Beijing Turns Inward: China's CAC Opens Probe Into DeepSeek and Moonshot Over Claude Data Flows
China's internet regulator is investigating whether DeepSeek and Moonshot routed sensitive user data — reportedly including police surveillance credentials — to Anthropic's Claude. It's the first time a Chinese AI lab's shortcut to a US frontier model has become a domestic data-security case.
For most of the past two years, the global AI story about China has run in one direction: Washington restricting chips, Beijing racing to catch up. On September 22, 2026, that story bent into an unfamiliar shape. According to The Information, the Cyberspace Administration of China (CAC) — the regulator that polices China’s internet and its data borders — has opened an investigation into DeepSeek and Moonshot AI over alleged unauthorized data flows to Anthropic, and has already questioned staff at both labs.
The irony is thick enough to cut with a knife. The same Chinese AI labs that Anthropic accuses of siphoning capability from Claude are now being investigated at home — not for stealing from a US company, but for potentially letting Chinese data leak outward to one.
What the probe is actually about
The CAC investigation follows Anthropic’s September 10 threat intelligence report, “Detecting and countering misuse of AI,” which alleged that Chinese AI labs systematically accessed Claude through fraudulent accounts and intermediate platforms. Two distinct patterns emerged from that disclosure.
The first is what Anthropic calls distillation: harvesting a frontier model’s outputs at scale to train a competitor. Anthropic’s report describes a CoT extraction pipeline attributed to DeepSeek, mirroring tactics it previously attributed to Moonshot — funneling prompts and chain-of-thought responses through networks of proxy accounts to build training corpora. The scale alleged in the September report is staggering: an Alibaba-affiliated campaign alone accounted for more than 151 million Claude exchanges between May and July 2026, at peaks of nearly three million exchanges per interval. A joint CISA advisory published September 8 went further, naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as having “likely with Chinese government awareness” extracted billions of tokens across US frontier models.
The second pattern is the one that matters to Beijing: routing. Anthropic alleges that DeepSeek and Moonshot secretly relayed selected real customer queries to Claude, then presented Claude’s answers to their own users as native model output. Those relayed queries weren’t anonymized. According to reporting around the disclosures, sensitive data flowed outward along with the prompts — and reportedly included credentials belonging to a Chinese police surveillance system.
That detail is what transforms the story from an intellectual-property dispute into a national-security case inside China. Under China’s Data Security Law and the Cybersecurity Law, transferring data collected within China to foreign entities without approval can be a violation in itself — regardless of intent. A Chinese AI lab piping domestic user prompts, and allegedly police-system credentials, to a San Francisco company’s servers is exactly the category of cross-border flow the CAC exists to stop.
Why now
The timing is not accidental. Anthropic’s threat report landed on September 10. Within days, US media — the Wall Street Journal, CNBC, SCMP — had amplified the routing allegations globally, complete with the claim that real Chinese user queries had been delivered to an American frontier model. From Beijing’s perspective, that is a worst-case narrative: Chinese national champions secretly dependent on US infrastructure, and Chinese data flowing west through the back door while the government touted AI self-reliance.
The CAC probe also lands on labs that Beijing has reasons to protect. Moonshot AI, the company behind the Kimi model family, confidentially filed for a Hong Kong IPO earlier this month, reportedly seeking a valuation of up to $5 billion. DeepSeek, whose V-series and R-series models made it the symbol of China’s efficient frontier push, is the flag-bearer of the open-weights movement. An adverse finding against either would be diplomatically awkward and commercially painful — which is precisely why the regulator moving against them anyway signals that the data-sovereignty issue is being treated as non-negotiable.
The sovereignty trap
Strip away the geopolitics and the structural problem is simple: Chinese labs wanted frontier capability faster than they could build it, and the fastest path ran through US models. Every relayed query was simultaneously a competitive shortcut (in Washington’s framing) and an unapproved export of Chinese data (in Beijing’s). The labs are now squeezed between two regulatory regimes that both treat the same activity as a violation — one side calling it theft, the other calling it a leak.
For Anthropic, the CAC probe is an unexpected form of vindication. The company spent months building the detection infrastructure behind its threat reports — identifying fraudulent account networks, measuring exchange volumes, naming labs publicly. Its stated goal was deterrence and policy attention in Washington. Getting enforcement attention in Beijing was not on the menu. If the CAC investigation produces penalties, restructuring, or mandated disclosures at DeepSeek or Moonshot, US labs will have achieved through disclosure what export controls and lawsuits could not: making unauthorized distillation carry a domestic cost for the companies doing it.
There is also a darker reading. A CAC probe brings staff questioning, data access for investigators, and potential influence over how these labs operate going forward. If the outcome is tighter state supervision of China’s most independent AI labs, the winners are not necessarily the US companies whose IP was taken — it is the Chinese state’s security apparatus, now handed a pretext to embed itself deeper in the sector.
What to watch
Three signals will tell us where this goes. First, whether the CAC confirms the probe publicly and under what legal provision — an announcement under the Data Security Law would put every Chinese AI company on notice that model-to-model routing through foreign APIs is now a regulated act. Second, whether Moonshot’s IPO timeline survives; a delay or downsizing would be the market’s read on regulatory risk. Third, whether Anthropic’s next threat report credits Chinese enforcement action — a small detail that would mark the first time the two governments’ AI interests visibly aligned, even if by accident.
The deeper lesson cuts both ways. Data sovereignty and intellectual property are converging into a single question: who is allowed to learn from whom. Washington answers with chip controls and criminal referrals; Beijing now answers with regulator visits. The labs caught in between built their strategies on the assumption that model outputs were a free commons. September’s events — the CISA advisory, Anthropic’s report, and now a Chinese investigation — suggest that commons is being fenced from both directions at once.
For users of DeepSeek and Moonshot products, the immediate stakes are more concrete. If the routing allegations are true, some fraction of their prompts traveled to US servers they never chose, processed by a company they never contracted with — and now sit in the middle of a cross-border criminal-adjacent inquiry. Trust, once routed through someone else’s model, is very hard to route back.
Sources
- [1] https://www.theinformation.com/articles/china-probes-deepseek-moonshot-potential-data-leaks-anthropic
- [2] https://www.anthropic.com/threat-intelligence-report-september-2026
- [3] https://www.wsj.com/tech/ai/chinese-ai-giants-accused-of-sending-millions-of-user-queries-to-u-s-models-768c9d26
- [4] https://www.cnbc.com/2026/09/11/chinese-ai-labs-moonshot-deepseek-alibaba-anthropic.html
- [5] https://www.scmp.com/news/us/diplomacy/article/3367112/moonshot-deepseek-secretly-routed-user-requests-claude-anthropic-claims
- [6] https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a