China’s internet regulator has opened a formal investigation into AI companies DeepSeek and Moonshot AI following accusations from Anthropic that both firms secretly routed sensitive user queries — including data potentially linked to Chinese police, military, and state-owned enterprises — to Anthropic’s Claude models without those users’ knowledge.

The probe, first reported by The Information, marks a striking role reversal: Beijing is now using Anthropic’s own security findings to scrutinize two of its most prominent domestic AI labs.

What Triggered the Investigation

The inquiry traces back to a 154-page threat intelligence report Anthropic published on September 10, covering misuse activity the company says it identified between December 2025 and August 2026. The report accused seven China-based AI labs — Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai), MiniMax, SenseTime, and Xiaomi — of engaging in what Anthropic termed “illicit distillation”: using Claude’s outputs as training material to improve their own, smaller AI models.

Anthropic was careful to clarify that distillation itself is a widely accepted and legitimate technique in AI development. Its specific objection centered on how the practice was allegedly carried out — through fraudulent accounts used to route enormous volumes of queries through Claude while disguising the true origin and purpose of the requests.

The Scale of the Activity

According to Anthropic’s report, the combined distillation activity across all seven named companies totaled approximately 190 million exchanges with Claude. The volume was heavily concentrated: Alibaba alone accounted for more than 151 million of those interactions, logged between May and July, making it by far the largest single contributor to the activity Anthropic identified. Moonshot AI followed with more than 23 million exchanges over the same period, while DeepSeek was linked to over 12 million interactions concentrated within a 14-day window in July.

Despite Alibaba representing the largest volume of flagged activity, China’s Cyberspace Administration (CAC) has notably not made Alibaba a focus of its investigation. The regulator initially summoned representatives from all seven companies named in Anthropic’s report, but subsequently narrowed its inquiry specifically to DeepSeek and Moonshot.

The Detail That Changed Everything: Real User Data, Not Just Training Requests

What elevated this from a routine intellectual-property dispute into a matter of Chinese national security concern was a more specific allegation buried within Anthropic’s findings. According to the company, Moonshot in at least some documented cases forwarded to Claude not just synthetic prompts generated for model training, but genuine, real-time requests submitted directly by users of Kimi, Moonshot’s consumer-facing chatbot — without those users being informed their query was actually being processed by an American company’s AI system.

In one case detailed in Anthropic’s report, a user the company believes may be connected to China’s People’s Liberation Army allegedly submitted data through Kimi originating from a surveillance camera network in Chengdu, reportedly tracking an individual’s movements across hundreds of cameras — some located near PLA facilities and defense research institutions. Separately, Anthropic said queries routed through DeepSeek to Claude included requests from engineers developing a public security system for a Chinese municipal government, involving processing of citizens’ movement data tied to national identification numbers.

Why Beijing Is Taking This So Seriously

For American observers, the primary concern surrounding Anthropic’s report has centered on whether Chinese firms improperly obtained the capabilities of a leading U.S. AI model. For Chinese regulators, however, the far more urgent issue is different: if Anthropic’s allegations are accurate, sensitive data belonging to Chinese citizens, government bodies, police, and state enterprises may have been transmitted to servers operated by a U.S. company — a scenario that could violate China’s strict domestic rules governing cross-border data transfers, particularly for information touching on national security or state-linked institutions.

According to The Information’s sourcing, CAC officials have visited the offices of both DeepSeek and Moonshot to directly question executives and staff, seeking to determine precisely how Claude was used and how much sensitive information may have crossed into U.S.-based systems. The investigation remains ongoing, and the CAC has not announced any timetable for its conclusion or indicated whether penalties will ultimately be imposed on either company. Neither DeepSeek nor Moonshot has issued a public comment on the allegations.

Uncomfortable Timing for Both Companies

The investigation arrives at a particularly inconvenient moment for both firms. DeepSeek is scheduled to brief the United Nations Security Council this week on AI-related risks during the UN General Assembly session — reportedly sharing a platform with Anthropic CEO Dario Amodei even as Chinese regulators scrutinize DeepSeek’s own data practices. Moonshot faces a separate complication: the company recently filed confidentially for a Hong Kong initial public offering targeting approximately $3 billion, and an active, undisclosed regulatory investigation is precisely the kind of material development that would typically need to be disclosed in any IPO prospectus.

A Broader U.S.-China AI Backdrop

The investigation is unfolding against the backdrop of high-level diplomatic engagement between Washington and Beijing, coinciding with discussions around a potential U.S.-China “AI dialogue” mechanism — a proposed framework under which the two governments would notify each other about AI-related incidents carrying national security implications. The timing underscores how AI governance, data sovereignty, and model security have become intertwined with broader geopolitical negotiations between the two countries, even as their leading AI labs remain locked in intense technical competition.

What Happens Next

With the CAC’s investigation still active and no penalty determination yet made, the coming weeks are likely to clarify both the scope of data that may have crossed into Claude’s systems and whether Chinese regulators will impose consequences on DeepSeek or Moonshot specifically. For the broader AI industry, the episode illustrates a novel enforcement dynamic: a leading U.S. AI lab’s own security and abuse-detection findings being repurposed by a foreign government to investigate domestic companies for potential violations of that same country’s data protection laws — a pattern that may become increasingly common as AI models trained by rival national ecosystems continue to interact, intentionally or not, across borders.