China’s reported inquiry into DeepSeek and Moonshot is chiefly about possible unauthorized cross border exposure of user data: Anthropic alleges the firms routed requests to Claude, including 12.1 million DeepSeek exc... The case separates two issues: Anthropic’s claim of unauthorized model distillation and China’s...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What prompted China’s Cyberspace Administration to investigate DeepSeek and Moonshot AI over Anthropic’s allegations that they secretly rout. Article summary: China’s investigation appears to be driven primarily by a data-security and sovereignty concern, not an endorsement of Anthropic’s intellectual-property claim: if Chinese users’ prompts were secretly passed to Claude, se. Topic tags: general, documentation, general web, government, news. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermark
China’s reported investigation of DeepSeek and Moonshot AI appears to have been prompted by a data-security question with wider geopolitical stakes: whether user requests intended for Chinese AI services were secretly sent to Anthropic’s Claude. If that occurred, the issue for Chinese regulators is not only whether a rival model was copied, but whether potentially sensitive Chinese data crossed into a U.S. AI system without users knowing. The inquiry remains open, and the allegations have not been publicly established as regulatory findings.
Anthropic said it detected industrial-scale campaigns involving DeepSeek, Moonshot and MiniMax that sought to extract Claude’s capabilities to improve other models. The company said the campaigns used fraudulent accounts and violated its access restrictions; it describes the practice as illicit distillation. 4
5
The most consequential allegation for a Chinese data regulator is that some traffic was not simply generated by test operators. Anthropic said Moonshot, which makes the Kimi model family, silently forwarded customer requests to Claude and presented Claude’s answers to users as Kimi outputs. In one ten-day period, Anthropic said, Moonshot relayed almost 300,000 customer requests through a network of 5,380 fraudulent accounts. 10
Anthropic also alleged that DeepSeek routed user requests to Claude. Reporting on Anthropic’s claims put DeepSeek’s activity at 12.1 million Claude exchanges over a 14-day period in July. Anthropic’s earlier account says the campaigns targeted valuable functions including reasoning, coding, data analysis, tool use and agentic capabilities. 4
These are Anthropic’s allegations, not independently verified conclusions by the Cyberspace Administration of China (CAC). That distinction matters because the claimed scale, attribution and purpose are central points in the dispute.
The reported CAC probe concerns whether user data may have reached Anthropic through the alleged routing. Regulators reportedly summoned all seven companies named in Anthropic’s report and questioned DeepSeek and Moonshot staff; no penalty had been decided at the time of reporting.
That creates a separate regulatory issue from the intellectual-property dispute. Even if Anthropic’s distillation allegations are contested, a provider that quietly sends customer prompts to another model provider could raise questions about:
In short, China has reason to examine an alleged data-routing practice on sovereignty and user-protection grounds without accepting Washington’s or Anthropic’s broader account of model theft.
Distillation generally means training a less capable model on outputs from a stronger model. Anthropic says that, in these cases, the conduct was unauthorized and designed to obtain proprietary capabilities at scale. 4
Its September threat report described Moonshot’s alleged routing as part of a broader campaign, saying it observed more than 23 million exchanges attributable to Moonshot between May and July 2026. 10 Anthropic also identified campaigns involving other China-based labs.
The policy controversy is therefore not about whether all model distillation is inherently illegitimate. It is about the alleged combination of restricted-account access, proxy networks, undisclosed customer-request forwarding and use of outputs to train competing systems.
Beijing rejected U.S. claims that Chinese AI developers were carrying out “aggressive” or “malicious” extraction of U.S. frontier-model capabilities. 18
The U.S. response has been more explicitly national-security focused. In a joint advisory, the FBI, NSA and CISA named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, alleging that the companies—likely with Chinese government awareness—had extracted billions of tokens across millions of requests from U.S. frontier AI models, including Claude, GPT, Gemini and Grok, since at least late 2024. 17
That advisory is an intelligence and cybersecurity assessment, not a court judgment or a finding of liability. Likewise, the reported CAC investigation does not itself prove Anthropic’s claims. What is clear is that both governments see the underlying conduct through different lenses: the U.S. emphasizes extraction of U.S. AI capabilities, while China’s reported inquiry emphasizes whether Chinese data may have been sent abroad.
The dispute surfaced as DeepSeek was expected to brief the UN Security Council on AI risks during the UN General Assembly week. It also coincided with expectations that Donald Trump and Xi Jinping would discuss AI safety and strategic competition.
That context makes the case larger than a fight between AI companies. It has become a test of how AI governance, cross-border data rules, model-access controls and national-security policy collide when competing AI systems are trained and served across jurisdictions.
Several important questions are unresolved:
For users and enterprise customers, the practical lesson is straightforward: an AI provider’s model name does not by itself establish where prompts are processed. Organizations handling confidential information should seek clear, documented answers on model routing, subprocessors, retention and cross-border data transfers.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
China’s reported inquiry into DeepSeek and Moonshot is chiefly about possible unauthorized cross border exposure of user data: Anthropic alleges the firms routed requests to Claude, including 12.1 million DeepSeek exc...
China’s reported inquiry into DeepSeek and Moonshot is chiefly about possible unauthorized cross border exposure of user data: Anthropic alleges the firms routed requests to Claude, including 12.1 million DeepSeek exc... The case separates two issues: Anthropic’s claim of unauthorized model distillation and China’s potential concern that domestic users’ prompts may have reached a U.S.
U.S. agencies have separately accused six China based AI companies of large scale extraction from U.S.