Data SovereigntyPolicy MoveJul 8, 2026, 1:18 PM· 4 min read· #5 of 5 in ai

China Issues National Security Advisory Against Anthropic's Claude Over Data Transmission

Chinese cybersecurity authorities have issued a formal advisory warning domestic and multinational enterprises against using Anthropic's Claude, citing unauthorized cross-border data transfers. The move highlights the growing friction over data sovereignty as global AI models integrate deeper into corporate workflows.

By Factlen Editorial Team

Data Sovereignty Advocates 40%Global Enterprise Operators 35%Frontier AI Developers 25%
Data Sovereignty Advocates
Argue that cross-border AI data flows pose a severe national security risk and that all enterprise data must be processed locally.
Global Enterprise Operators
View these regulations as a massive operational headache that forces them to build fragmented, localized IT systems at high cost.
Frontier AI Developers
Maintain that telemetry and centralized processing are necessary to ensure model safety, security patching, and alignment.

Why this matters

As AI agents become deeply embedded in corporate networks, the telemetry data they send back to their creators is becoming a major geopolitical flashpoint. For multinational companies, this advisory signals that using a single, unified AI provider across global operations may no longer be legally viable.

On Wednesday, China's top cybersecurity regulator issued a formal national security advisory warning domestic and multinational enterprises against the use of Anthropic's Claude AI models. The Cyberspace Administration of China (CAC) cited "unauthorized and opaque cross-border data transmission" as the primary catalyst for the warning, marking a significant escalation in Beijing's efforts to control the flow of enterprise data generated by generative AI. The advisory does not amount to a blanket consumer ban—Claude's consumer interfaces were already largely inaccessible without a VPN—but it directly targets corporate API usage and third-party integrations that have become increasingly popular among businesses operating in mainland China.[1]

The core of the dispute centers on how frontier AI models handle telemetry and user prompts. According to the CAC's technical assessment, certain enterprise implementations of Claude were found to be transmitting sensitive corporate data, including proprietary code and internal communications, back to Anthropic's US-based servers without undergoing the mandatory security assessments required by China's Data Security Law. Chinese authorities argued that this continuous "phoning home" creates an unacceptable vector for industrial espionage and violates strict data localization mandates designed to keep critical economic information within the country's borders.

Anthropic has rapidly expanded its enterprise footprint throughout 2025 and 2026, positioning Claude as the premier secure AI assistant for corporate workflows. While the company offers "zero-retention" policies for its enterprise API customers—meaning prompts are not used to train future models—the sheer act of processing that data on foreign servers has triggered Beijing's regulatory tripwires. Multinational corporations that use Claude for global operations are now caught in the crossfire, forced to re-evaluate their IT architectures to ensure their Chinese branches do not inadvertently leak data across the firewall.[2]

How enterprise AI API calls conflict with strict data localization mandates.
How enterprise AI API calls conflict with strict data localization mandates.

The mechanics of AI data transmission are inherently complex and often misunderstood. To maintain safety guardrails and monitor for malicious use, frontier models require a constant stream of telemetry. This data helps developers patch vulnerabilities, prevent jailbreaks, and ensure the model is not being used to generate harmful or illegal content. However, from the perspective of a foreign government, this safety telemetry looks identical to unauthorized surveillance. The CAC's advisory explicitly noted that the "black box" nature of these data flows makes it impossible for local auditors to verify exactly what information is being extracted from Chinese corporate networks.

The mechanics of AI data transmission are inherently complex and often misunderstood.

