China’s Cyberspace Administration is reportedly examining whether DeepSeek and Moonshot routed customer prompts to Anthropic’s Claude without proper disclosure. Anthropic says DeepSeek, Moonshot and MiniMax made more than 16 million Claude exchanges through about 24,000 fraudulent accounts; its broader report descri...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How is China’s Cyberspace Administration responding to Anthropic’s allegations that DeepSeek and Moonshot AI secretly routed millions of use. Article summary: China’s Cyberspace Administration is reportedly investigating DeepSeek and Moonshot over whether they diverted customer prompts to Claude, with the central domestic concern being potential exposure of users’ sensitive da. Topic tags: general, general web, news. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers
China’s internet regulator, the Cyberspace Administration of China (CAC), is reportedly investigating DeepSeek and Moonshot AI after Anthropic alleged that the companies routed customer queries to Claude and presented the resulting answers as their own. The reported focus is potential user-data exposure and disclosure, rather than a public Chinese acceptance of Anthropic’s intellectual-property claims. As of the available reporting, the CAC has not published findings, enforcement action, or a detailed statement on the inquiry.
Anthropic’s September 2026 threat-intelligence report described what it called “illicit distillation”: using outputs from a more capable model to train or improve another model without authorization. It said activity it disrupted from December 2025 through August 2026 used fraudulent accounts, proxy services, coordinated prompts, and other methods intended to evade its access controls. 16
15
The most consequential allegation is not simply that competitors queried Claude. Anthropic said DeepSeek and Moonshot sometimes forwarded conversations from their own products to Claude, then returned Claude’s outputs to customers as if they came from their own systems. If true, that could mean user prompts—including potentially sensitive requests—were transmitted to an undisclosed third-party provider. The supplied reporting does not independently establish particular instances of customer data exposure. 10
Anthropic identified seven China-based organizations in its report: Alibaba, DeepSeek, Moonshot, Zhipu (also branded as Z.ai), Xiaomi, SenseTime, and MiniMax. It said the broader alleged campaigns generated roughly 190 million exchanges with Claude, including more than 151 million attributed to an Alibaba-linked operation. 7
1
For DeepSeek, Moonshot, and MiniMax specifically, Anthropic said the companies generated more than 16 million exchanges through approximately 24,000 fraudulent accounts. Anthropic characterized the accounts and proxy infrastructure as a way to bypass its terms of service and regional restrictions. 15
Those numbers are Anthropic’s assessments, not a regulator’s final determination. The named companies’ alleged roles and the claimed purpose of the exchanges should therefore be understood as disputed allegations rather than adjudicated facts.
The report’s reasoning-related allegation was directed at Zhipu/Z.ai, not framed as proof that Claude’s hidden reasoning system had been fully recovered. Anthropic said Zhipu ran a chain-of-thought extraction pipeline, replaying captured Claude reasoning traces through Claude to clean them for training GLM models; it said the operation rotated through 273 fraudulent accounts over 10 days. 16
In practical terms, the allegation concerns attempts to capture useful reasoning-style outputs and transform them into training material. It does not, on the evidence provided, demonstrate extraction of an underlying private model architecture or a complete internal “thinking signature.”
The reported CAC inquiry creates an important distinction. A Chinese regulatory review of whether user data was routed to Claude without proper notice would address domestic privacy, data-handling, and compliance concerns. It would not itself validate Anthropic’s allegation that the companies unlawfully copied model capabilities.
Publicly, Chinese officials have rejected the broader U.S. accusations. China’s Foreign Ministry said it opposed attempts to “throw mud” at China by distorting facts, while reporting on Beijing’s response has characterized the allegations as unfounded and politically motivated. 17
Before Anthropic released its report, the FBI, NSA, and CISA issued a joint advisory alleging that China-based AI companies had conducted industrial-scale distillation of U.S. frontier models since at least late 2024. The advisory named DeepSeek, Moonshot, Alibaba, MiniMax, StepFun, and Z.ai, and described targets that included Claude, GPT, Gemini, and Grok. 21
19
That framing makes the dispute more than a commercial fight over terms of service. U.S. agencies are positioning alleged model distillation as a technology-security and export-control concern. But the provided material does not establish that the United States has imposed new sanctions specifically on Chinese open-weight models; that remains a possible policy path, not a confirmed outcome.
The reported CAC investigation emerged as DeepSeek was expected to brief the UN Security Council on AI risks, alongside U.S. AI companies, during a meeting on AI and international security. The allegations also arrived ahead of a planned Trump–Xi meeting, adding AI access, model capabilities, and technology protection to an already sensitive bilateral agenda.
For users and enterprise buyers, the immediate lesson is straightforward: model provenance and data-routing disclosure matter. If an AI product sends prompts to another provider, customers need a clear account of where data goes, which model generates the answer, and what contractual and privacy protections apply. The CAC’s reported investigation may ultimately clarify those questions—but it has not yet produced a public conclusion.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
China’s Cyberspace Administration is reportedly examining whether DeepSeek and Moonshot routed customer prompts to Anthropic’s Claude without proper disclosure.
China’s Cyberspace Administration is reportedly examining whether DeepSeek and Moonshot routed customer prompts to Anthropic’s Claude without proper disclosure. Anthropic says DeepSeek, Moonshot and MiniMax made more than 16 million Claude exchanges through about 24,000 fraudulent accounts; its broader report described nearly 200 million exchanges tied to seven China based or...
The dispute has become a U.S. China AI policy issue: U.S.