13 Revisions and No Warrant: China's CCTV Affiliate X-Rays Anthropic's Privacy Record
CCTV-linked Yuyuantantian counts 13 privacy-policy revisions, data transfers to the US, and intelligence ties — the latest volley in AI's geopolitics.
On September 19, 2026, an account affiliated with China Central Television published a detailed takedown of Anthropic’s data practices. The target was not Claude’s capabilities but its paperwork: a privacy policy revised thirteen times since 2023, quietly expanded data-collection categories, and clauses that — in Beijing’s reading — turn a commercial AI service into an arm of American intelligence.
The post came from Yuyuantantian (玉渊潭天), the influential social-media outlet tied to CCTV that has become one of China’s preferred channels for signaling official displeasure without a formal ministry statement. Its timing was pointed: Washington and Beijing are preparing for trade talks, with a meeting between President Xi Jinping and President Donald Trump expected to anchor the agenda. AI has moved from technical appendix to headline issue in that relationship, and the Yuyuantantian post reads as a pre-negotiation positioning of grievances.
What the post actually alleges
The account’s case rests on a close reading of Anthropic’s public documents, and the specifics are worth laying out.
Thirteen revisions since 2023. Yuyuantantian counts 13 privacy-policy changes over roughly three years — a pace that makes meaningful user consent nearly impossible. Each revision is notified in passing; no user can reasonably track what has shifted between versions.
Cross-border data transfers. According to the post, the policy now includes provisions to transfer data from users in Canada, Brazil, South Korea, and the European Union to the United States. For jurisdictions with strict data-localization or transfer rules, this is the sharpest legal edge of the complaint.
Data sources tripled, then doubled. Anthropic’s declared data sources expanded from three to six between June 2024 and September 2025, the post says. Then, in September 2025, the company changed its model-training terms so that user data is used for training by default — an opt-out model rather than opt-in.
Sharing with intelligence agencies. The post cites an Anthropic report saying the company shares “technical indicators” with relevant intelligence agencies after alleging that some Chinese companies engaged in model-distillation activity — that is, using Claude’s outputs to train rival models. And it notes that two of three threat-intelligence job postings at Anthropic preferred candidates who spoke Mandarin or Russian, had government or military intelligence-analysis experience, and held top-secret US clearance.
The context Beijing is working from
The sharpest single allegation lands on the June 2026 policy revision. As reported at the time, Anthropic updated its consumer privacy policy on June 8, 2026 — effective July 8 — to permit sharing user conversation data with law enforcement based on an internal “good faith belief” that it is necessary, without waiting for legal process. The old policy shared data only when legally required. That shift sparked a sustained backlash on Reddit and elsewhere when users noticed it, and it is precisely the clause Yuyuantantian now amplifies to a global audience: sharing “when the company considers it necessary without legal procedures.”
There is also a documented trajectory behind the distillation claim. Anthropic said it secretly tracked Claude Code users in China through an anti-distillation tracker, removed the code in early July 2026 after a security researcher exposed it, and days later Beijing’s Ministry of Industry and Information Technology warned companies off Claude Code over “backdoor” risks in versions 2.1.91 to 2.1.196 — risks Anthropic said were simply its anti-distillation telemetry. In September, Anthropic published its most detailed threat-intelligence report to date, covering state-backed surveillance operations it disrupted, including operations it attributed to Chinese actors. Each of those episodes hardened the mutual narrative: Washington sees industrial theft; Beijing sees surveillance infrastructure embedded in a consumer product.
Why this matters beyond the spat
Three consequences worth taking seriously, whichever side of the Pacific you sit on.
First, privacy policy has become geopolitics. A clause change in a consumer terms-of-service document is now quoted in state-media broadcasts and weighed in leader-level diplomacy. Every frontier lab is de facto writing foreign policy when it drafts data-transfer language. Expect regulators in the EU, Korea, Brazil, and Canada — the exact jurisdictions Yuyuantantian names — to read the same clauses with their own enforcement lens.
Second, the “safety company” framing is under strain. Anthropic’s brand was built on responsibility and transparency. Its own transparency products — the threat-intelligence reports, the system-trust disclosures — are now being used against it, cited line by line as evidence of intelligence entanglement. Transparency cuts both ways, and adversaries will archive every revision.
Third, the trust-decay loop is symmetric. Chinese users were never Anthropic’s market in any official sense; the company said as much when it noted Chinese users were never authorized to use Claude Code. But the audience for this post is not only Chinese. It is every government and enterprise in a third country deciding whose models to procure. If both American and Chinese AI suppliers are framed as instruments of the other’s state, the result is a bifurcated market — with data-localization requirements and procurement blacklists hardening on both sides.
What to watch
The immediate question is whether a Chinese regulator follows the media signal with a formal action — as MIIT did after the July Claude Code disclosures. The bilateral track matters too: if the Xi–Trump meeting produces any AI working group, data-sharing clauses of this kind are exactly the grist it would process. And for Anthropic specifically, the EU dimension may bite hardest: the named transfer provisions invite scrutiny under GDPR’s adequacy and standard-contractual-clause framework, and European regulators have shown little hesitation on AI data practices this year.
For users, the practical upshot is simpler. A privacy policy that changes thirteen times in three years, trains on your data by default, and shares with authorities on internal judgment is no longer a policy — it is a standing negotiation you were never invited to. Yuyuantantian’s numbers may serve Beijing’s interests, but the underlying documents are public, and they say what they say.
Sources
- [1] https://www.bloomberg.com/news/articles/2026-09-19/china-state-tv-affiliate-flags-anthropic-data-and-privacy-risks
- [2] https://www.straitstimes.com/asia/east-asia/china-state-tv-affiliate-flags-anthropic-data-and-privacy-risks
- [3] https://www.anthropic.com/threat-intelligence-report-september-2026
- [4] https://privacy.claude.com/en/articles/10301952-updates-to-our-privacy-policy