Regulation6 minNewsroom

China Investigates DeepSeek and Moonshot AI

Bandeiras da China em mastros diante de um prédio ministerial de pedra cinza em Pequim, com escadaria larga e portão guardado.

Chinese regulator examines if police data leaked to Claude via hidden routing, according to The Information. Both companies have not commented.

China's Cyberspace Administration has launched an investigation into DeepSeek and Moonshot AI to determine whether sensitive data from Chinese users reached Claude, the model from the American company Anthropic, through hidden request routing. This information comes from The Information, which attributed the report to sources familiar with the matter in an article dated September 22. According to the same report, the regulator is examining whether police, military, and state-linked company data traversed an American AI system.


Neither DeepSeek nor Moonshot had publicly commented by the time this article was published, and the CAC has not officially confirmed the existence of the investigation. The investigation is ongoing and no penalties have been decided.


Source of the Accusation


The origin is a 154-page threat intelligence report published by Anthropic on September 10, covering activity from December 2025 to August 2026. According to the document, Moonshot routed over 23 million exchanges to Claude between May and July, while DeepSeek routed over 12.1 million within a 14-day window in July. The report also describes an incident where Moonshot allegedly transmitted about 300,000 client requests through 5,380 fraudulent accounts over a ten-day period.


Anthropic refers to this practice as illicit distillation, a term the company had used in February when it published an analysis of the same type of attack. The September accusation is qualitatively different from the previous one. It is not just about using Claude to train a competing model: according to Anthropic, both companies routed requests from their own users to Claude, meaning that clients who thought they were using a Chinese model had their requests processed by Anthropic.


Seven Chinese labs were named in the report. In addition to DeepSeek and Moonshot, Alibaba, Zhipu, SenseTime, MiniMax, and Xiaomi are also mentioned. The CAC summoned representatives from the seven before narrowing the focus to two, according to The Information.


What the Investigation Establishes, and What It Does Not


One detail inverses the obvious reading. The Chinese regulator is not investigating the two companies due to Anthropic’s loss. It is investigating because of the reverse: data from Chinese citizens and agencies leaving the country within inference requests. If the accusation is confirmed, the relevant violation in Beijing is the cross-border data transfer under the Data Security Law and the PIPL, not intellectual property.


This also means that any potential Chinese sanction does not validate Anthropic's business thesis. The two processes run on separate tracks, and it is possible that the CAC punishes the leak without ever commenting on the distillation. Treating the investigation as confirmation of Anthropic’s allegations is the most likely misreading of this week.


The diplomatic context weighs heavily. The investigation comes just before a meeting between Donald Trump and Xi Jinping where artificial intelligence is on the agenda, and neither government has an interest in leaving the issue without a public stance.


The Provenance Problem Facing the Buyer


For the CTO who put a Chinese model into production at a cost, the question has shifted from benchmarking to whether the supplier processes the request in its own model or routes it to third parties, and if that third party is declared in the contract as a subcontractor.


In the European Union, the answer has immediate consequences. The obligations of the AI Act for general-purpose models are effective from August 2, 2026, and the GDPR requires that the controller know the chain of subcontractors and the geographic destination of processing. Undeclared routing to an American provider invalidates the international transfer basis declared by the European company, regardless of who made the error.


In Brazil and the rest of Latin America, where Kimi and DeepSeek entered fintechs and engineering teams precisely due to the cost per token, the practical risk is of audit. The LGPD requires the operator to inform about the use of subcontractors, and a company that cannot describe where its clients' prompts go has a compliance problem even without any incident occurring.


In India, where IT service providers embed low-cost models into platforms delivered to Western clients, the exposure is contractual: data residency clauses signed with European and American banks do not survive undeclared routing.


The cheapest check is not technical, it is contractual: requiring in writing the list of subcontractors and the jurisdiction where inference occurs, with an audit right. API contracts closed by price rarely include this clause, and it is this clause that defines who is accountable when routing appears in the news.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Regulation