Beijing Turns Inward: CAC Probes DeepSeek and Moonshot as Chinese AI Stocks Plunge
China's internet regulator has sent officials into DeepSeek and Moonshot AI over user data routed to Anthropic's Claude, sending Z.ai and MiniMax shares down as much as 12%.
For two years, the sharpest AI regulatory pressure on Chinese labs came from Washington — export controls, entity lists, and Justice Department indictments. This week the pressure arrived from the opposite direction. China’s Cyberspace Administration (CAC) has opened a formal data-security investigation into DeepSeek and Moonshot AI, the two startups behind the R1 and Kimi model families, after Anthropic alleged that both companies covertly routed sensitive Chinese user data to Claude models hosted on US servers.
The market reaction was immediate and brutal. On Wednesday, Hong Kong-listed shares of Z.ai fell as much as 12% and MiniMax Group dropped as much as 6.8%, dragging the broader universe of Chinese AI model developers lower. Bloomberg Law and the Seoul Economic Daily reported Zhipu AI (Z.ai’s parent) down around 12% at the lows. The Information first broke the news of the probe on September 22; by the Asian session on September 23, the selloff was in full swing.
What the CAC is actually investigating
According to Bloomberg Law, the Cyberspace Administration has dispatched officials to the offices of both DeepSeek and Moonshot to interview senior executives and employees on site — a concrete, physical regulatory step, not a paperwork request. The focus is whether Chinese users’ data left the country and landed on Anthropic’s servers without their knowledge or consent.
The trigger is Anthropic’s fourth threat-intelligence report, a 154-page document published on September 10 that detailed what the company calls “distillation campaigns” — systematic attempts to extract Claude’s capabilities by harvesting its outputs at scale. Seven Chinese AI companies were named. Two of them, DeepSeek and Moonshot, stand accused of something more specific than bulk scraping: silently forwarding real Chinese user queries to Claude and passing the results back to users as if they came from their own models.
The details from the report are striking. Anthropic says Moonshot routed nearly 300,000 Kimi user requests to Claude Opus through roughly 5,380 intermediary accounts, harvesting Claude’s reasoning traces along the way. The South China Morning Post highlighted an even more sensitive slice: Anthropic’s report describes engineers working on a case-management system for a municipal Public Security Bureau who sent Claude data used to compare an individual’s movements against police records and national identification numbers.
That last detail explains why Beijing — not Washington — is now the aggrieved party. Chinese data-security and PIPL rules strictly govern the transfer of personal information and “important data” outside China. If a Chinese AI lab funneled citizen data, let alone police-linked records, to a US company’s servers, that is a domestic legal exposure of the first order, entirely separate from any US intellectual-property claim.
From Washington’s complaint to Beijing’s case
The irony is thick. When Anthropic’s report landed on September 10, the framing in Western media was IP theft: Chinese labs “cloning” American frontier models. A week later, the same document has become evidence in a Chinese regulatory action about data leaving China. The same facts, read through two different legal lenses, produce two different crimes — and the companies at the center are now squeezed from both sides.
There is also a sovereign-AI subtext that is hard to miss. Chinese regulators have spent two years pushing domestic models to replace foreign ones in government and enterprise deployments, partly on the argument that Chinese data must stay on Chinese infrastructure. If DeepSeek and Moonshot were quietly depending on Claude — routing live user traffic through thousands of intermediary accounts — then the “domestic” label on some of that capability becomes questionable. The CAC’s probe is, among other things, an audit of whether China’s model champions were as sovereign as advertised.
For Anthropic, the turn of events is double-edged. Its allegations are now being acted upon — but by the regulator of the accused, on data-protection grounds the company itself did not emphasize. And it raises an uncomfortable operational question for every US lab: when you publish telemetry showing that foreign users’ data transited your systems, you are simultaneously documenting a compliance problem in someone else’s jurisdiction.
Why the market read it as systemic
A 12% one-day drop for Z.ai — a company not itself named as a probe target — signals that investors priced in contagion, not just company-specific risk. Several threads drive that reading.
First, breadth of practice. Anthropic’s report described an industry-wide pattern: Alibaba’s campaign alone allegedly involved more than 151 million exchanges with Claude between May and July. If routing user traffic through frontier US models was a common shortcut for training data, synthetic data, or even live inference, then the CAC’s probe of two firms could expand to many more, and Hong Kong’s newly listed AI cohort (Moonshot and Z.ai both completed IPOs there this year) is the exposed layer.
Second, enforcement posture. Sending officials into offices to interview staff is a step beyond document requests. It suggests the CAC is building a case, not registering a concern. Chinese internet companies have long memories of what a full-throated CAC investigation can do to a business.
Third, the timing. This lands days after the White House reportedly accused Moonshot of distilling Anthropic’s Fable model for Kimi K3, and weeks after US advisories on Chinese distillation campaigns. Chinese AI firms now face synchronized scrutiny from both governments — one accusing them of stealing American IP, the other of leaking Chinese data.
What to watch
The probe’s scope will define the story. If it stays confined to the two named companies and concludes with fines and remediation orders, the sector will absorb the shock and move on — distillation will get more careful, and “model provenance” audits will become a standard part of Chinese AI compliance. If it widens to other labs named in Anthropic’s report, or to the intermediary API-routing platforms that made the traffic possible, the reckoning gets much bigger.
Watch also for the compliance ripple: Chinese AI vendors serving government and state-owned-enterprise customers may soon need to certify that no user request ever touches a foreign frontier model, even indirectly. That would be a meaningful commercial wall between the two AI ecosystems — one built not by export controls in Washington, but by data-protection enforcement in Beijing.
For now, the image of the week is inverted from the usual narrative: Chinese AI champions under formal investigation, their shares falling, and the catalyst a US lab’s own security telemetry. The race between the two AI ecosystems has produced plenty of irony, but rarely this concentrated.
Sources are listed in the article metadata. Market figures are intraday moves reported by Bloomberg, Yahoo Finance, and the Seoul Economic Daily on September 23, 2026.
Sources
- [1] https://www.theinformation.com/articles/china-probes-deepseek-moonshot-potential-data-leaks-anthropic
- [2] https://www.bloomberg.com/news/articles/2026-09-23/chinese-ai-firms-fall-on-report-of-deepseek-moonshot-probe
- [3] https://www.scmp.com/news/us/diplomacy/article/3367112/moonshot-deepseek-secretly-routed-user-requests-claude-anthropic-claims
- [4] https://aiweekly.co/alerts/chinas-cac-probes-deepseek-moonshot-over-claude-data-routing
- [5] https://en.sedaily.com/international/2026/09/23/china-probes-deepseek-moonshot-ai-chinese-ai-stocks-tumble
- [6] https://qz.com/china-deepseek-moonshot-anthropic-data-probe-092326