For most of this year, the loudest AI-sovereignty complaints have run in one direction: China accusing the US of trying to preserve technological dominance. This week the complaint runs the other way. China's own internet regulator, the Cyberspace Administration of China, is investigating two of the country's own AI labs, DeepSeek and Moonshot, over allegations that they secretly routed user requests, including sensitive police and state-linked data, through Anthropic's Claude.

7
Chinese AI companies named in Anthropic's original report, before the CAC narrowed its focus to two
12.1M
Exchanges Anthropic says DeepSeek routed to Claude in a 14-day window in July
0
Penalties announced so far, the investigation is still active

What Anthropic Alleged

The investigation traces back to a 154-page threat intelligence report Anthropic published September 10, which named seven Chinese companies, DeepSeek, Moonshot, Alibaba, Zhipu, SenseTime, MiniMax, and Xiaomi, in connection with what Anthropic characterized as large-scale unauthorized use of Claude. The specific allegation against DeepSeek: The company routed more than 12.1 million exchanges to Claude over a 14-day period in July, with some users reportedly believing they were interacting with DeepSeek's own model the entire time. Moonshot's alleged conduct involved a large volume of routed exchanges over several months, some of it reportedly funneled through thousands of accounts that appeared fraudulent, most traced to Singapore and Japan rather than China.

Anthropic's own framing for this practice is illicit distillation, using a competitor's model outputs to improve your own model cheaply, and the company said the pattern was likely inconsistent with applicable privacy laws.

Why Beijing Cares About This Specifically

The Cyberspace Administration initially summoned representatives from all seven named companies before narrowing its focus specifically to DeepSeek and Moonshot. According to The Information's reporting, the regulator's core concern isn't user privacy in the abstract, it's whether sensitive Chinese police, military, and state-linked corporate data ended up inside a US AI system as a side effect of the routing.

The Detail That Escalated ThisPer the South China Morning Post's reporting on Anthropic's findings, engineers working on a case-management system for a municipal Public Security Bureau, a local Chinese police agency, reportedly sent data to Claude that was used to compare an individual's movements against police records. If accurate, that means law-enforcement-sensitive Chinese government data may have passed through a US company's servers without anyone at the police bureau necessarily knowing.

CAC officials reportedly visited company offices directly to interview executives and employees and gauge the severity of the potential breach, and regulators are specifically weighing whether the conduct violated China's rules governing data moving across its borders.

The Timing Isn't a Coincidence

This is unfolding just ahead of a planned meeting between President Trump and Chinese President Xi Jinping, where the two governments are reportedly discussing a potential AI incident-reporting mechanism between the countries. A domestic Chinese investigation into cross-border data exposure, arriving right before that meeting, gives Beijing a concrete example to point to in any conversation about AI-related data risk, one that doesn't require accusing the US of anything since the exposure was allegedly caused by China's own companies.

The irony is worth sitting with directly. Much of this year's AI-sovereignty rhetoric, on both sides, has assumed the risk runs one direction, one country's models threatening another's data or market position. This case shows the same exposure can happen through ordinary commercial shortcuts entirely within a company's own competitive pressure to keep up, with no state actor directing it at all.

What This Means If You Use These Models

Sources: AI Pulse · Compliance Watch · workplaceai.ai. The CAC investigation: The Information, as reported by Bloomberg, Yahoo Finance, and Cryptopolitan, September 22, 2026. Anthropic's original threat intelligence report and specific allegations: Gizmodo and AnalyticsInsight, both September 22, 2026. The Public Security Bureau detail: South China Morning Post, as reported by aiweekly.co. Context on the Trump-Xi meeting and AI incident-reporting discussions: Stocktwits, citing The Information. Every figure and detail above is attributed to its original reporting; none is a WorkplaceAI study.