The Pulse
China Probes DeepSeek and Moonshot Over User Data Sent to Anthropic
China’s cyberspace regulator is investigating DeepSeek and Moonshot after Anthropic alleged that customer requests were silently routed to Claude.

AI.info Team ·
China’s Cyberspace Administration is investigating DeepSeek and Moonshot AI over user data that may have reached Anthropic’s servers without customers’ knowledge, according to Quartz, which cited reporting by The Information. Officials visited both firms to question executives and staff. The investigation is ongoing, and the regulator has not announced penalties or a timetable.
The inquiry followed a 154-page threat-intelligence report that Anthropic published on September 10, 2026. Anthropic accused seven China-based AI companies of routing requests through Claude to collect its outputs for model training. The companies named were Alibaba, Moonshot AI, DeepSeek, Zhipu, MiniMax, Xiaomi and SenseTime.
According to Quartz, the Cyberspace Administration summoned representatives from all seven companies before narrowing its focus to DeepSeek and Moonshot. Anthropic’s complaint concerns illicit distillation: using a more capable model to generate material that can be used to train or improve another model. The regulator’s concern is different. It is examining whether Chinese users’ prompts and other data were sent to an American company without their awareness, potentially implicating Chinese data-security rules.
Moonshot’s Kimi Requests
Anthropic says Moonshot, the company behind the Kimi family of models, silently forwarded some customer requests to Claude instead of processing them with Kimi. Users allegedly received Claude’s responses while believing they were using a Kimi model.
Anthropic reported that, during one 10-day period, Moonshot relayed almost 300,000 customer requests to Anthropic, most of them routed to Claude’s Opus model. The report also said Moonshot used a proxy network involving 5,380 fraudulent accounts, most of which appeared to be located in Singapore and Japan.
The report identified sensitive information in some of the relayed requests. One case involved a user Anthropic assessed as likely affiliated with the People’s Liberation Army who used Kimi to examine surveillance footage of a single individual collected from hundreds of cameras in Chengdu. Some cameras were outside PLA facilities, institutes affiliated with the China Electronics Technology Group Corporation and a major state-owned enterprise.
In a separate Moonshot case, an engineer used Kimi to build an internal system for a major Chinese state-owned enterprise. The engineer’s requests exposed internal code and live credentials from several major Chinese companies. Anthropic said the user had no way of knowing that the requests were being forwarded to Claude.
Anthropic estimated that Moonshot sent more than 23 million exchanges through Claude between May and July 2026. It said Moonshot saved at least some of those exchanges and built a pipeline to extract Claude’s reasoning transcripts for model training.
DeepSeek’s Routing Activity
Anthropic said DeepSeek used similar methods, silently relaying some customer exchanges to Claude and targeting Claude’s reasoning traces. DeepSeek reportedly identified users attempting to access its models through third-party or Anthropic coding harnesses, including Claude Code, the Claude Agent SDK and OpenCode. Selected requests were then relayed to Claude Opus.
One example involved an employee of a Chinese technology company who used what they believed was DeepSeek to analyze internal documentation. Anthropic said the relayed material included the full specifications, organizational structure and strategic objectives of a major artificial-intelligence program.
In a separate case, DeepSeek relayed requests from an information-technology operator working with data from a Russian government agency associated with the country’s Ministry of Defense. The requests exposed live credentials for a Russian government database.
Anthropic separately described a Chinese police-surveillance case involving engineers who were building a case-management system for a municipal Public Security Bureau. The engineers used DeepSeek while developing a tool that compared a person’s movements with police records containing citizens’ national identification numbers.
Anthropic said DeepSeek generated more than 12.1 million exchanges over 14 days in July 2026. The company also said DeepSeek used a cross-session replay technique to recover reasoning transcripts that Claude normally returns only as a protected reference.
What the Inquiry Could Determine
Quartz reported that the Cyberspace Administration has not said whether DeepSeek or Moonshot will face sanctions. It also has not explained why Alibaba is not currently the focus of the inquiry, even though Anthropic attributed more than 151 million exchanges to Alibaba in the same report.
The regulator’s investigation does not resolve Anthropic’s broader allegations about model training. It does, however, raise a separate question for users: whether an AI product handled a request through the model identified in its interface or silently sent it to an overseas provider.
Anthropic’s report describes allegations rather than findings by Chinese authorities. The Cyberspace Administration has not released its own account of the suspected routing, and no penalties have been announced.