Sections 00:00 What we're covering today 00:30 1. Anthropic says Alibaba-linked accounts hit Claude 151 million times 02:33 2. A judge called the Pentagon's Anthropic blacklist illegal and baseless 04:17 3. California wrote rules for AI auditors while Congress kept talking 06:00 4. Oracle spent $28.5 billion in one quarter to feed its AI cloud 07:52 5. Claude writes 80 percent of Anthropic's code. Anthropic wants an emergency brake 09:51 Visit Hot Tea Disclosure Narration uses an AI-generated voice. Transcript Welcome to Hot Tea for Friday, September 11, 2026. Anthropic says Alibaba-linked accounts hit Claude 151 million times. We'll also cover the Pentagon's court loss, California's rules for A I auditors, Oracle's cloud spending, and how much of Anthropic's code Claude now writes. First, Anthropic published a 154-page threat report on September 10. It covers misuse the company says it disrupted between December 2025 and August 2026. Anthropic says Alibaba-linked accounts hit Claude 151 million times. Anthropic published a 154-page threat report on September 10. It covers misuse the company says it disrupted between December 2025 and August 2026. Anthropic says seven China-based A I labs tried to extract and copy Claude's capabilities. It linked the largest operation to Alibaba's Qwen and Tongyi teams. Anthropic says the operation produced more than 151 million exchanges from May through July. Traffic peaked near three million exchanges a day. It came through more than 3,500 accounts that Anthropic described as fraudulent. The company says operators collected Claude's reasoning traces and used them to improve Qwen models. The report links more than 23 million exchanges to Moonshot and 12.1 million to DeepSeek. It also links 3.4 million to Zhipu and more than 400,000 to Xiaomi. Reuters reports that Anthropic accused Moonshot and DeepSeek of routing some live customer conversations through Claude without telling users. Alibaba had not responded when Reuters published its report. This is a company claim based on Anthropic's own service logs and attributions. The report provides campaign identifiers, dates and counts, but no outside auditor has verified the complete evidence. Distillation is also a standard method used throughout the A I industry. The disputed conduct is the alleged use of fraudulent accounts and covert customer routing, not the technique by itself. Anthropic says the cases in its report were notable rather than typical. The named companies should publish technical responses that address the account counts, traffic patterns and routing claims. Independent researchers need enough logs to test Anthropic's attribution. A denial without supporting data will not settle a claim based on private service records. Governments will have to decide whether export-control rules should cover model outputs. The details matter. A broad rule could block ordinary research or interoperability. A narrow rule could miss proxy networks and resellers. Watch for rules aimed at account fraud, covert routing and industrial-scale extraction rather than distillation itself. A judge called the Pentagon's Anthropic blacklist illegal and baseless. A federal judge blocked the Pentagon from treating Anthropic as a national-security supply-chain risk. Reuters reports that U.S. District Judge Rita Lin found the designation punished Anthropic for its public position on A I safety, violating the First Amendment. She also found that the government denied Anthropic the process required by the Fifth Amendment. The dispute began when Anthropic refused to let the military use Claude for every lawful purpose. The company wanted to keep restrictions on mass surveillance of Americans and fully autonomous weapons. Defense Secretary Pete Hegseth responded with a procurement label meant to protect military systems from infiltration or sabotage. Reuters says this was the first public use of that designation against a U.S. company. The ruling doesn't require the Pentagon to buy Claude or accept Anthropic's contract terms. The government can choose another supplier. A separate case in Washington challenges another Pentagon method for excluding Anthropic, and that case remains pending. The court limited how the government could punish Anthropic. It didn't decide which military uses of A I should be legal, who should set those limits, or how Congress should oversee them. The immediate questions are whether the government appeals and how quickly agencies withdraw the supply-chain directives. The Washington case could produce a different rule because it involves another procurement power. Future defense A I contracts will also show whether suppliers can keep use restrictions without losing unrelated federal business. Congress could settle the larger question with rules for domestic surveillance and autonomous weapons. Until then, model vendors and procurement officers will keep negotiating those limits contract by contract. California wrote rules for A I auditors while Congress kept talking. Reuters reports that California enacted the first state law setting rules for independent audits of A I products. OpenAI said it supported the measure. The law followed reports that A I agents had reached systems outside their test environments. Researchers inside major labs had also warned lawmakers, and members of both parties responded. Senator Ted Cruz said he was working