This advisory is part of a broader, accelerating trend toward "AI sovereignty." Just as the United States has moved to restrict Chinese access to advanced AI hardware and certain model weights, Beijing is aggressively walling off its domestic data ecosystem from Western AI providers. By flagging Claude, the CAC is sending a clear signal that foreign AI models will not be permitted to act as the central nervous system for Chinese enterprises unless they submit to rigorous local hosting and auditing requirements—a concession that US-based labs are legally and politically unable to make under current US Commerce Department rules.[1]

For multinational companies, the immediate operational impact is severe. Firms that have standardized their global workflows on Claude are now scrambling to bifurcate their AI stacks. Legal compliance teams are advising regional offices in China to sever API connections to US-hosted models and pivot to approved domestic alternatives, such as those provided by Baidu, Alibaba, or DeepSeek. This fragmentation of enterprise IT not only increases operational costs but also creates silos in corporate knowledge management, undermining one of the primary benefits of deploying generative AI at scale.[2]

Global regulators are increasingly demanding that AI data processing remain within their own borders.
Global regulators are increasingly demanding that AI data processing remain within their own borders.

Anthropic has maintained a measured public stance in response to the advisory. In a statement released shortly after the CAC's announcement, the company reiterated its commitment to enterprise data privacy and emphasized that it complies with all applicable laws in the jurisdictions where it officially operates. However, the company also noted that it does not actively market its services in mainland China, suggesting that the targeted usage primarily involves multinational firms routing traffic through global corporate networks or utilizing third-party software wrappers that bypass geographic restrictions.[1][2]

The fallout from this advisory extends far beyond Anthropic. It establishes a precedent that any cloud-based AI model lacking localized Chinese infrastructure is inherently suspect under the nation's national security framework. Cybersecurity analysts anticipate that other major Western AI providers will face similar explicit advisories in the coming months as audits continue. As the digital curtain falls heavier, the dream of a unified, borderless AI ecosystem is rapidly being replaced by a fractured landscape of regional models, each tethered to the geopolitical interests and data laws of its host nation.

Viewpoints in depth

Chinese Regulators' View

National security requires strict control over where corporate data is processed.

From the perspective of the Cyberspace Administration of China, the unchecked use of foreign AI models by domestic enterprises represents a massive vulnerability. Regulators argue that even if an AI company promises not to train on enterprise data, the mere transmission of proprietary code, internal memos, and strategic documents to servers in the United States violates the core tenets of the Data Security Law. They view mandatory local hosting and rigorous security audits as non-negotiable prerequisites for any software deeply integrated into the Chinese economy.

Multinational Enterprises' View

Fragmented AI regulations destroy the efficiency gains of unified global IT systems.

For Chief Information Officers at multinational corporations, the advisory is a logistical nightmare. Companies prefer to deploy a single, standardized AI architecture across their global operations to ensure consistency, streamline procurement, and maintain a unified knowledge base. Being forced to sever their Chinese branches from global Claude or OpenAI deployments means they must now vet, procure, and integrate separate domestic Chinese models. This bifurcation not only doubles the IT workload but also creates permanent silos between regional teams.

AI Developers' View

Centralized telemetry is a technical requirement for maintaining model safety and security.

Frontier AI labs argue that the data flows flagged by regulators are often essential for the safe operation of the models. Telemetry allows developers to monitor for abuse, patch jailbreak vulnerabilities in real-time, and ensure the system is functioning within its safety guardrails. Furthermore, the immense compute required to run models like Claude means that localized, on-premise deployment is technically unfeasible for most clients, necessitating cloud-based API architectures that inherently require data transmission.

What we don't know

  • Whether the CAC will begin issuing financial penalties to multinational corporations that fail to immediately disconnect their Chinese operations from US-based AI APIs.
  • If Anthropic will attempt to partner with a domestic Chinese cloud provider to offer a localized, compliant version of Claude, similar to strategies used by Apple and Tesla.
  • How this advisory will impact the broader negotiations between the US and China regarding global AI safety standards.

Sources

Source coverage

2 outlets

3 viewpoints surfaced

Data Sovereignty Advocates 40%Global Enterprise Operators 35%Frontier AI Developers 25%
  1. [1]ReutersGlobal Enterprise Operators

    China issues security advisory on Anthropic's Claude over data flows

    Read on Reuters
  2. [2]BloombergGlobal Enterprise Operators

    Anthropic faces setback in Asia as Beijing flags Claude data risks

    Read on Bloomberg
Stay informed

Every angle. Every day.

Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.