthropic, Google, Meta and SpaceXAI to disclose known attempts by China or other hostile actors to gain unauthorised access to sensitive AI model weights, Reuters reported. He also requested information about the companies' cybersecurity safeguards.
Model weights are numerical parameters learned during training that help determine how an AI system operates. Obtaining them could allow another organisation to reproduce significant capabilities without undertaking the same development and training process.
Reuters noted that although OpenAI and Anthropic have reported distillation activity involving Chinese developers, relatively few publicly known cases involve the theft of advanced model weights. Coxon's assertion that Chinese spies are already inside OpenAI and Anthropic therefore remains unverified. The documented extraction campaigns and congressional scrutiny highlight growing concerns about AI security, but neither proves his allegation.




