China Launches Investigation into Leading AI Labs Following Anthropic Data Leak Allegations

The Cyberspace Administration of China (CAC) has initiated a formal investigation into several prominent domestic artificial intelligence companies, most notably DeepSeek and Moonshot AI, following a contentious threat intelligence report published by the San Francisco-based AI research firm Anthropic. The regulatory probe, first reported by The Information, centers on allegations that these Chinese labs may have been silently relaying sensitive user data to Anthropic’s servers by routing customer queries through the Claude API, effectively bypassing user consent and violating stringent domestic data security protocols.
While the CAC has summoned all seven companies identified in the Anthropic report—including Zhipu AI, Xiaomi, SenseTime, and MiniMax—the focus has intensified on Moonshot AI and DeepSeek. Investigators have reportedly conducted interviews with staff members at these firms to determine the extent of the data traffic, though no formal penalties or administrative sanctions have been levied at this stage.
The Genesis of the Conflict: Anthropic’s September Report
The current regulatory friction originated on September 10, when Anthropic released a detailed threat intelligence assessment documenting a practice known as "model distillation" or unauthorized API relaying. According to the document, several China-based AI labs were processing customer requests by surreptitiously forwarding them to Anthropic’s Claude models.
Anthropic alleged that Moonshot AI, in particular, was masking these interactions, presenting the Claude-generated responses to its own users as if they had been produced by its proprietary Kimi model. The scale of the activity identified was significant: Anthropic claimed to have tracked over 23 million exchanges from Moonshot between May and July 2026. Furthermore, the report highlighted a sharp spike in activity, recording nearly 300,000 requests processed through 5,380 suspicious accounts within a single ten-day window.
While Anthropic’s primary grievance focused on the intellectual property implications of its models being used to train or augment competitors, the narrative has shifted dramatically as it reached the desk of Chinese regulators.
The Inversion of the Grievance
The tension has evolved into a paradoxical confrontation. Anthropic’s complaint was fundamentally an issue of intellectual property theft and unauthorized model usage—a concern about what was being extracted from its systems. Conversely, the CAC’s investigation is rooted in the sovereign security of Chinese data—a concern about what was being transmitted to the United States.
Beijing’s regulatory stance treats the unauthorized cross-border flow of data as a potential national security breach. By allegedly funneling queries through American-owned servers without notifying the end-users, these Chinese AI labs have inadvertently placed themselves in the crosshairs of the CAC’s strict data sovereignty laws. This distinction is critical; it suggests that China is not validating Anthropic’s claims of copyright infringement, but is instead leveraging the same evidence to identify potential lapses in domestic data compliance.
Allegations of Sensitive Data Exposure
The investigation gained momentum following reports of highly sensitive queries being routed through these platforms. According to reporting from The Information, one specific interaction involved a user suspected of being affiliated with the People’s Liberation Army (PLA). This user reportedly tasked Moonshot’s Kimi model with analyzing complex surveillance footage tracking an individual across hundreds of municipal cameras in Chengdu.
Crucially, this footage allegedly included areas surrounding defense-linked institutes and PLA facilities. If accurate, the transit of such data to an American server constitutes a severe violation of China’s cross-border data transfer regulations, which are among the most restrictive in the world.
While TNW has not independently verified the specific contents of the leaked intelligence document, the implications are profound. If these platforms are indeed serving as conduits for sensitive imagery to foreign-operated cloud infrastructure, the regulatory response will likely move beyond simple administrative questioning. The September report also noted that other relayed queries had inadvertently exposed live credentials linked to a Russian defense agency, further underscoring the risks associated with unauthorized API-hopping.
Chronology of Escalation
The timeline of these events reflects a rapidly deteriorating landscape for AI diplomacy between the U.S. and China:
- July 2026: Alibaba implements a ban on "Claude Code," citing concerns over potential backdoors and the unauthorized transfer of Chinese data to U.S.-based servers.
- September 9, 2026: A joint advisory from the U.S. NSA, FBI, and CISA identifies six Chinese firms suspected of AI distillation, which the Chinese Foreign Ministry dismisses as "unfounded" the following day.
- September 10, 2026: Anthropic publishes its threat intelligence report, naming seven Chinese labs and detailing the mechanics of the API relaying.
- September 22, 2026: The CAC confirms it has summoned the seven named companies for questioning.
- Late September 2026: DeepSeek prepares for its scheduled briefing at the United Nations Security Council, creating a high-stakes contrast between its international image and domestic regulatory scrutiny.
Broader Implications and Corporate Fallout
The timing of this investigation is particularly damaging for the companies involved. DeepSeek, which has positioned itself as a transparent and responsible actor in the global AI safety debate, is currently navigating the optics of presenting at the United Nations Security Council while under investigation by its own national regulator. The irony of lecturing the international community on AI risk while potentially failing to manage its own data integrity is not lost on industry observers.
Moonshot AI faces a different set of challenges. As the company moves toward a planned initial public offering (IPO) in Hong Kong, the specter of an ongoing regulatory investigation is a significant material risk that must be disclosed to potential investors. Regulatory uncertainty regarding data practices can suppress valuations and deter institutional interest.
Meanwhile, Zhipu AI, another company on the list, has faced separate, localized scrutiny. The company recently faced public backlash after a developer discovered that its ZCode tool was uploading encrypted snapshots of local code repositories without explicit user permission. While the company has since open-sourced the tool and committed to third-party audits, the incident highlights the broader, systemic lack of trust regarding how Chinese AI tools handle user data.
The Policy Dilemma for Beijing
The Chinese government is currently trapped in a complex policy dilemma. Publicly punishing its most promising AI startups would be a tacit admission that the accusations made by an American firm are accurate, potentially signaling weakness in its domestic oversight. However, ignoring the issue is equally problematic. The unauthorized transmission of data involving military facilities or sensitive government infrastructure is an issue that the CAC cannot overlook without undermining its own authority.
As the investigation continues, it serves as a stark reminder of the "mirror-image" nature of the current AI arms race. Earlier this year, Chinese firms were accusing American companies of exploiting their market access to harvest data; now, the dynamic has reversed, with American companies accusing Chinese firms of using foreign infrastructure to scale their models.
Ultimately, this case represents a critical test of the efficacy of China’s data security regime. As the line between domestic innovation and international connectivity blurs, the regulatory burden on AI labs is set to increase. Whether the CAC decides to levy fines, enforce stricter oversight, or mandate a complete overhaul of these companies’ backend architecture remains to be seen. What is clear is that the era of unfettered API experimentation in the Chinese AI sector has come to an abrupt and costly end.







