← All posts / Policy

Beijing Turns Inward: China's Regulator Probes DeepSeek and Moonshot Over Data That Reached Claude

China's CAC has opened a data-security probe into DeepSeek and Moonshot AI after Anthropic's 154-page threat report alleged the labs routed sensitive Chinese police, military and corporate data to Claude — and Chinese AI stocks sold off on the news.

Beijing Turns Inward: China's Regulator Probes DeepSeek and Moonshot Over Data That Reached Claude

The strangest regulatory story of the AI year has an unusual protagonist: a Chinese regulator investigating Chinese AI champions — not for copying American models, but for allegedly sending Chinese data to one.

On September 22, The Information reported that the Cyberspace Administration of China (CAC), the country’s powerful internet regulator, has opened a data-security probe into DeepSeek and Moonshot AI, the two most internationally prominent Chinese AI startups. The trigger was not a domestic complaint but a foreign document: Anthropic’s 154-page threat intelligence report published on September 10, which alleged that seven Chinese AI companies had used fraudulent accounts at industrial scale to extract outputs from Claude — and, in the process, routed massive volumes of their own users’ data onto Anthropic’s servers in the United States.

Beijing’s concern, according to people with knowledge of the matter, is the direction of the flow. Anthropic’s report described cases where DeepSeek and Moonshot forwarded Chinese users’ requests — including sensitive material like police security-camera footage — to Claude without those users’ knowledge. The CAC is now examining whether data involving Chinese police, military, and state-linked companies was transferred to US models in violation of China’s Data Security Law, the sweeping 2021 statute that treats certain categories of data as subject to state control the moment they cross a border.

How a US threat report became a Chinese enforcement action

The sequence is worth tracing, because it is almost certainly a template.

On September 8, the NSA, CISA, and FBI published a joint advisory (AA26-251A) naming six China-based AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — and accusing them of distilling billions of tokens from Claude, GPT, Gemini, and Grok since late 2024. Two days later, on September 10, Anthropic published its own account: a 154-page threat intelligence report documenting what its team had disrupted over the previous eight months. The report alleged that Chinese labs ran roughly 200 million exchanges through Claude using more than 24,000 fraudulent accounts, with DeepSeek, Moonshot, and MiniMax named as the heaviest users. Engineers building a case-management system for a municipal Public Security Bureau in China, the report noted, used DeepSeek — which relayed those requests to Claude.

Washington’s framing was intellectual property theft. Beijing read the same document and saw something else entirely: evidence that some of its most sensitive data — policing, military, state-owned enterprise traffic — had been flowing to an American AI company’s servers, carried there by its own national champions.

The CAC summoned representatives from all seven Chinese companies named in Anthropic’s report, then narrowed its focus to two. DeepSeek and Moonshot drew the scrutiny because of the nature of the data implicated, not merely the volume. Alibaba, which Anthropic’s report identified as running the larger extraction campaign by token count, is notably not the focus of the probe.

That asymmetry is the story’s sharpest edge. The heaviest alleged distiller is not the one being investigated for data leaks. Beijing, it appears, is not primarily mad that its labs copied Anthropic’s model — it is mad about what left the country in the process.

Markets noticed

The commercial impact was immediate. On September 23, Bloomberg reported that shares of Chinese AI model developers fell after The Information’s story, with Zhipu AI down as much as 12% and other AI-linked names declining 6.8% in Hong Kong trading. Fox Business’s Liz Claman led her show segment with the selloff; MarketVector’s Joy Yang framed it as the week’s defining data-security story for Chinese tech.

The timing could hardly be worse for the companies involved. Moonshot confidentially filed for a Hong Kong IPO earlier this month and is reportedly seeking a pre-IPO round at a $50 billion valuation; DeepSeek just crossed a $1 billion annualized revenue run rate and is reportedly in talks to raise at a steep markup. A CAC data-security probe is precisely the kind of open regulatory question that makes underwriters and late-stage investors recalculate. Neither company has publicly commented on the investigation.

The sovereignty inversion

Strip away the specifics and the structural point is this: data has become the gravitational center of the US-China AI contest, and it pulls in both directions at once.

From Washington’s perspective, Chinese labs distilling American frontier models is capability theft — a national-security advisory-level concern because it erodes the lead that justifies export controls on the chips those models are trained with. From Beijing’s perspective, the same traffic — Chinese police systems and military-adjacent enterprises querying DeepSeek, DeepSeek relaying to Claude — is a sovereignty breach under the Data Security Law’s logic that sensitive data belongs under Chinese jurisdiction wherever it travels.

Both governments are now enforcing against the same conduct, for opposite reasons, using the same evidence base: Anthropic’s server logs. A US AI company’s abuse report has become the factual foundation for a Chinese regulatory action against Chinese firms. Whatever else this is, it is a first.

It also completes a neat inversion of the usual pattern. For most of the past decade, the CAC’s data-security actions targeted foreign companies operating in China — Didi’s failed US listing and subsequent probe being the canonical case. Now the tool points inward, at companies Beijing has simultaneously been promoting as national AI champions. The dual identity — crown jewels on Monday, investigation targets on Tuesday — is the position DeepSeek and Moonshot find themselves in.

What comes next

The probe’s outcome matters beyond the two companies. If the CAC formalizes findings that routing user queries to foreign models constitutes a Data Security Law violation, every Chinese AI lab, app builder, and enterprise deploying models abroad faces a new compliance perimeter. The practical effect would push Chinese AI products toward domestic models for sensitive workloads — a result that would, ironically, reward the very companies Anthropic accused of distillation, by walling off their home market from foreign competitors.

For Anthropic, the probe is an unexpected vindication of its threat-intelligence posture. The company has been publishing misuse reports since 2025, and its September edition — with its granular account of fraudulent accounts and routing patterns — has now been cited by a US federal advisory and, apparently, acted on by China’s own regulator. That gives the reports a second audience their authors probably did not anticipate: the government of the country where much of the documented misuse originated.

And for the broader industry, the episode clarifies what “AI security” now means in practice. The threat model is no longer just prompt injection, jailbreaks, or model exfiltration. It is the mundane fact that every API call is a cross-border data transfer, and that the logs of those transfers — held by a frontier lab, published in a PDF — can trigger enforcement in either direction.

The probe is ongoing, and neither the CAC nor the companies involved have confirmed its scope. But the precedent is already visible: in the AI cold war, the most consequential intelligence agency may turn out to be a trust-and-safety team with a 154-page report.