China Probes DeepSeek and Moonshot Over Routing Sensitive User Data to Anthropic's Claude
China's Cyberspace Administration is investigating domestic AI startups DeepSeek and Moonshot AI over allegations that they covertly routed sensitive user data to US-based Anthropic.
By Tariq Nasser
- Chinese Regulators
- Focused on enforcing strict cross-border data transfer laws and preventing state secrets from reaching foreign servers.
- US AI Developers
- Concerned with protecting intellectual property and preventing foreign competitors from distilling their frontier models.
- Privacy Advocates
- Alarmed by the deceptive routing of user prompts to third-party servers without explicit consent or zero-data-retention guarantees.
Perspectives this story doesn't cover
- End users whose data was routed without consent
- Third-party model routing service providers
Fast facts
- China's internet regulator is actively investigating AI startups DeepSeek and Moonshot over cross-border data transfers.
- The probe stems from an Anthropic report alleging the companies routed millions of user requests to its Claude model.
- Regulators are concerned that sensitive data, including surveillance footage near military sites, reached US servers without user consent.
- Anthropic claims Moonshot routed over 23 million exchanges and DeepSeek routed 12.1 million exchanges to Claude.
- The investigation complicates Moonshot's planned $3 billion IPO and DeepSeek's upcoming UN Security Council briefing.
Why this matters
This investigation exposes a critical vulnerability in the global AI supply chain: how easily sensitive national and corporate data can cross borders when local developers secretly route user prompts to foreign models to boost their own performance.
The Cyberspace Administration of China has escalated its scrutiny of domestic artificial intelligence developers, dispatching officials to question executives at DeepSeek and Moonshot AI over allegations that the startups covertly routed sensitive Chinese user data to US-based Anthropic. The regulatory intervention transforms what began as a corporate dispute over intellectual property into a formal national security probe regarding cross-border data flows.[1][2][3][4][5]
The investigation centers on the mechanics of how DeepSeek and Moonshot operate their respective AI assistants. According to a 154-page threat intelligence report published by Anthropic on September 10, 2026, the Chinese firms engaged in "illicit distillation"—a process where a company silently forwards user prompts to a more capable competitor model, in this case Claude, and uses the returned outputs to train its own systems. While Anthropic's primary grievance was the unauthorized extraction of its model's capabilities, Beijing's concern focuses entirely on the data traveling in the opposite direction.[1][2][3]
Chinese regulators are specifically examining whether the routing mechanisms exposed restricted state and corporate information to American servers without user consent. Anthropic's report detailed instances where the data passed to Claude included highly sensitive material. In one cited example, Moonshot allegedly forwarded surveillance footage captured by hundreds of cameras in Chengdu, including feeds located near People's Liberation Army facilities.[1][2][5]
DeepSeek faces similar scrutiny over its handling of law enforcement data. Anthropic claims that DeepSeek relayed requests from engineers developing a police surveillance case management system, inadvertently exposing live credentials connected to a Russian government database. Anthropic's report noted that the routed sessions "contained names, email addresses, company data, and other sensitive data of hundreds of end users," adding that the practices "are likely inconsistent with privacy laws."[1][5]
DeepSeek faces similar scrutiny over its handling of law enforcement data.
The sheer volume of the alleged routing is substantial. Anthropic reported observing over 23 million exchanges linked to Moonshot between May and July 2026. DeepSeek allegedly routed more than 12.1 million exchanges over a concentrated 14-day window in July 2026. In both cases, users submitting prompts to the Chinese platforms were reportedly unaware that their requests were being processed by an American AI system.[1][2][5]
The Cyberspace Administration initially summoned representatives from all seven Chinese companies named in Anthropic's report—which also included Alibaba, Zhipu, MiniMax, Xiaomi, and SenseTime—before narrowing its active investigation to DeepSeek and Moonshot. The regulatory action arrives at a delicate time for both firms. Moonshot has reportedly filed confidentially for a $3 billion initial public offering in Hong Kong, a process that requires the disclosure of active regulatory probes.[1][3][4]
DeepSeek is scheduled to brief the United Nations Security Council this week on the international security risks posed by artificial intelligence, while Moonshot navigates the disclosure requirements for its planned public offering. The Cyberspace Administration's active presence at both headquarters marks the first major test of how Beijing will enforce its cross-border data laws against the widespread industry practice of third-party model routing.[3][5]
The probe also highlights the technical reality beneath the marketing claims of sovereign AI development: relying on third-party model routers can easily bypass national data controls, leaving end users and regulators scrambling to map where data actually flows.[5]
Sources
[1]TechRepublicUS AI DevelopersChina Reportedly Probes DeepSeek, Moonshot Over Claude Data Routing
Read on TechRepublic →
[2]GizmodoUS AI DevelopersChina Probes DeepSeek, Moonshot AI Over Anthropic's Claims They Route Requests to Claude
Read on Gizmodo →
[3]The News InternationalChinese RegulatorsChinese regulator probes DeepSeek and Moonshot over secret data routing
Read on The News International →
[4]Investing.comChinese RegulatorsChina regulator probes DeepSeek and Moonshot AI over data routing - Information
Read on Investing.com →
[5]DecryptPrivacy AdvocatesChina Probes DeepSeek and Moonshot Over Alleged Data Leaks to Anthropic's Claude
Read on Decrypt →
Comments
More in Technology
See all →Orbital Milestone
FAA Grants Final License for Starship's First Orbital Flight and Starlink V3 Deployment
4 sources
Enterprise Security
Citrix Confirms Two Unpatched Zero-Day Vulnerabilities in NetScaler Under Active Exploitation
5 sources
OAuth Security
The Evidence Pack: How the New 'Umbrij' Malware Bypasses Passwords to Hijack Corporate Gmail
4 sources
AI Malware
AI Model DeepSeek Creates Working Browser-Native Ransomware by Abusing Chromium API
4 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




