For most of this year, the loudest AI-sovereignty complaints have run in one direction: China accusing the US of trying to preserve technological dominance. This week the complaint runs the other way. China's own internet regulator, the Cyberspace Administration of China, is investigating two of the country's own AI labs, DeepSeek and Moonshot, over allegations that they secretly routed user requests, including sensitive police and state-linked data, through Anthropic's Claude.
What Anthropic Alleged
The investigation traces back to a 154-page threat intelligence report Anthropic published September 10, which named seven Chinese companies, DeepSeek, Moonshot, Alibaba, Zhipu, SenseTime, MiniMax, and Xiaomi, in connection with what Anthropic characterized as large-scale unauthorized use of Claude. The specific allegation against DeepSeek: The company routed more than 12.1 million exchanges to Claude over a 14-day period in July, with some users reportedly believing they were interacting with DeepSeek's own model the entire time. Moonshot's alleged conduct involved a large volume of routed exchanges over several months, some of it reportedly funneled through thousands of accounts that appeared fraudulent, most traced to Singapore and Japan rather than China.
Anthropic's own framing for this practice is illicit distillation, using a competitor's model outputs to improve your own model cheaply, and the company said the pattern was likely inconsistent with applicable privacy laws.
Why Beijing Cares About This Specifically
The Cyberspace Administration initially summoned representatives from all seven named companies before narrowing its focus specifically to DeepSeek and Moonshot. According to The Information's reporting, the regulator's core concern isn't user privacy in the abstract, it's whether sensitive Chinese police, military, and state-linked corporate data ended up inside a US AI system as a side effect of the routing.
CAC officials reportedly visited company offices directly to interview executives and employees and gauge the severity of the potential breach, and regulators are specifically weighing whether the conduct violated China's rules governing data moving across its borders.
The Timing Isn't a Coincidence
This is unfolding just ahead of a planned meeting between President Trump and Chinese President Xi Jinping, where the two governments are reportedly discussing a potential AI incident-reporting mechanism between the countries. A domestic Chinese investigation into cross-border data exposure, arriving right before that meeting, gives Beijing a concrete example to point to in any conversation about AI-related data risk, one that doesn't require accusing the US of anything since the exposure was allegedly caused by China's own companies.
What This Means If You Use These Models
- If your organization routes any workload through DeepSeek's or Moonshot's APIs, this is a reasonable moment to ask both vendors directly whether your requests were ever forwarded to a third-party model, and what their current policy is on outbound routing.
- This isn't a US-versus-China story alone. Any AI vendor, anywhere, that quietly routes requests through a competitor's model to fill capability gaps creates the same blind spot: You may not know whose infrastructure is actually processing your data.
- Watch whether the CAC's investigation produces public penalties or just quiet internal changes. A regulator willing to discipline its own national champions over this would be a meaningfully different signal than one that settles it privately.
Sources: AI Pulse · Compliance Watch · workplaceai.ai. The CAC investigation: The Information, as reported by Bloomberg, Yahoo Finance, and Cryptopolitan, September 22, 2026. Anthropic's original threat intelligence report and specific allegations: Gizmodo and AnalyticsInsight, both September 22, 2026. The Public Security Bureau detail: South China Morning Post, as reported by aiweekly.co. Context on the Trump-Xi meeting and AI incident-reporting discussions: Stocktwits, citing The Information. Every figure and detail above is attributed to its original reporting; none is a WorkplaceAI study.