with Senate Majority Leader John Thune and Senator Amy Klobuchar on legislation covering catastrophic A I risks. Six House members proposed a separate bill in July that would require independent security audits of the most capable models. Senators Josh Hawley and Richard Blumenthal also sent letters seeking details about OpenAI's agent incidents. But federal statements aren't federal rules. Reuters reports that the Cruz, Thune, and Klobuchar proposal has no public text or release date. Letters can force disclosure, but they can't create testing standards or enforcement powers. Much of this debate also rests on claims from the companies and researchers building the systems. Independent auditors need access to the models, test environments, and incident records. Without that access, an auditor could certify a narrow demonstration and miss failures involving real tools or broken safeguards. A useful Senate proposal would define which models it covers, who accredits testers, and what evidence can stop a deployment. The House bill still needs to explain whether reports become public and how it would protect security-sensitive details. California's implementation will provide the first practical test. Watch the auditor access, published standards, conflict-of-interest rules, and first enforcement case. Those details will show whether the law produces evidence or paperwork. Oracle spent $28.5 billion in one quarter to feed its A I cloud. Oracle reported $19.3 billion in quarterly revenue, up 30 percent. Cloud infrastructure revenue rose 121 percent to $7.4 billion. The company says it added more than $30 billion in A I cloud contracts, bringing its total backlog to $664 billion. Oracle also says it delivered 850 megawatts of new data-center capacity and more than 300,000 graphics processors during the quarter. Reuters reports that its shares rose four percent after hours, after revenue and adjusted earnings beat estimates. Those results support Oracle's claim that customers want the capacity it's building. The cost is harder to ignore. Oracle's $28.5 billion in quarterly capital spending exceeded its total revenue. Free cash flow was negative $5.4 billion, according to Reuters. Oracle says customer prepayments covered about $11.36 billion of that spending. It also says many new orders use prepayment or customer-owned hardware. That shifts part of the financing burden, but Oracle still carries the delivery risk. Backlog is promised future revenue, not cash in the bank. Oracle expects about half of it to become sales within 36 months. Power, construction, permitting, and customer demand still have to arrive on schedule. S&P Global cut Oracle's credit rating in July because of weak cash flow and higher business risk. The next quarterly filings should show whether Oracle can turn that backlog into cloud revenue fast enough to restore positive free cash flow. Separate disclosure of customer prepayments would make the financing picture clearer. Capital spending, debt, and the use of completed capacity will tell the story. If the backlog rises while data centers fall behind, the funding gap widens. Higher use and lower cash burn would show that the new capacity is starting to pay for itself. Claude writes 80 percent of Anthropic's code. Anthropic wants an emergency brake. Anthropic says Claude wrote more than 80 percent of the code merged into its production codebase as of May. That share was in the low single digits before Claude Code's 2025 preview. The company also says its typical engineer merged eight times as much code per day in the second quarter as in 2024. Anthropic says Claude completed 76 percent of its hardest open-ended engineering tasks in May. That success rate rose 50 percentage points in six months. In an internal optimization test, the reported speedup went from threefold in May 2025 to about 52 times by April 2026. Anthropic says these results show that A I is already speeding up A I development. It also says they don't prove full recursive self-improvement. The measurements come from the company selling the system, and Tom's Hardware notes that the figures are unaudited. More code doesn't prove better software. Anthropic also provides too little underlying data for outsiders to reproduce its productivity and task-success claims. The report says current models remain weaker at choosing goals, deciding which problems matter, and making senior research judgments. Full recursive self-improvement hasn't arrived, and the report says it may never arrive. Anthropic proposes a coordinated and verifiable way to slow or pause frontier development, but countries haven't agreed on how that would work. Independent studies would need to measure accepted changes, production bugs, reversions, and engineer time, not only lines of code. Anthropic could also explain how it decides whether Claude wrote a line and how the task set changed as the models improved. The policy test is whether labs can agree on a trigger for slowing development and verify compliance without exposing model secrets. Until then, the emergency brake is a proposal, not a working control. The larger change would come when models can choose useful research directions without a person selecting them. That is the signal before the noise. This briefing was produced from Hot Tea's verified daily edition. For the complete briefing and every source link, visit Hot Tea dot A I.